Tcl Source Code

View Ticket
Login
Ticket UUID: 85fc8bca030ecf2656929cc0a222145a57cca8b2
Title: Pointer arithmetic with NULL in buildInfoObjCmd()
Type: Bug Created on: 2025-08-31 22:50:10
Submitter: chrstphrchvz Assigned to: jan.nijtmans
Subsystem: 54. Configuration Reporting Severity: Minor
Priority: 5 Medium Last modified: 2025-09-01 07:29:01
Status: Closed Closed by: jan.nijtmans
Resolution: Fixed Closed on: 2025-09-01 07:29:01
Version: 9.0
Description:

Example UBSan error for the default case:

% tcl::build-info boneless
tclBasic.c:755:36: runtime error: applying non-zero offset 1 to null pointer
0

The error is due to p++ being used as the for loop condition. I believe there is an instance of this in the ID_COMPILER case as well. One possible fix:

--- generic/tclBasic.c
+++ generic/tclBasic.c
@@ -731,7 +731,8 @@
 	}
 	return TCL_OK;
     case ID_COMPILER:
-	for (p = strchr(buildData, '.'); p++; p = strchr(p, '.')) {
+	for (p = strchr(buildData, '.'); p != NULL; p = strchr(p, '.')) {
+	    p++;
 	    /*
 	     * Does the word begin with one of the standard prefixes?
 	     */
@@ -752,7 +753,8 @@
 	break;
     default:		/* Boolean test for other identifiers' presence */
 	arg = TclGetStringFromObj(objv[1], &len);
-	for (p = strchr(buildData, '.'); p++; p = strchr(p, '.')) {
+	for (p = strchr(buildData, '.'); p != NULL; p = strchr(p, '.')) {
+	    p++;
 	    if (!strncmp(p, arg, len)
 		    && ((p[len] == '.') || (p[len] == '-') || (p[len] == '\0'))) {
 		if (p[len] == '-') {

User Comments:
jan.nijtmans added on 2025-09-01 07:29:01:

Fixed [6d62aed3e5980b48|here]

Thanks for the report and the fix!