Hello, I'm working on Rust bindings to AngelScript to embed into my game engine.
I'm writing custom addons that are functionally the same as the official "stdlib" ones you made. The addons I've made that are in question here are the array and string addon. A decent amount of the code is basically translated to Rust from the actual C++ addons.
I understand this question may be out of scope since its bindings, but I was hoping you might be able to give me some insight into AngelScript that could help me debug this issue.
The current problem is that a foreach loop on an array<string> will crash with a double free error: free(): double free detected in tcache 2 . If I use a regular for loop like for (int i = 0... and index in the array, it works fine. Looking at the docs here, I see that the foreach syntax is just syntactic sugar over a classic for loop, and that the thing being double freed here is val, that matches some things I saw later in debugging.
Here's the minimal angelscript code I found that causes this issue.
void main() {
array<string> a;
a.insertLast("test");
a.insertLast("test1");
a.insertLast("test2");
a.insertLast("test3");
// free(): double free detected in tcache 2
foreach(auto val : a) { }
// This works fine
/* for (int i = 0; i < a.length; i++) {
auto val = a[i];
} */
print("done");
}The foreach is where the double free error happens and the test crashes. I decided to add some debug messages to my string constructors and destructors and got this:
string_construct, out=0x7f8b20028550
string_op_assign, self="",val="test"
stringconstruct, out=0x7f8b20028590
string_op_assign, self="",val="test1"
stringconstruct, out=0x7f8b200269c0
string_op_assign, self="",val="test2"
stringconstruct, out=0x7f8b20028620
string_op_assign, self="",val="test3"
stringcopy_construct, other="test",out=0x7f8b2001fc80
string_destruct, out=0x7f8b2001fc80,str="test"
string_copy_construct, other="test1",out=0x7f8b2001fc80
string_destruct, out=0x7f8b2001fc80,str="test1"
string_copy_construct, other="test2",out=0x7f8b2001fc80
string_destruct, out=0x7f8b2001fc80,str="test2"
string_copy_construct, other="test3",out=0x7f8b2001fc80
string_destruct, out=0x7f8b2001fc80,str="test3"
string_destruct, out=0x7f8b2001fc80,str="(��"It appears like the destruct for the last string copied to val is called twice, and the 2nd time its called the string data gets all wonky from the destruct.
I copied the same script to the asrun sample, added the debug prints to the official string addon, and see a similar thing where the last string is destructed twice (I truncated the stringconstruct and assign prints):
string_copy_construct, other="c",out=0x55a7bd20149c
string_destruct, out=0x55a7bd20149c,str="c"
string_copy_construct, other="b",out=0x55a7bd20149c
string_destruct, out=0x55a7bd20149c,str="b"
string_copy_construct, other="d",out=0x55a7bd20149c
string_destruct, out=0x55a7bd20149c,str="d"
string_copy_construct, other="a",out=0x55a7bd20149c
string_destruct, out=0x55a7bd20149c,str="a"
string_destruct, out=0x55a7bd20149c,str="a"If you'd like to see the code or run the test yourself, you can see the repo here. You can follow the build steps in the readme, then use this command to run the test that shows this problem:
cargo test addons::array::tests::foreach_string -- --exact --nocaptureOnce again, I completely understand if this is out of scope of this forum since its super unsupported. I thought I might ask anyway to see if you'd be able to offer some insight on what could be going wrong.
Thanks for making such a cool project!