Update of bug #68682 (group groff):
Status: In Progress => Fixed
Privacy: Private => Public
Open/Closed: Open => Closed
_______________________________________________________
Follow-up Comment #2:
commit 879108fbd1fb02a71a5419485384da7f3b7eab9f
Author: G. Branden Robinson <[email protected]>
Date: Thu Sep 17 20:11:08 2026 -0500
[refer]: Regression-test Savannah #68682.
* src/preproc/refer/tests/check-index-file-validity.sh: Do it.
Test fails at this commit.
commit 0f9635654f74897052f979700f35aa5d853f72ee
Author: G. Branden Robinson <[email protected]>
Date: Thu Sep 17 20:12:48 2026 -0500
[libbib]: Fix Savannah #68682 (1/2).
* src/libs/libbib/index.cpp (index_search_item::get_invalidity_reason):
Check index of file name for nonsense (nonpositive) value, and reject
it if has one. This prevents us from an out-of-bounds read of the
(memory-mapped) index file.
Fixes <https://savannah.gnu.org/bugs/?68682> (1/2). Thanks to Pavol
Sloboda for the report and analysis. Problem dates back to groff's
birth. (And I didn't catch it when doing the work for commit
1b97881fc0, 2021-09-12.)
Test still fails at this commit.
commit cd999c60023ef7d4cc48b46561856e93a0abf711
Author: G. Branden Robinson <[email protected]>
Date: Thu Sep 17 20:12:57 2026 -0500
[libbib]: Fix Savannah #68682 (2/2).
* src/libs/libbib/index.cpp
(index_search_item_iterator::index_search_item_iterator): Add
`found_list` to initializer list, making it a null pointer, because
the file name index might not be valid. Thus, bracket the entire
function body on the condition `ind->is_valid()`.
Fixes <https://savannah.gnu.org/bugs/?68682> (2/2).
_______________________________________________________
Reply to this item at:
<https://savannah.gnu.org/bugs/?68682>
_______________________________________________
Message sent via Savannah
https://savannah.gnu.org/
signature.asc
Description: PGP signature
