Attached debdiff cfortran_20210827-1.1ubuntu1 for stonking. Changes: - debian/rules: pass -std=gnu17 in DEB_CFLAGS_MAINT_APPEND to restore C17 function prototype semantics for the package testsuite under GCC 15. - debian/patches/0002-fix-fstr-test-buffer-overflow.patch: allocate + 1 byte in eg/fstr/fstr.c to fix heap buffer overflow when strcpy writes the terminating NUL byte under _FORTIFY_SOURCE=3.
Tested on Ubuntu stonking (GCC 15.2.0, glibc 2.43): - dpkg-buildpackage builds cleanly. - dh_auto_test passes all 41 testsuites in eg/ (abc, cf14, e2, easy, eq, f0, f20, f27, fa, fb, fc, fcb, fd, fe, ff, fg, fh, fi, fj, fk, fl, fm, fn, forr, fstr, ft, fun, fz, pz, q, rev, rr, ss1, strtok, sub, subt, sz, sz1, user, v7, vv). - cfortran_20210827-1.1ubuntu1_all.deb package generated successfully. Forwarded to Debian BTS: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1114078 Upstream PR for buffer overflow: https://github.com/bastien-roucaries/cfortran/pull/3 ** Description changed: + [ Impact ] + cfortran 20210827-1.1 fails to build from source (FTBFS) in Ubuntu stonking under GCC 15. This blocks cfortran from migrating to stonking and holds up autopkgtests for reverse dependencies. + + During package build, the testsuite fails with two distinct errors: + 1. GCC 15 defaults to C23, where empty parameter lists in prototypes mean strictly 0 arguments. The package testsuite exercises function pointer casts and legacy wrappers, failing with: + e2/e2.c:10:28: error: too many arguments to function 'easy_'; expected 0, have 2 + q/q.c:15: error: passing 'int (*)(void)' to parameter of type '__compar_fn_t' + 2. Under default Ubuntu -D_FORTIFY_SOURCE=3, eg/fstr/fstr.c triggers heap buffer overflow termination because malloc(ls>lsave?ls:lsave) misses + 1 byte for the terminating NUL byte before strcpy. + + [ Fix ] + 1. debian/rules: pass export DEB_CFLAGS_MAINT_APPEND = -std=gnu17 so the internal testsuite builds with C17 semantics. + 2. debian/patches/0002-fix-fstr-test-buffer-overflow.patch: allocate + 1 byte in eg/fstr/fstr.c to accommodate the terminating NUL byte under _FORTIFY_SOURCE=3. + + [ Test Plan ] + 1. Build cfortran in stonking container with GCC 15: + dpkg-buildpackage -us -uc -b + 2. Verify all test binaries in eg/ are compiled and executed during dh_auto_test: + abc, cf14, e2, easy, eq, f0, f20, f27, fa, fb, fc, fcb, fd, fe, ff, fg, fh, fi, fj, fk, fl, fm, fn, forr, fstr, ft, fun, fz, pz, q, rev, rr, ss1, strtok, sub, subt, sz, sz1, user, v7, vv. + 3. Verify test exit code is 0 and cfortran_20210827-1.1ubuntu1_all.deb is generated cleanly. + + [ Where problems could occur ] + - Scope is minimal: cfortran is an Architecture: all package distributing the header file /usr/include/cfortran/cfortran.h and examples. + - -std=gnu17 is appended to DEB_CFLAGS_MAINT_APPEND in debian/rules, affecting only the package build and its internal testsuite, with zero adverse impact on installed header files. + - The fstr test patch only affects the example test executable. + + [ Other Info ] + - Debian Bug: #1114078 (https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1114078). Patch forwarded to Debian BTS. + - Upstream PR for buffer overflow: https://github.com/bastien-roucaries/cfortran/pull/3 + - Target series: stonking (Ubuntu 26.10 devel series). + - All 41 testsuites pass with 0 regressions. + + --- [ Original Report ] cfortran 20210827-1.1 fails to build from source in stonking. Regressing architectures (built before, fail now): amd64. Build log(s): - https://launchpad.net/ubuntu/+source/cfortran/20210827-1.1/+build/32793393/+files/buildlog_ubuntu-stonking-amd64.cfortran_20210827-1.1_BUILDING.txt.gz - Diagnosis (deterministic matcher): testsuite-failure — dh_auto_test. + Diagnosis (deterministic matcher): testsuite-failure - dh_auto_test. Root cause: GCC 15 defaults to C23, where an empty parameter list `()` means "no arguments". cfortran.h's PROTOCCALLSFFUN* macros (PROTOCCALLSFFUN2 -> VOID_cfG -> VOID_cfGZ -> CFC_, cfortran.h:1482/1494) declare Fortran routines as e.g. `easy_()` and then call them with arguments, so `make check` fails: e2/e2.c:10:28: error: too many arguments to function 'easy_'; expected 0, have 2 This is a toolchain-induced regression (20210827-1 last built with an older GCC); the source itself did not change in a relevant way. Existing reports: - Debian: https://bugs.debian.org/1114078 (serious, same error) - Debian (autopkgtest, same root cause): https://bugs.debian.org/1119857 - Upstream: https://github.com/bastien-roucaries/cfortran/issues/2 (open, no fix) - Possibly also needed afterwards: https://github.com/bastien-roucaries/cfortran/pull/3 (fstr_test coredump with -D_FORTIFY_SOURCE=3 -O2) Suggested workaround: build with -std=gnu17, e.g. export DEB_CFLAGS_MAINT_APPEND = -std=gnu17 in debian/rules. Since cfortran.h is a header consumed by reverse dependencies, a proper fix needs cfortran.h to emit full prototypes. The autopkgtest block ("arch:all not built yet") will clear once the package builds. ** Changed in: cfortran (Ubuntu) Status: New => Confirmed ** Tags added: patch ** Patch added: "cfortran 20210827-1.1ubuntu1 debdiff for stonking" https://bugs.launchpad.net/ubuntu/+source/cfortran/+bug/2168915/+attachment/6005168/+files/cfortran_20210827-1.1ubuntu1.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2168915 Title: cfortran 20210827-1.1 FTBFS: C23 (GCC 15) rejects K&R-style prototypes in cfortran.h To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/cfortran/+bug/2168915/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
