Fw: Bug#180914: sed: Another .* crash

Bonzini bonzini@gnu.org
Sat Feb 15 13:33:00 GMT 2003


> Are you looking into this ATM?

A NULL pointer is obtained from mctx->state_log[*pidx]->node_set in
proceed_next_node and dereferenced in re_node_set_contains.  But I did not
go much further, I find the complexity of the matcher overwhelming; the
algorithms used (or at least the purpose of the functions!) ought to be
described somewhere.

However, I've tried to extract a test case from it using re_search and
re_compile_pattern, and I did not succeed.  So I removed knowledge of
internal regex functions (re_search_internal and re_compile_internal) from
sed and to my surprise it fixed the bug.  I will try distilling a test case
that uses regcomp and regexec, and if this also fails, then it was sed's
bug.

> Also, I couldn't find a configure option to build sed with glibc regex
> instead of its own while it used to be there in sed 3.x.

It will be there in 4.0.6, to be expected at the beginning of March.  I just
don't have time to do pre-release testing of the new version on at least
three or four architectures.

Paolo




More information about the Libc-alpha mailing list