URL: <https://savannah.gnu.org/bugs/?68720>
Summary: [pic,troff,libgroff] add stronger guards against
giant memory allocations
Group: GNU roff
Submitter: gbranden
Submitted: Sun 27 Sep 2026 11:26:44 PM UTC
Category: General
Severity: 3 - Normal
Item Group: Refactoring
Status: Confirmed
Privacy: Public
Assigned to: None
Open/Closed: Open
Discussion Lock: Unlocked
Planned Release: None
_______________________________________________________
Follow-up Comments:
-------------------------------------------------------
Date: Sun 27 Sep 2026 11:26:44 PM UTC By: G. Branden Robinson <gbranden>
Building _groff_ with GCC 12 provokes some squawks.
src/preproc/pic/object.cpp: In member function ‘make_line.constprop’:
src/preproc/pic/object.cpp:1666:39: warning: argument 1 value
‘18446744073709551615’ exceeds maximum object size 9223372036854775807
[-Walloc-size-larger-than=]
1666 | position *v = new position[nsegments];
| ^
src/preproc/pic/object.cpp:1666:39: note: in a call to built-in allocation
function ‘operator new []’
In member function ‘__ct ’,
inlined from ‘get_width’ at src/libs/libgroff/font.cpp:436:62:
src/libs/libgroff/font.cpp:387:26: warning: argument 1 value
‘18446744073709551615’ exceeds maximum object size 9223372036854775807
[-Walloc-size-larger-than=]
387 | width = new int[ch_size];
| ^
/usr/include/c++/12/new: In member function ‘get_width’:
/usr/include/c++/12/new:128:26: note: in a call to allocation function
‘operator new []’ declared here
128 | _GLIBCXX_NODISCARD void* operator new[](std::size_t) _GLIBCXX_THROW
(std::bad_alloc)
| ^
In member function ‘__ct ’,
inlined from ‘get_width’ at src/libs/libgroff/font.cpp:450:23:
src/libs/libgroff/font.cpp:387:26: warning: argument 1 value
‘18446744073709551615’ exceeds maximum object size 9223372036854775807
[-Walloc-size-larger-than=]
387 | width = new int[ch_size];
| ^
/usr/include/c++/12/new: In member function ‘get_width’:
/usr/include/c++/12/new:128:26: note: in a call to allocation function
‘operator new []’ declared here
128 | _GLIBCXX_NODISCARD void* operator new[](std::size_t) _GLIBCXX_THROW
(std::bad_alloc)
| ^
CXXLD troff
src/roff/troff/input.cpp: In function ‘read_drawing_command’:
src/roff/troff/input.cpp:10643:43: warning: argument 1 value
‘18446744073709551615’ exceeds maximum object size 9223372036854775807
[-Walloc-size-larger-than=]
10643 | point = new hvpair[maxpoints * 2];
| ^
src/roff/troff/input.cpp:10643:43: note: in a call to built-in allocation
function ‘operator new []’
In member function ‘__ct ’,
inlined from ‘read_drawing_command’ at
src/roff/troff/input.cpp:10725:35:
src/roff/troff/node.cpp:5134:29: warning: argument 1 value
‘18446744073709551615’ exceeds maximum object size 9223372036854775807
[-Walloc-size-larger-than=]
5134 | point = new hvpair[npoints];
| ^
src/roff/troff/node.cpp:5134:29: note: in a call to built-in allocation
function ‘operator new []’
src/roff/troff/node.cpp: In function ‘grow_font_table’:
src/roff/troff/node.cpp:6657:47: warning: argument 1 value
‘18446744073709551615’ exceeds maximum object size 9223372036854775807
[-Walloc-size-larger-than=]
6657 | font_table = new font_info *[font_table_size];
| ^
src/roff/troff/node.cpp:6657:47: note: in a call to built-in allocation
function ‘operator new []’
In member function ‘__ct ’,
inlined from ‘init_output’ at src/roff/troff/node.cpp:7635:22:
src/roff/troff/node.cpp:1701:62: warning: argument 1 value
‘18446744073709551615’ exceeds maximum object size 9223372036854775807
[-Walloc-size-larger-than=]
1701 | font_mounting_position = new symbol[mounting_position_count];
| ^
src/roff/troff/node.cpp:1701:62: note: in a call to built-in allocation
function ‘operator new []’
src/roff/troff/node.cpp: In member function ‘select_font’:
src/roff/troff/node.cpp:1280:66: warning: argument 1 value
‘18446744073709551615’ exceeds maximum object size 9223372036854775807
[-Walloc-size-larger-than=]
1280 | font_mounting_position = new symbol[mounting_position_count];
| ^
src/roff/troff/node.cpp:1280:66: note: in a call to built-in allocation
function ‘operator new []’
In member function ‘__ct ’,
inlined from ‘get_width’ at src/libs/libgroff/font.cpp:436:62:
src/libs/libgroff/font.cpp:387:26: warning: argument 1 value
‘18446744073709551615’ exceeds maximum object size 9223372036854775807
[-Walloc-size-larger-than=]
387 | width = new int[ch_size];
| ^
src/libs/libgroff/font.cpp:387:26: note: in a call to built-in allocation
function ‘operator new []’
In member function ‘__ct ’,
inlined from ‘get_width’ at src/libs/libgroff/font.cpp:450:23:
src/libs/libgroff/font.cpp:387:26: warning: argument 1 value
‘18446744073709551615’ exceeds maximum object size 9223372036854775807
[-Walloc-size-larger-than=]
387 | width = new int[ch_size];
| ^
src/libs/libgroff/font.cpp:387:26: note: in a call to built-in allocation
function ‘operator new []’
In member function ‘__ct ’,
inlined from ‘copy’ at src/roff/troff/node.cpp:5218:24:
src/roff/troff/node.cpp:5144:29: warning: argument 1 value
‘18446744073709551615’ exceeds maximum object size 9223372036854775807
[-Walloc-size-larger-than=]
5144 | point = new hvpair[npoints];
| ^
src/roff/troff/node.cpp:5144:29: note: in a call to built-in allocation
function ‘operator new []’
Sampling these, the variables getting passed as array sizes seem not to be
uninitialized, so I guess GCC's static analyzer is concerned that we might be
incrementing them in a poorly bounded loop or similar.
Clean this stuff up for _groff_ 1.26 or _maybe_ 1.25.
_______________________________________________________
Reply to this item at:
<https://savannah.gnu.org/bugs/?68720>
_______________________________________________
Message sent via Savannah
https://savannah.gnu.org/
signature.asc
Description: PGP signature
