通用内存分配崩溃,用于覆盖C++中的新建和删除

Generic Memory allocation crash for overloding new and delete in C++

本文关键字:C++ 新建 删除 覆盖 用于 内存 分配 崩溃      更新时间:2023-10-16

我有以下代码。当我删除分配的内存时,以下代码崩溃,即 Rational::d eleteMemPool((;

获取输出为

内存池值为 00000000 内存池值为 003462E8

内存池值为 003462E8

这里用于删除崩溃,尽管我们有有效的指针。

任何人都可以帮我这里有什么错误吗?

#include <string>
#include <iostream>

template < class T >
class MemoryPool {
public:
    MemoryPool (size_t size = EXPANSION_SIZE);
    ~MemoryPool ();
    inline void* alloc (size_t size); // Allocate a T element from the free list.
    inline void free (void *someElement); // Return a T element to the free list.
private:
    MemoryPool<T> *next; // next element on the free list.
    enum { EXPANSION_SIZE = 32}; // If the freeList is empty, expand it by this amount.
    void expandTheFreeList(int howMany = EXPANSION_SIZE); // Add free elements to the free list
};
template < class T > MemoryPool < T > :: MemoryPool (size_t size) {
    expandTheFreeList(size);
}
template < class T > MemoryPool < T > :: ~MemoryPool () {
    MemoryPool<T> *nextPtr = next;
    for (nextPtr = next; nextPtr != NULL; nextPtr = next) {
        next = next->next;
        delete [] nextPtr;
    }
}
template < class T > inline void* MemoryPool < T > :: alloc (size_t) {
    if (!next) {
        expandTheFreeList();
    }
    MemoryPool<T> *head = next;
    next = head->next;
    return head;
}
template < class T > inline void MemoryPool < T > :: free (void *doomed) {
    MemoryPool<T> *head = static_cast <MemoryPool<T> *> (doomed);
    head->next = next;
    next = head;
}
template < class T > void MemoryPool < T > :: expandTheFreeList(int howMany) {
    // We must allocate an object large enough to contain the next pointer.
    size_t size = (sizeof(T) > sizeof(MemoryPool<T> *)) ? sizeof(T) : sizeof(MemoryPool<T> *);
    void *pNewAlloc = new char[size];
    MemoryPool<T> *runner = static_cast <MemoryPool<T> *> (pNewAlloc);
    next = runner;
    for (int i = 0; i < howMany ; i++) {
        void *pNewAlloc = new char[size];
        runner->next = static_cast <MemoryPool<T> *> (pNewAlloc);
        runner = runner->next;
    }
    runner->next = 0;
}
class Rational {
public:
    Rational (int a = 0, int b = 1 ) : n(a), d(b) {}
    void *operator new(size_t size) { return memPool->alloc(size); }
    void operator delete(void *doomed,size_t size)  { memPool->free(doomed); }
    static void newMemPool() { 
        std::cout << "mempool value is " << Rational::memPool << std::endl;
        memPool = new MemoryPool <Rational>; 
        std::cout << "mempool value is " << Rational::memPool << std::endl;
    }
    static void deleteMemPool() { 
        std::cout << "mempool value is " << Rational::memPool << std::endl;
        delete memPool; 
    }
private:
    int n; // Numerator
    int d; // Denominator
    static MemoryPool <Rational> *memPool;
};
MemoryPool <Rational> *Rational::memPool = 0;
int main() {
    Rational *array[1000];
    Rational::newMemPool();

    // Start timing here
    for (int j = 0; j < 1; j++) {
        for (int i = 0; i < 10; i++) {
            array[i] = new Rational(i);
        }
        for (int i = 0; i < 10; i++) {
            delete array[i];
        }
    }
    // Stop timing here
    Rational::deleteMemPool();
}

堆栈跟踪:

Stack trace:>
ReadParsing.exe!Rational::deleteMemPool() Line 75   C++
ReadParsing.exe!main() Line 107 C++
ReadParsing.exe!__tmainCRTStartup() Line 586 + 0x19 bytes   C
ReadParsing.exe!mainCRTStartup() Line 403   C
kernel32.dll!7c817077()

您在删除内存池中的块时遇到问题。 分配块时,在 expandTheFreeList(i) 中使用new char[size]

但是当你删除这些块时,你会使用delete [] nextPtr

template < class T > MemoryPool < T > :: ~MemoryPool () {
    MemoryPool<T> *nextPtr = next;
    for (nextPtr = next; nextPtr != NULL; nextPtr = next) {
        next = next->next;
        delete [] nextPtr;     //  <-- problem
    }
}

而且由于nextPtr是一个memoryPool<T>*,你释放了错误的东西(它最终会递归到这个 destrcutor 中引导(。

将该问题行更改为:

delete [] reinterpret_cast<char*>(nextPtr);

似乎让事情不会崩溃。当然,可能还有其他问题。