让 valgrind 开心 vs 避免段错误

making valgrind happy vs avoiding segfault

我是 C 的新手,正在尝试学习 char 数组的动态内存分配,但不确定为什么我不能让 valgrind 对 0 错误感到满意,同时避免段错误。我的例子是基于这个例子:

How to dynamically allocate memory for char** in C

根据该示例,我编写了以下测试代码:

#include <stdlib.h>
#include <stdio.h>

int main (int argc, char* argv[]){
        char **myChar;

        int nEl = 5;
        int nChars = 10;

        myChar = (char**)malloc(sizeof(char*));
        for (int it = 0; it < nEl; it++) {
                myChar[it] = (char*)malloc((nChars) * sizeof(char));
        }

        //for (int it = 0; it < nEl; it++) {
        //        free(myChar[it]);
        //}
        //free(myChar);

        return 0;
}

它按原样编译,运行s 没有问题,以 return 0x0 退出,但 valgrind 抱怨:

4 errors in context 1 of 1:
Invalid write of size 8
   at 0x400583: main (in /home/username/Documents/personal/tmp/cprog2/test2)
 Address 0x5204048 is 0 bytes after a block of size 8 alloc'd
   at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
   by 0x40054D: main (in /home/username/Documents/personal/tmp/cprog2/test2)

ERROR SUMMARY: 4 errors from 1 contexts (suppressed: 0 from 0)

计算出 valgrind 期望 malloc 的 **myChar 和 myChar[it] 是 free(),我取消注释注释位,但是程序段错误和 valgrind 是这样说的:

4 errors in context 1 of 2:
Invalid read of size 8
   at 0x4005EF: main (in /home/username/Documents/personal/tmp/cprog2/test2)
 Address 0x5204048 is 0 bytes after a block of size 8 alloc'd
   at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
   by 0x40058D: main (in /home/username/Documents/personal/tmp/cprog2/test2)


4 errors in context 2 of 2:
Invalid write of size 8
   at 0x4005C3: main (in /home/username/Documents/personal/tmp/cprog2/test2)
 Address 0x5204048 is 0 bytes after a block of size 8 alloc'd
   at 0x4C2DB8F: malloc (in /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
   by 0x40058D: main (in /home/username/Documents/personal/tmp/cprog2/test2)

ERROR SUMMARY: 8 errors from 2 contexts (suppressed: 0 from 0)

为什么我不能让 valgrind 开心并编译 运行 一个可用的应用程序?

您没有分配足够的内存:

myChar = (char**)malloc(sizeof(char*));

这为单个 char * 分配了 space,但您将此内存视为分配了 5 个(即 nEl)内存。

因此,您的写入超出了已分配内存的末尾。这就是 Valgrind 在显示 "Address 0x5204048 is 0 bytes after a block of size 8 alloc'd" 时提醒您的内容。这样做会调用未定义的行为,在本例中表现为崩溃。

如果你想要 space 作为 nEl 指针,分配那个数量的 space:

myChar = malloc(sizeof(char*) * nEl);

此外,don't cast the return value of malloc