Details
-
Bug
-
Resolution: Unresolved
-
P2: Important
-
None
-
5.15.2, 6.0.0 RC2
-
None
-
6012285e7dedb4364e2db087b7d5cbfc2973320a
Description
QTreeView has the ridiculous idea of storing QModelIndexes to the underlying model to populate a vector of QTreeViewItem objects:
struct QTreeViewItem { QTreeViewItem() : parentItem(-1), expanded(false), spanning(false), hasChildren(false), hasMoreSiblings(false), total(0), level(0), height(0) {} QModelIndex index; // we remove items whenever the indexes are invalidated int parentItem; // parent item index in viewItems uint expanded : 1; uint spanning : 1; uint hasChildren : 1; // if the item has visible children (even if collapsed) uint hasMoreSiblings : 1; uint total : 28; // total number of children visible uint level : 16; // indentation int height : 16; // row height };
Once you know this, it's super easy to build models that make QTreeView crash – just build a (tree) model for which the QModelIndexes internal pointers are not stable over time.
... QStandardItemModel would be a good example, but that model is broken if one removes and replaces internal nodes (QTBUG-89145). It's still easy to set it up in a crashing way, build a tree and remove a node from the middle via takeItem (QTBUG-89072). ...
One may concoct an evil-but-technically-100%-correct model which will crash if any QModelIndex is held across event loop iterations:
- store a number N in the model
- run a QTimer with 0 interval that increments the N in the model
- from index()/parent()/etc., return QModelIndexes loaded with the current N
- in any method taking an index, check if the number in the index matches N, if not crash
One may even concoct a less-than-evil model, that changes its model indexes only after a signal emission, and QTreeView would still break down. For isntance, tree of indivudally allocated nodes, returning QModelIndexes with pointers to the nodes. Nodes are immutable and changing a node's data means creating a new node and installing it in place of old node (and emit dataChanged() as expected). However, QTreeView::dataChanged doesn't flush its list of QModelIndex, resulting in a crash.
Attachments
Issue Links
- relates to
-
QTBUG-88966 [REG 5.15 -> 6.0.0] Crash when expanding items in QTreeView
- Closed
Gerrit Reviews
For Gerrit Dashboard: QTBUG-89146 | ||||||
---|---|---|---|---|---|---|
# | Subject | Branch | Project | Status | CR | V |
325659,1 | Add an autotest for QTBUG-89146 | dev | qt/qtbase | Status: NEW | 0 | 0 |