From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED.blaine.gmane.org!not-for-mail From: Paul Eggert Newsgroups: gmane.emacs.bugs Subject: bug#36773: 27.0.50; Accessing a cached SVG with eww can cause Emacs to crash Date: Thu, 25 Jul 2019 14:37:26 -0700 Organization: UCLA Computer Science Department Message-ID: <3ffd73c9-3fa6-f5d6-63c5-21be090a332f@cs.ucla.edu> References: Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="------------60B73300050BF92D9D931E0C" Injection-Info: blaine.gmane.org; posting-host="blaine.gmane.org:195.159.176.226"; logging-data="106221"; mail-complaints-to="usenet@blaine.gmane.org" User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:60.0) Gecko/20100101 Thunderbird/60.8.0 Cc: 36773@debbugs.gnu.org To: Pip Cet Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Thu Jul 25 23:38:10 2019 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([209.51.188.17]) by blaine.gmane.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.89) (envelope-from ) id 1hqlRC-000RWJ-Bk for geb-bug-gnu-emacs@m.gmane.org; Thu, 25 Jul 2019 23:38:10 +0200 Original-Received: from localhost ([::1]:35448 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.86_2) (envelope-from ) id 1hqlRB-0000cR-Bw for geb-bug-gnu-emacs@m.gmane.org; Thu, 25 Jul 2019 17:38:09 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]:47318) by lists.gnu.org with esmtp (Exim 4.86_2) (envelope-from ) id 1hqlR7-0000RD-39 for bug-gnu-emacs@gnu.org; Thu, 25 Jul 2019 17:38:06 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1hqlR4-0002Gt-TS for bug-gnu-emacs@gnu.org; Thu, 25 Jul 2019 17:38:04 -0400 Original-Received: from debbugs.gnu.org ([209.51.188.43]:59945) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1hqlR4-0002Fp-My for bug-gnu-emacs@gnu.org; Thu, 25 Jul 2019 17:38:02 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1hqlR4-0002Fx-JB for bug-gnu-emacs@gnu.org; Thu, 25 Jul 2019 17:38:02 -0400 X-Loop: help-debbugs@gnu.org In-Reply-To: Resent-From: Paul Eggert Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Thu, 25 Jul 2019 21:38:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 36773 X-GNU-PR-Package: emacs Original-Received: via spool by 36773-submit@debbugs.gnu.org id=B36773.15640906598645 (code B ref 36773); Thu, 25 Jul 2019 21:38:02 +0000 Original-Received: (at 36773) by debbugs.gnu.org; 25 Jul 2019 21:37:39 +0000 Original-Received: from localhost ([127.0.0.1]:40533 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1hqlQh-0002FM-4u for submit@debbugs.gnu.org; Thu, 25 Jul 2019 17:37:39 -0400 Original-Received: from zimbra.cs.ucla.edu ([131.179.128.68]:60396) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1hqlQf-0002F6-0J for 36773@debbugs.gnu.org; Thu, 25 Jul 2019 17:37:38 -0400 Original-Received: from localhost (localhost [127.0.0.1]) by zimbra.cs.ucla.edu (Postfix) with ESMTP id ABFA416007D; Thu, 25 Jul 2019 14:37:30 -0700 (PDT) Original-Received: from zimbra.cs.ucla.edu ([127.0.0.1]) by localhost (zimbra.cs.ucla.edu [127.0.0.1]) (amavisd-new, port 10032) with ESMTP id 32cx9f_0ioX9; Thu, 25 Jul 2019 14:37:30 -0700 (PDT) Original-Received: from localhost (localhost [127.0.0.1]) by zimbra.cs.ucla.edu (Postfix) with ESMTP id EF93F1626EB; Thu, 25 Jul 2019 14:37:29 -0700 (PDT) X-Virus-Scanned: amavisd-new at zimbra.cs.ucla.edu Original-Received: from zimbra.cs.ucla.edu ([127.0.0.1]) by localhost (zimbra.cs.ucla.edu [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id 4ohjM3dOU25X; Thu, 25 Jul 2019 14:37:29 -0700 (PDT) Original-Received: from [192.168.1.9] (cpe-23-242-74-103.socal.res.rr.com [23.242.74.103]) by zimbra.cs.ucla.edu (Postfix) with ESMTPSA id C80B916007D; Thu, 25 Jul 2019 14:37:29 -0700 (PDT) Content-Language: en-US X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 209.51.188.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.org gmane.emacs.bugs:163741 Archived-At: This is a multi-part message in MIME format. --------------60B73300050BF92D9D931E0C Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit Thanks for writing those patches. The image.c patch is obviously needed to prevent a core dump, so I installed the attached variant of it (added a comment, changed a never-can-happen branch in obsolete code to an eassume). I assume the Elisp changes are good too, but I didn't check them so didn't install them. --------------60B73300050BF92D9D931E0C Content-Type: text/x-patch; name="0001-Don-t-crash-when-parsing-bad-SVG-data.patch" Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename="0001-Don-t-crash-when-parsing-bad-SVG-data.patch" >From 2fbe24895bc621cb2ff1b9898c010eec288545f6 Mon Sep 17 00:00:00 2001 From: Paul Eggert Date: Thu, 25 Jul 2019 14:29:22 -0700 Subject: [PATCH] Don't crash when parsing bad SVG data Derived from a patch by Pip Cet (Bug#36773#47). * src/image.c (svg_load_image): Work around librsvg 2.40.13 bug. --- src/image.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/src/image.c b/src/image.c index 355c849491..8cab860085 100644 --- a/src/image.c +++ b/src/image.c @@ -9530,10 +9530,13 @@ svg_load_image (struct frame *f, struct image *img, char *contents, if (base_file) g_object_unref (base_file); g_object_unref (input_stream); - if (err) goto rsvg_error; + + /* Check rsvg_handle too, to avoid librsvg 2.40.13 bug (Bug#36773#26). */ + if (!rsvg_handle || err) goto rsvg_error; #else /* Make a handle to a new rsvg object. */ rsvg_handle = rsvg_handle_new (); + eassume (rsvg_handle); /* Set base_uri for properly handling referenced images (via 'href'). See rsvg bug 596114 - "image refs are relative to curdir, not .svg file" @@ -9654,7 +9657,8 @@ svg_load_image (struct frame *f, struct image *img, char *contents, return 1; rsvg_error: - g_object_unref (rsvg_handle); + if (rsvg_handle) + g_object_unref (rsvg_handle); /* FIXME: Use error->message so the user knows what is the actual problem with the image. */ image_error ("Error parsing SVG image `%s'", img->spec); -- 2.17.1 --------------60B73300050BF92D9D931E0C--