fprintf() crashes on wide-oriented stream.
Brian Inglis
Brian.Inglis@Shaw.ca
Mon Nov 6 18:26:52 GMT 2023
On 2023-11-02 12:53, Corinna Vinschen wrote:
> On Oct 4 16:16, Jeff Johnston wrote:
>> I finally took a look at this. The issue is whether POSIX compliance is
>> desired. Corinna would have strong opinions that it is desired and thus,
>> I think she should have her say when she gets back. I personally believe
>> that newlib should have behaved like glibc.
> I took a look into the POSIX docs. POSIX aligns with ISO/IEC 9899:1999.
> The description is slightly vague, in that it only has to say this:
> "Byte input/output functions cannot be applied to a wide-oriented
> stream, and wide-character input/output functions cannot be applied to
> a byte-oriented stream."
> It does not explicitely outline what "cannot be applied" means in this
> context.
That seems to me to imply that the compiler /could/ diagnose if oriented stream
functions are used consistently, and that those explicitly byte- or
wide-oriented stream I/O functions should check the orientation and fail, or do
nothing, unless they are required to be flexible like the perror/psig...
functions mentioned below, to adapt and not change the stream orientation.
> IIUC, this *could* mean that in case of the testcase a crash is as much
> standards-compliant as the GLibC behaviour. Not that a crash is desired,
> of course...
> In how far the BSD behaviour is covered by this description, I really
> can't tell.
> I wonder if the Austin group could clarify, or if a clarification
> already exists and I just missed it. CC Eric, in case he wants to
> follow up on this.
> Either way, I think that the safe way forward is actually to behave
> as GLibC does.
As far as I could see, the only obvious changes are tweaks for exceptions about
open_wmemstream.
It also looks like errno should be set to EBADF to indicate that the operation
is invalid for the stream.
>> I also think the test snippet is invalid and should have performed an fwide
>> call on stdout to reset the wide-orientation and have the code work
>> properly in all cases.
That should not be necessary, as the first byte- or wide-oriented stream I/O
function called against the stream after fopen or freopen sets the orientation
from unoriented; that includes fwide() if called with a non-zero argument;
otherwise fwide() may query the stream orientation but not change it after it is
set.
> In terms of ISO/IEC 9899:1999 I agree. However, it also shows the
> flaw that newlib crashes with a buffer overflow, which we should
> avoid if possible.
Also note from Takashi's issue raised by Eric 5 years ago, perror(), psignal(),
and psiginfo() "shall not change the orientation of the standard error stream":
https://collaboration.opengroup.org/operational/mailarch.php?soph=N&action=show&archive=austin-group-l&num=27231&limit=100&offset=9400&sid=
https://www.mail-archive.com/austin-group-l@opengroup.org/msg02582.html
--
Take care. Thanks, Brian Inglis Calgary, Alberta, Canada
La perfection est atteinte Perfection is achieved
non pas lorsqu'il n'y a plus rien à ajouter not when there is no more to add
mais lorsqu'il n'y a plus rien à retirer but when there is no more to cut
-- Antoine de Saint-Exupéry
More information about the Newlib
mailing list