From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: Po Lu via "Bug reports for GNU Emacs, the Swiss army knife of text editors" Newsgroups: gmane.emacs.bugs Subject: bug#58042: 29.0.50; ASAN use-after-free in re_match_2_internal Date: Wed, 05 Oct 2022 21:52:52 +0800 Message-ID: <871qrmv0ln.fsf@yahoo.com> References: <83edvnv965.fsf@gnu.org> <83pmf6u76i.fsf@gnu.org> <83mtaau43p.fsf@gnu.org> <83ilkytyif.fsf@gnu.org> <877d1ewnx0.fsf@yahoo.com> <87tu4iv7w5.fsf@yahoo.com> <838rlutmqo.fsf@gnu.org> Reply-To: Po Lu Mime-Version: 1.0 Content-Type: text/plain Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="17053"; mail-complaints-to="usenet@ciao.gmane.io" User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/28.0.91 (gnu/linux) Cc: gerd.moellmann@gmail.com, alan@idiocy.org, 58042@debbugs.gnu.org To: Eli Zaretskii Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Wed Oct 05 16:08:12 2022 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1og54F-0004FK-00 for geb-bug-gnu-emacs@m.gmane-mx.org; Wed, 05 Oct 2022 16:08:11 +0200 Original-Received: from localhost ([::1]:47412 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1og54D-0000nt-Gl for geb-bug-gnu-emacs@m.gmane-mx.org; Wed, 05 Oct 2022 10:08:09 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]:60074) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1og4qY-0005hS-Va for bug-gnu-emacs@gnu.org; Wed, 05 Oct 2022 09:54:03 -0400 Original-Received: from debbugs.gnu.org ([209.51.188.43]:57274) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1og4qY-00018L-IO for bug-gnu-emacs@gnu.org; Wed, 05 Oct 2022 09:54:02 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1og4qY-0000lM-2e for bug-gnu-emacs@gnu.org; Wed, 05 Oct 2022 09:54:02 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Po Lu Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Wed, 05 Oct 2022 13:54:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 58042 X-GNU-PR-Package: emacs Original-Received: via spool by 58042-submit@debbugs.gnu.org id=B58042.16649779942849 (code B ref 58042); Wed, 05 Oct 2022 13:54:02 +0000 Original-Received: (at 58042) by debbugs.gnu.org; 5 Oct 2022 13:53:14 +0000 Original-Received: from localhost ([127.0.0.1]:56345 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1og4pm-0000js-1O for submit@debbugs.gnu.org; Wed, 05 Oct 2022 09:53:14 -0400 Original-Received: from sonic315-20.consmr.mail.ne1.yahoo.com ([66.163.190.146]:38942) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1og4pi-0000je-RB for 58042@debbugs.gnu.org; Wed, 05 Oct 2022 09:53:12 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1664977983; bh=g0wFxmZ+TtTnkB4ANhhOtRYyH1OWFb1AABNja+1h5iM=; h=From:To:Cc:Subject:References:Date:In-Reply-To:From:Subject:Reply-To; b=otsPB9fvMzsO07GPeHUjkG/Z3XIUw9g+qmlD5HSGb1X6eEixkgy0hduGsf8HbgcGSqeCPec28JUbdo5CgaYM9X2fR6FdFlSxf8FfyA2lmJ5MpMn+71TjpVVD7mxEWwDw+6PE4zbNnE0gtDMwLYLe01N/95v0NRNQuAm+L5O14CVus4rxJHaaeG4dQBVxZDhsQKX6IHkeKAkIX4xgxEaUg/zc/DlaP8B8AZiv6rzw0PfM80VM3YicnvWMBehyBNyGZ9KTUrD8wy7Dxda/TT9qo5MyFSIdwts+6+e49d4SFVCQoKGziilWf11t7xPHLOKHO7wpAjekL7kH/pinGnDltg== X-SONIC-DKIM-SIGN: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s2048; t=1664977983; bh=ZvMjq8hZfTvskkvIrbfKJ2wQoABKGoBPNKaNm2FuvMt=; h=X-Sonic-MF:From:To:Subject:Date:From:Subject; b=gvOqPLDP6MdFoz03RQmilkhQfs7kfTW5QcAJWUtwmo6j2qNm2UdS4ANx24oNSvFkm9jatmu6PMrc6cBdHyMkIasuP9wGRJ17un/Ta1tioSW61/sIUy9GvbFynegqiTEuqAiw5mDqfRIZjoJvsPFoGn4+YOt8tPdL+Si0BhBK9HAERqshQWgBuw9u7/vl45KzCLq7pR4CHPxwpkn0qdOPuTYcIPj+5i1Iv36GEtsVINPib5qolkRtBq9Vlx27jpProqpmYTDMmRHxt6/4mBAyz1E6SVWRPeSpr1cWroOOAzMbT5eX3jrc2LgPxcThSLAI+fXZm3N3yq3htbV1U5O2CA== X-YMail-OSG: fXePB6IVM1mqeQ68wcrTrRdIuiCfdUKfnlKy0s1SiKflpdvVAG9fouSQ.JgmWLj rWWN2gZRbkPZmmEaLHUHIUb5N2BLJRN7W7iONwvqw74vqfXauk3JkmSPNOS057v2q3S529yKwRM5 lyer8MfatrrTCvSYzi0MS99TV6wyXdCSQZ2FVdQNX8DJH7asLG8IcVXQAuTzWbDz51OaOPnM70X3 h2wQaveMxmtL2o_C9BGuVD9eoKZyjERjk2kNA9a51PAJn3hxhbSsb23Y5IV9PulxvcAblNmsA9X7 B_Nxp_2YVNpWkgcBPzP3tsZM4pORm3WIR7t1V9AuBNhOH8Fl2j9ADJ4LZ9RD_KVnvDBl4xfs2IAD .XnlngyDm_6CVBPyqs8cMT0ZEpSrQcx24dzm1HeEtOXvPkgTM5BnLdIwzfm94HIO_hq2QKf.747R jkWWTzAw77IL2BP1CVY5BSESKPoVL_Ii0nxk5mOeV1.Q_LfqgNXs5HJjRnBLC_09s_KvuWvpZEo7 _8Gio1urxo1xAHnUuPeG3OVWb_qBisVdKN0EffX1jQ0d.vQtEDGeEJhnFzEaiYGlVRLxSHIk1D1N hr7suk0tCCccbb_qa0ZlFUGpcYQqFxAgxYZrJ4HBAFVnu.XenhVxZD.Bagl7y3W28EBDHXTVbaeK C_qDT7kghsYEyhYWSToFfo9RBw9Dbpc0s4t2cterqxw5ZdddOSZmhMPOM6uwccPSnevsvH_qqik4 rOWHzqtclcW0UJKSikVP2SJ4WId8uJOfVOs1uoUKh94xD8xbW.wx7PFBTd99avwFldhfOP043LT0 pJ0695koZDSAhTetzZE1deeB7MBnS0QXJmBqJx1kag X-Sonic-MF: Original-Received: from sonic.gate.mail.ne1.yahoo.com by sonic315.consmr.mail.ne1.yahoo.com with HTTP; Wed, 5 Oct 2022 13:53:03 +0000 Original-Received: by hermes--production-sg3-cf9dc7f8d-tskmz (Yahoo Inc. Hermes SMTP Server) with ESMTPA ID 393a6a4cb9a3be2d24eeafb1ec4eaf4f; Wed, 05 Oct 2022 13:53:01 +0000 (UTC) In-Reply-To: <838rlutmqo.fsf@gnu.org> (Eli Zaretskii's message of "Wed, 05 Oct 2022 16:37:35 +0300") X-Mailer: WebService/1.1.20702 mail.backend.jedi.jws.acl:role.jedi.acl.token.atz.jws.hermes.yahoo X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.io gmane.emacs.bugs:244540 Archived-At: Eli Zaretskii writes: > We call maybe_quit in many places, basically anywhere where we have > potentially long loops. It isn't just Fmemq. So if we want to > prevent maybe_quit from indirectly calling arbitrary Lisp, we'd need > to block_input inside probably_quit. Which means > process_pending_signals will not call the read-socket hook and will > not gobble input. That's bad, I think. > > And note that this is only problematic on macOS (AFAIU), because there > the read-socket hook can trigger redisplay. There are many different ways to trigger redisplay from the read-socket hook in the Haiku port as well, and I haven't seen any problems there. Besides, any call to automatic GC today can run arbitrary Lisp through finalizer functions, and that includes redisplay. So unless the read_socket_hook does not cons at all, there is no way to prevent probably_quit from running Lisp code.