You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于new/delete与SecureZeroMemory的问题:delete[] szPassword为何失败?

分析你的new/delete与SecureZeroMemory问题

Hey Jeff, let's dig into why your delete[] szPassword is failing when you grab the sizeof() value—it's a super common pitfall with dynamic memory in C++!

核心误区:sizeof()不是在算你分配的内存大小

First off, that st2 value of 8 is a dead giveaway. When you call sizeof() on a pointer (like szPassword, which is a char*), you're not getting the size of the memory you allocated with new[]—you're getting the size of the pointer itself. On 64-bit systems, pointers are 8 bytes wide, which is exactly what st2 is showing you.

If you allocated space for "a", that's 2 bytes total (the character 'a' plus the null terminator \0), but sizeof(szPassword) doesn't know that—it just tells you how big the pointer variable is.

为什么这会搞砸delete[]?

Here's the critical part: I bet you're using that st2 value (8 bytes) as the second parameter to SecureZeroMemory. If you do that, you're telling the function to zero out 8 bytes starting at szPassword—but you only allocated 2 bytes. That means you're writing 6 bytes past the end of your allocated memory, right into the heap metadata that the C++ runtime uses to track memory blocks.

Heap metadata includes things like the size of the allocated block, pointers to adjacent blocks, and validation checks. When you overwrite that stuff, the runtime has no way to properly clean up the memory when you call delete[]—it either hits an assertion failure, crashes, or behaves unpredictably.

为什么跳过sizeof()让一切正常?

When you don't grab that sizeof() value, you're probably using the correct size for SecureZeroMemory—like strlen(szPassword) + 1 (which gives you the actual 2 bytes needed for "a" plus the null terminator). Since you're not writing past your allocated memory, the heap metadata stays intact, and delete[] works as expected.

修复方案

To fix this, you need to track the actual size of your dynamically allocated memory, not rely on sizeof() for pointers:

  1. Explicitly track the allocation size

    // Calculate and store the exact size you need
    size_t passwordLen = strlen("a") + 1; // +1 for the null terminator
    char* szPassword = new char[passwordLen];
    strcpy(szPassword, "a");
    
    // Use the tracked size for SecureZeroMemory
    SecureZeroMemory(szPassword, passwordLen);
    
    delete[] szPassword; // This will work now!
    
  2. Use std::string to avoid manual memory management
    Even better, let the standard library handle memory for you—this eliminates the risk of heap corruption entirely:

    std::string password = "a";
    // Zero out the underlying buffer (including the null terminator)
    SecureZeroMemory(password.data(), password.size() + 1);
    // No need for delete—std::string cleans up automatically when it goes out of scope
    

内容的提问来源于stack exchange,提问作者JeffR

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 08:06:16