From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.ciao.gmane.io!not-for-mail From: Yuan Fu Newsgroups: gmane.emacs.bugs Subject: bug#40000: 27.0.60; next-single-char-property-change hangs on bad argument Date: Mon, 9 Mar 2020 11:40:01 -0400 Message-ID: Mime-Version: 1.0 (Mac OS X Mail 13.0 \(3608.60.0.2.5\)) Content-Type: multipart/alternative; boundary="Apple-Mail=_F4073758-4BA9-4C69-86EE-2510F46E593E" Injection-Info: ciao.gmane.io; posting-host="ciao.gmane.io:159.69.161.202"; logging-data="128436"; mail-complaints-to="usenet@ciao.gmane.io" To: 40000@debbugs.gnu.org Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Mon Mar 09 16:44:35 2020 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1jBKa2-000XHM-Sa for geb-bug-gnu-emacs@m.gmane-mx.org; Mon, 09 Mar 2020 16:44:34 +0100 Original-Received: from localhost ([::1]:45386 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1jBKa1-0001xA-QO for geb-bug-gnu-emacs@m.gmane-mx.org; Mon, 09 Mar 2020 11:44:33 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]:39725) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1jBKWe-0004xJ-E1 for bug-gnu-emacs@gnu.org; Mon, 09 Mar 2020 11:41:06 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1jBKWc-0008PC-JD for bug-gnu-emacs@gnu.org; Mon, 09 Mar 2020 11:41:04 -0400 Original-Received: from debbugs.gnu.org ([209.51.188.43]:45380) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1jBKWc-0008Oz-9U for bug-gnu-emacs@gnu.org; Mon, 09 Mar 2020 11:41:02 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1jBKWc-0006rn-7F for bug-gnu-emacs@gnu.org; Mon, 09 Mar 2020 11:41:02 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Yuan Fu Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Mon, 09 Mar 2020 15:41:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: report 40000 X-GNU-PR-Package: emacs X-Debbugs-Original-To: Bug Report Emacs Original-Received: via spool by submit@debbugs.gnu.org id=B.158376841126320 (code B ref -1); Mon, 09 Mar 2020 15:41:02 +0000 Original-Received: (at submit) by debbugs.gnu.org; 9 Mar 2020 15:40:11 +0000 Original-Received: from localhost ([127.0.0.1]:51353 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1jBKVm-0006qP-SW for submit@debbugs.gnu.org; Mon, 09 Mar 2020 11:40:11 -0400 Original-Received: from lists.gnu.org ([209.51.188.17]:59107) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1jBKVl-0006qI-Fv for submit@debbugs.gnu.org; Mon, 09 Mar 2020 11:40:09 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]:39568) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1jBKVj-0002rE-ES for bug-gnu-emacs@gnu.org; Mon, 09 Mar 2020 11:40:09 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1jBKVg-0007zX-JV for bug-gnu-emacs@gnu.org; Mon, 09 Mar 2020 11:40:07 -0400 Original-Received: from mail-qk1-x729.google.com ([2607:f8b0:4864:20::729]:38833) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1jBKVg-0007zH-Bk for bug-gnu-emacs@gnu.org; Mon, 09 Mar 2020 11:40:04 -0400 Original-Received: by mail-qk1-x729.google.com with SMTP id h14so3666412qke.5 for ; Mon, 09 Mar 2020 08:40:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:mime-version:subject:message-id:date:to; bh=a+1eKkY8hlOIWNs4HKxgZEZ84bwLC7FebH5sh5lwsCk=; b=T1ZMOrZ2hx8/q2tOtzSYA/ajzG8AzUoxWsi8Pt6Va5LjR91M8apOc/cYwzeiEd4BrZ loIwq5gsVAmD2TZhytdr5liFczWu1JGPZBaA3FrBBH/07oeC2Nhod+/jVADtRWihhSRS aS+eEDBCOEUvSQ8VyAZ0xbjjoTh2ovTeI7Ibmx7g4IZMDLFcQiB+khR0yareYT3cOY0/ g5dtdLk447IPy1Z4wmR6csrJgd5AM91j+4pkGR+eEqzzGIn+4DQ4Ws49Noo4WraCtN/w b+rUvWSqNAZUoYlLbUCYYiEBWfDWl1PIUI3GFep7zfaBvU87rUUKaJQEulNCHwvpqeYR sVvA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:mime-version:subject:message-id:date:to; bh=a+1eKkY8hlOIWNs4HKxgZEZ84bwLC7FebH5sh5lwsCk=; b=JHjb3WP+qTR+I2msGfM4r7ymkwd7Ze5ulbpESAX4E/rAmmI06+wmvX7u9CsN96npOU fOqeQ4NgZO+gwWd79Lx0n/h/ehspvlnk88nhYw3fV3mXBN5Znqs8ZRSM/5BrNBObdYJV vi0ocu22EQT+VDo7FsJbKiP1IOSPDxCWuVaXNwDQSqKyIkD44FHEbRE4w6e001C28uix imW70JAlunmZGun5UboKIBGbEdN3tBbwR3QlFzk+EJIp+cJP1kszcMvZwvrUJ0RCl19V 7W9V+j9Y1GFinwC7GsVOCpMnZmqsgYD1mVf9tCdh7s63S+zE8rmR+L6VKS/bTlx8jSiP KPmw== X-Gm-Message-State: ANhLgQ3m5gEUSwbXXqbalelkhS4tmk1Rz/ITTQiKhGa82dRStcvJlWSf nUTCdIAQIpsbRN4dn/yBGJDpzSWBRlBbkoz/ X-Google-Smtp-Source: ADFU+vsn9wHA//MKftjC1O/8M/TuIP/sDOamebqK3LqqlniZKFsXu5RlaEDWyp0IWDKFrZQ8Krue4g== X-Received: by 2002:ae9:dcc1:: with SMTP id q184mr15202591qkf.480.1583768403002; Mon, 09 Mar 2020 08:40:03 -0700 (PDT) Original-Received: from [192.168.1.5] (c-174-60-229-153.hsd1.pa.comcast.net. [174.60.229.153]) by smtp.gmail.com with ESMTPSA id g9sm9325090qkl.39.2020.03.09.08.40.02 for (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 09 Mar 2020 08:40:02 -0700 (PDT) X-Mailer: Apple Mail (2.3608.60.0.2.5) X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 209.51.188.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.io gmane.emacs.bugs:177095 Archived-At: --Apple-Mail=_F4073758-4BA9-4C69-86EE-2510F46E593E Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 If I pass a LIMIT > point-max to next-single-char-property-change, Emacs = hangs. Of course, I shouldn=E2=80=99t pass such a bad argument, but = next-single-char-property-change should probably error out instead of = hanging in a infinite loop IMHO. Here is the relevant C code: while (true) { position =3D Fnext_char_property_change (position, limit); if (XFIXNAT (position) >=3D XFIXNAT (limit)) { position =3D limit; break; } value =3D Fget_char_property (position, prop, object); if (!EQ (value, initial_value)) break; } If it gets a LIMIT larger than point-max, position can never =3D=3D = limit, so it will loop in the while loop infinitely. I would add a check = in the beginning of the function, to signal an out-of-range error. Or = maybe set limit to poin-max quietly. Other similar functions could have = the same problem, previous-single-char-property-change comes to my mind. Yuan In GNU Emacs 27.0.60 (build 1, x86_64-apple-darwin19.3.0, NS = appkit-1894.30 Version 10.15.3 (Build 19D76)) of 2020-02-25 built on missSilver Repository revision: f27187f963e9e36435b508e29256e048799e0ff2 Repository branch: emacs-27 Windowing system distributor 'Apple', version 10.3.1894 System Description: Mac OS X 10.15.3 Recent messages: For information about GNU Emacs and the GNU system, type C-h C-a. Configured using: 'configure --with-modules --with-pdumper=3Dyes = --oldincludedir=3D/Applications/Xcode.app/Contents/Developer/Platforms/Mac= OSX.platform/Developer/SDKs/MacOSX.sdk/usr/include/libxml2/' Configured features: RSVG GLIB NOTIFY KQUEUE ACL GNUTLS LIBXML2 ZLIB TOOLKIT_SCROLL_BARS XIM NS MODULES THREADS PDUMPER LCMS2 Important settings: value of $LC_CTYPE: UTF-8 value of $LANG: en_CN.UTF-8 locale-coding-system: utf-8-unix Major mode: Fundamental Minor modes in effect: tooltip-mode: t global-eldoc-mode: t electric-indent-mode: t mouse-wheel-mode: t tool-bar-mode: t menu-bar-mode: t file-name-shadow-mode: t global-font-lock-mode: t blink-cursor-mode: t auto-composition-mode: t auto-encryption-mode: t auto-compression-mode: t buffer-read-only: t line-number-mode: t transient-mark-mode: t Load-path shadows: None found. Features: (shadow sort mail-extr emacsbug message rmc puny dired dired-loaddefs format-spec rfc822 mml easymenu mml-sec password-cache epa derived epg epg-config gnus-util rmail rmail-loaddefs text-property-search time-date subr-x seq byte-opt gv bytecomp byte-compile cconv mm-decode mm-bodies mm-encode mail-parse rfc2231 mailabbrev gmm-utils mailheader cl-loaddefs cl-lib sendmail rfc2047 rfc2045 ietf-drums mm-util mail-prsvr mail-utils tooltip eldoc electric uniquify ediff-hook vc-hooks lisp-float-type mwheel term/ns-win ns-win ucs-normalize mule-util term/common-win tool-bar dnd fontset image regexp-opt fringe tabulated-list replace newcomment text-mode elisp-mode lisp-mode prog-mode register page tab-bar menu-bar rfn-eshadow isearch timer select scroll-bar mouse jit-lock font-lock syntax facemenu font-core term/tty-colors frame minibuffer cl-generic cham georgian utf-8-lang misc-lang vietnamese tibetan thai tai-viet lao korean japanese eucjp-ms cp51932 hebrew greek romanian slovak czech european ethiopic indian cyrillic chinese composite charscript charprop case-table epa-hook jka-cmpr-hook help simple abbrev obarray cl-preloaded nadvice loaddefs button faces cus-face macroexp files text-properties overlay sha1 md5 base64 format env code-pages mule custom widget hashtable-print-readable backquote threads kqueue cocoa ns lcms2 multi-tty make-network-process emacs) Memory information: ((conses 16 44008 8151) (symbols 48 5908 1) (strings 32 15290 1605) (string-bytes 1 499152) (vectors 16 9324) (vector-slots 8 119382 11662) (floats 8 19 25) (intervals 56 177 0) (buffers 1000 12)) --Apple-Mail=_F4073758-4BA9-4C69-86EE-2510F46E593E Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 If I pass a LIMIT > point-max = to next-single-char-property-change, Emacs hangs. Of course, I = shouldn=E2=80=99t pass such a bad argument, = but next-single-char-property-change should probably error out = instead of hanging in a infinite loop IMHO.

Here is the relevant C code:

while (true)
=  {
=    position =3D Fnext_char_property_change (position, = limit);
=    if (XFIXNAT (position) >=3D XFIXNAT = (limit))
=      {
position =3D = limit;
= break;
=      }

  =  value =3D Fget_char_property (position, prop, = object);
=    if (!EQ (value, initial_value))
  =    break;
=  }

If it = gets a LIMIT larger than point-max, position can never =3D=3D limit, so = it will loop in the while loop infinitely. I would add a check in the = beginning of the function, to signal an out-of-range error. Or maybe set = limit to poin-max quietly. Other similar functions could have the same = problem, previous-single-char-property-change comes to my = mind.

Yuan

In GNU Emacs 27.0.60 (build 1, = x86_64-apple-darwin19.3.0, NS appkit-1894.30 Version 10.15.3 (Build = 19D76))
of 2020-02-25 built on missSilver
Repository revision: = f27187f963e9e36435b508e29256e048799e0ff2
Repository = branch: emacs-27
Windowing system distributor 'Apple', = version 10.3.1894
System Description:  Mac OS X 10.15.3

Recent messages:
For information = about GNU Emacs and the GNU system, type C-h C-a.

Configured using:
'configure --with-modules = --with-pdumper=3Dyes
= --oldincludedir=3D/Applications/Xcode.app/Contents/Developer/Platforms/Mac= OSX.platform/Developer/SDKs/MacOSX.sdk/usr/include/libxml2/'

Configured features:
RSVG GLIB = NOTIFY KQUEUE ACL GNUTLS LIBXML2 ZLIB TOOLKIT_SCROLL_BARS XIM
NS MODULES THREADS PDUMPER LCMS2

Important settings:
  value of $LC_CTYPE: = UTF-8
  = value of $LANG: en_CN.UTF-8
  locale-coding-system: = utf-8-unix

Major mode: Fundamental

Minor modes in effect:
  tooltip-mode: t
  = global-eldoc-mode: t
  electric-indent-mode: t
  = mouse-wheel-mode: t
  tool-bar-mode: t
  = menu-bar-mode: t
  file-name-shadow-mode: = t
  = global-font-lock-mode: t
  blink-cursor-mode: t
  = auto-composition-mode: t
  auto-encryption-mode: t
  = auto-compression-mode: t
  buffer-read-only: t
  = line-number-mode: t
  transient-mark-mode: t

Load-path shadows:
None = found.

Features:
(shadow sort = mail-extr emacsbug message rmc puny dired dired-loaddefs
format-spec rfc822 mml easymenu mml-sec password-cache epa = derived epg
epg-config gnus-util rmail rmail-loaddefs = text-property-search time-date
subr-x seq byte-opt gv = bytecomp byte-compile cconv mm-decode mm-bodies
mm-encode = mail-parse rfc2231 mailabbrev gmm-utils mailheader cl-loaddefs
cl-lib sendmail rfc2047 rfc2045 ietf-drums mm-util mail-prsvr = mail-utils
tooltip eldoc electric uniquify ediff-hook = vc-hooks lisp-float-type
mwheel term/ns-win ns-win = ucs-normalize mule-util term/common-win
tool-bar dnd = fontset image regexp-opt fringe tabulated-list replace
newcomment text-mode elisp-mode lisp-mode prog-mode register = page
tab-bar menu-bar rfn-eshadow isearch timer select = scroll-bar mouse
jit-lock font-lock syntax facemenu = font-core term/tty-colors frame
minibuffer cl-generic cham = georgian utf-8-lang misc-lang vietnamese
tibetan thai = tai-viet lao korean japanese eucjp-ms cp51932 hebrew greek
romanian slovak czech european ethiopic indian cyrillic = chinese
composite charscript charprop case-table epa-hook = jka-cmpr-hook help
simple abbrev obarray cl-preloaded = nadvice loaddefs button faces
cus-face macroexp files = text-properties overlay sha1 md5 base64 format
env = code-pages mule custom widget hashtable-print-readable backquote
threads kqueue cocoa ns lcms2 multi-tty make-network-process = emacs)

Memory information:
((conses 16 44008 8151)
(symbols 48 5908 1)
(strings 32 15290 1605)
(string-bytes 1 = 499152)
(vectors 16 9324)
(vector-slots 8 = 119382 11662)
(floats 8 19 25)
(intervals = 56 177 0)
(buffers 1000 12))
= --Apple-Mail=_F4073758-4BA9-4C69-86EE-2510F46E593E--