I found a use-after-free violation in DoForAllConstructs, when it's being passed one of the destruction functions (and MEM_TABLE_SIZE=0 for debugging). I was able to fix it with the following workaround, but I'm not sure that's the best option because it would fall over if any of the supplied functions need to modify "next". The only better fix would be the change the signature of the functions we pass to include what "next" is supposed to be.
This fix is fine had has been checked into subversion. The functions passed into DoForAllConstructs don't change the next pointer.