From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Paul Eggert Newsgroups: gmane.emacs.bugs Subject: bug#31556: 27.0.50; Reading a certain invalid bytecode object triggers an assertion Date: Tue, 22 May 2018 12:45:12 -0700 Organization: UCLA Computer Science Department Message-ID: <45809362-9611-032a-f4cd-84c9e12f5ebc@cs.ucla.edu> References: NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="------------F0770807F4987F07B05C567C" X-Trace: blaine.gmane.org 1527018247 19955 195.159.176.226 (22 May 2018 19:44:07 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Tue, 22 May 2018 19:44:07 +0000 (UTC) User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.7.0 Cc: 31556-done@debbugs.gnu.org, Pip Cet To: Philipp Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Tue May 22 21:44:03 2018 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1fLDCV-00053h-4H for geb-bug-gnu-emacs@m.gmane.org; Tue, 22 May 2018 21:44:03 +0200 Original-Received: from localhost ([::1]:57603 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fLDEc-00021C-9j for geb-bug-gnu-emacs@m.gmane.org; Tue, 22 May 2018 15:46:14 -0400 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:37866) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fLDEV-000202-8B for bug-gnu-emacs@gnu.org; Tue, 22 May 2018 15:46:08 -0400 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fLDEQ-0007ke-BH for bug-gnu-emacs@gnu.org; Tue, 22 May 2018 15:46:07 -0400 Original-Received: from debbugs.gnu.org ([208.118.235.43]:36606) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1fLDEQ-0007kQ-5z for bug-gnu-emacs@gnu.org; Tue, 22 May 2018 15:46:02 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1fLDEQ-0002t8-0f for bug-gnu-emacs@gnu.org; Tue, 22 May 2018 15:46:02 -0400 In-Reply-To: Resent-From: Paul Eggert Original-Sender: "Debbugs-submit" Resent-To: bug-gnu-emacs@gnu.org Resent-Date: Tue, 22 May 2018 19:46:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: cc-closed 31556 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: Mail-Followup-To: 31556@debbugs.gnu.org, eggert@cs.ucla.edu, p.stephani2@gmail.com Original-Received: via spool by 31556-done@debbugs.gnu.org id=D31556.152701832311046 (code D ref 31556); Tue, 22 May 2018 19:46:01 +0000 Original-Received: (at 31556-done) by debbugs.gnu.org; 22 May 2018 19:45:23 +0000 Original-Received: from localhost ([127.0.0.1]:44502 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1fLDDn-0002s5-JZ for submit@debbugs.gnu.org; Tue, 22 May 2018 15:45:23 -0400 Original-Received: from zimbra.cs.ucla.edu ([131.179.128.68]:32800) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1fLDDj-0002rs-JL for 31556-done@debbugs.gnu.org; Tue, 22 May 2018 15:45:22 -0400 Original-Received: from localhost (localhost [127.0.0.1]) by zimbra.cs.ucla.edu (Postfix) with ESMTP id 347191601D4; Tue, 22 May 2018 12:45:13 -0700 (PDT) Original-Received: from zimbra.cs.ucla.edu ([127.0.0.1]) by localhost (zimbra.cs.ucla.edu [127.0.0.1]) (amavisd-new, port 10032) with ESMTP id p9DsJcnS3Xop; Tue, 22 May 2018 12:45:12 -0700 (PDT) Original-Received: from localhost (localhost [127.0.0.1]) by zimbra.cs.ucla.edu (Postfix) with ESMTP id 45A85160516; Tue, 22 May 2018 12:45:12 -0700 (PDT) X-Virus-Scanned: amavisd-new at zimbra.cs.ucla.edu Original-Received: from zimbra.cs.ucla.edu ([127.0.0.1]) by localhost (zimbra.cs.ucla.edu [127.0.0.1]) (amavisd-new, port 10026) with ESMTP id YYRyC4nnAQlF; Tue, 22 May 2018 12:45:12 -0700 (PDT) Original-Received: from Penguin.CS.UCLA.EDU (Penguin.CS.UCLA.EDU [131.179.64.200]) by zimbra.cs.ucla.edu (Postfix) with ESMTPSA id 265191601D4; Tue, 22 May 2018 12:45:12 -0700 (PDT) Content-Language: en-US X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 208.118.235.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.org gmane.emacs.bugs:146403 Archived-At: This is a multi-part message in MIME format. --------------F0770807F4987F07B05C567C Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit Thanks for reporting that. I installed the attached to fix it. If you see similar bugs in this area, please let us know. --------------F0770807F4987F07B05C567C Content-Type: text/x-patch; name="0001-Fix-failed-assertion-when-load-force-doc-strings.patch" Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename*0="0001-Fix-failed-assertion-when-load-force-doc-strings.patch" >From f47a28e686706290008c9c0e5ee3a2f241d6acae Mon Sep 17 00:00:00 2001 From: Paul Eggert Date: Tue, 22 May 2018 12:26:22 -0700 Subject: [PATCH] Fix failed assertion when load-force-doc-strings Problem reported by Philipp Stephani (Bug#31556). * src/lread.c (read_vector): When load_force_doc_strings, check for byte code vectors that are invalid because they are too short. * test/src/lread-tests.el (lread-invalid-bytecodes): New test. --- src/lread.c | 4 +++- test/src/lread-tests.el | 4 ++++ 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/src/lread.c b/src/lread.c index b8db117c79..239c66ccb8 100644 --- a/src/lread.c +++ b/src/lread.c @@ -3829,9 +3829,11 @@ read_vector (Lisp_Object readcharfun, bool bytecodeflag) tem = read_list (1, readcharfun); len = Flength (tem); + if (bytecodeflag && XFASTINT (len) <= COMPILED_STACK_DEPTH) + error ("Invalid byte code"); vector = Fmake_vector (len, Qnil); - size = ASIZE (vector); + size = XFASTINT (len); ptr = XVECTOR (vector)->contents; for (i = 0; i < size; i++) { diff --git a/test/src/lread-tests.el b/test/src/lread-tests.el index 647e886d34..639a6da93a 100644 --- a/test/src/lread-tests.el +++ b/test/src/lread-tests.el @@ -207,4 +207,8 @@ lread-tests--last-message ;; bug was fixed. (eval-buffer)))) +(ert-deftest lread-invalid-bytecodes () + (should-error + (let ((load-force-doc-strings t)) (read "#[0 \"\"]")))) + ;;; lread-tests.el ends here -- 2.17.0 --------------F0770807F4987F07B05C567C--