| Ticket UUID: | 85fc8bca030ecf2656929cc0a222145a57cca8b2 | ||
| Title: | Pointer arithmetic with NULL in buildInfoObjCmd() | ||
| Type: | Bug | Created on: | 2025-08-31 22:50:10 |
| Submitter: | chrstphrchvz | Assigned to: | jan.nijtmans |
| Subsystem: | 54. Configuration Reporting | Severity: | Minor |
| Priority: | 5 Medium | Last modified: | 2025-09-01 07:29:01 |
| Status: | Closed | Closed by: | jan.nijtmans |
| Resolution: | Fixed | Closed on: | 2025-09-01 07:29:01 |
| Version: | 9.0 | ||
| Description: | ||||
|
Example UBSan error for the default case:
% tcl::build-info boneless
tclBasic.c:755:36: runtime error: applying non-zero offset 1 to null pointer
0
The error is due to p++ being used as the for loop condition. I believe there is an instance of this in the ID_COMPILER case as well. One possible fix:
--- generic/tclBasic.c
+++ generic/tclBasic.c
@@ -731,7 +731,8 @@
}
return TCL_OK;
case ID_COMPILER:
- for (p = strchr(buildData, '.'); p++; p = strchr(p, '.')) {
+ for (p = strchr(buildData, '.'); p != NULL; p = strchr(p, '.')) {
+ p++;
/*
* Does the word begin with one of the standard prefixes?
*/
@@ -752,7 +753,8 @@
break;
default: /* Boolean test for other identifiers' presence */
arg = TclGetStringFromObj(objv[1], &len);
- for (p = strchr(buildData, '.'); p++; p = strchr(p, '.')) {
+ for (p = strchr(buildData, '.'); p != NULL; p = strchr(p, '.')) {
+ p++;
if (!strncmp(p, arg, len)
&& ((p[len] == '.') || (p[len] == '-') || (p[len] == '\0'))) {
if (p[len] == '-') {
| ||||
| User Comments: | ||||
jan.nijtmans added on 2025-09-01 07:29:01:
Fixed [6d62aed3e5980b48|here] Thanks for the report and the fix! | ||||
