From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: Gerd =?UTF-8?Q?M=C3=B6llmann?= Newsgroups: gmane.emacs.bugs Subject: bug#58334: 29.0.50; ASAN heap use after free in gui_produce_glyphs Date: Fri, 07 Oct 2022 13:29:38 +0200 Message-ID: References: <87mta8qx48.fsf@yahoo.com> <83v8ownmi1.fsf@gnu.org> <83r0zjopre.fsf@gnu.org> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="2804"; mail-complaints-to="usenet@ciao.gmane.io" User-Agent: Gnus/5.13 (Gnus v5.13) Cc: luangruo@yahoo.com, 58334@debbugs.gnu.org To: Eli Zaretskii Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Fri Oct 07 15:27:18 2022 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1ognNl-0000Vp-VH for geb-bug-gnu-emacs@m.gmane-mx.org; Fri, 07 Oct 2022 15:27:17 +0200 Original-Received: from localhost ([::1]:49332 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1ognNk-00062Q-PT for geb-bug-gnu-emacs@m.gmane-mx.org; Fri, 07 Oct 2022 09:27:16 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]:49336) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1oglYJ-0003ww-GV for bug-gnu-emacs@gnu.org; Fri, 07 Oct 2022 07:30:03 -0400 Original-Received: from debbugs.gnu.org ([209.51.188.43]:35448) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1oglYJ-00027u-3L for bug-gnu-emacs@gnu.org; Fri, 07 Oct 2022 07:30:03 -0400 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1oglYI-0000uA-U6 for bug-gnu-emacs@gnu.org; Fri, 07 Oct 2022 07:30:02 -0400 X-Loop: help-debbugs@gnu.org Resent-From: Gerd =?UTF-8?Q?M=C3=B6llmann?= Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Fri, 07 Oct 2022 11:30:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 58334 X-GNU-PR-Package: emacs Original-Received: via spool by 58334-submit@debbugs.gnu.org id=B58334.16651421873362 (code B ref 58334); Fri, 07 Oct 2022 11:30:02 +0000 Original-Received: (at 58334) by debbugs.gnu.org; 7 Oct 2022 11:29:47 +0000 Original-Received: from localhost ([127.0.0.1]:34525 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1oglY2-0000sA-QX for submit@debbugs.gnu.org; Fri, 07 Oct 2022 07:29:47 -0400 Original-Received: from mail-ed1-f48.google.com ([209.85.208.48]:44900) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1oglY2-0000rx-1P for 58334@debbugs.gnu.org; Fri, 07 Oct 2022 07:29:46 -0400 Original-Received: by mail-ed1-f48.google.com with SMTP id g27so6572192edf.11 for <58334@debbugs.gnu.org>; Fri, 07 Oct 2022 04:29:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=content-transfer-encoding:mime-version:user-agent:message-id:date :references:in-reply-to:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=CFeYcESFSJNRG+cZYIiikiqLJ8roSldTupupPJ2bHDE=; b=enRViIhrVEeufC7dliVRUdUnctah1mOrlaXQAV38BSjpS5hLftysIa8nxTg4018ulG nQHifWX4uHWvju9m70XBXzxDzL2Cfw3Siy/0JUvXm90uuG7R4PAqLcVknVAXpxiQuzor /ZNKAAKq43lZ47Mgu4hx7iphjQ8DTqaK/ZMan8xQufhp2fmUylKbdU1Eaobmg+iADfeE n3UaFDYc2jRXXeZOPkRMIV6tYCULvwgojPNqw4HRSxTDnmShLVr66lT6GmYiK8S/7SkK xCrHHMGnk3vapc5fpI+yuEHj+0OSCuAZopciO4gN6YIQ8xbGBsEFO4+WQDWvQOViMfEb pe1Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=content-transfer-encoding:mime-version:user-agent:message-id:date :references:in-reply-to:subject:cc:to:from:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=CFeYcESFSJNRG+cZYIiikiqLJ8roSldTupupPJ2bHDE=; b=XkvityQJK6KU6U0IR5EmmjoFkLaPnJbGFjPyAzHaXbqT6lZApXsNnsSuZLeuyRgPi4 zGhcHjcG16jnbhCSXQR26LjXPJvK9vAZAu3YhijCxQ/fOUxPqnWaY0R0kfIDxcs9+tki e7vLBcaY7lV1kZOYy/vUapuwVPkZjAboIx2Nfe70e4U/UYuRj/GbSqO3Q654t9B78zVx ktqGnytJhaWybLY0kqCS9MjKrKb0OA2qp48U8IPFrFc7sNNp8+6Azre834HF+td/TzZk YHeGThza3xHuggtSBpnNwRxvk+TQhYEbAp89FkFfMhRi35yA63jNPeRi6NKAi/nc3PPl iiYg== X-Gm-Message-State: ACrzQf2yWyklkxCqJCjPLDtVuNoU1b8WtQ+PvULgP2pmKzBTzVma+Qvo NlUUw2ILT2hS5V9Aw2RUlkQgS8LBihcDAw== X-Google-Smtp-Source: AMsMyM4MUpYB/vzHTsg56K8cDeMvuPmbIRwyi43a88e0Qf1UXd676ag08WwUqXGCiZoKgmJd3UBcDA== X-Received: by 2002:aa7:dd45:0:b0:458:7474:1fbe with SMTP id o5-20020aa7dd45000000b0045874741fbemr4114902edw.334.1665142179730; Fri, 07 Oct 2022 04:29:39 -0700 (PDT) Original-Received: from Mini.fritz.box (pd9e36c8d.dip0.t-ipconnect.de. [217.227.108.141]) by smtp.gmail.com with ESMTPSA id 13-20020a170906308d00b0078c1e174e11sm1073580ejv.136.2022.10.07.04.29.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 07 Oct 2022 04:29:39 -0700 (PDT) In-Reply-To: <83r0zjopre.fsf@gnu.org> (Eli Zaretskii's message of "Fri, 07 Oct 2022 14:08:05 +0300") X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane-mx.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.io gmane.emacs.bugs:244764 Archived-At: Eli Zaretskii writes: >> From: Gerd M=C3=B6llmann >> Cc: Po Lu , 58334@debbugs.gnu.org >> Date: Fri, 07 Oct 2022 10:07:01 +0200 >>=20 >> Gerd M=C3=B6llmann writes: >>=20 >> > Eli Zaretskii writes: >> >> IOW, I don't see how block_input anywhere can solve this particular >> >> problem. >> > >> > I wonder too. >>=20 >> And, while vaccuming, I also wondered what happens with the glyph >> matrices, and maybe other global state? > > Fvertical_motion (and other functions that call the move_it_* > functions) in general don't rely on glyph matrices. So I'm not sure > what exactly worries you. I not yet worried, just wondering :-). If we don't change some other shared state, then we're safe if we prevent freeing faces? That's would be good.