fixes for several bugs found via fuzzing: overflow in $'...' hex expansion; fix for accessing freed memory when reading input from stdin and using multiple redirections to stdin; fix for pointer aliasing problem after a syntax error while executing a command string

This commit is contained in:
Chet Ramey
2025-12-30 16:06:40 -05:00
parent 722a855459
commit 4b27601dfd
10 changed files with 235 additions and 11 deletions
+36
View File
@@ -403,3 +403,39 @@ EOF
5 echo three
history10.sub
1 echo first
2 echo one
3 echo two
4 echo three
5 echo x
6 echo y
7 echo z
8 echo last
echo one append
one append
echo two append
two append
echo three append
three append
1 echo first
2 echo x
3 echo y
4 echo z
5 echo last
6 echo one append
7 echo two append
8 echo three append
edit
echo edit append
edit append
1 echo first
2 echo x
3 echo y
4 echo z
5 echo last
6 echo one append
7 echo two append
8 echo three append
9 # simulate readline edit_and_execute_command
10 echo edit append
+1
View File
@@ -137,3 +137,4 @@ test_runsub ./history6.sub
test_runsub ./history7.sub
test_runsub ./history8.sub
test_runsub ./history9.sub
test_runsub ./history10.sub
+53
View File
@@ -0,0 +1,53 @@
#
# Copyright 2025 Free Software Foundation, Inc.
#
# This program is free software: you can redistribute it and/or modify
# it under the terms of the GNU General Public License as published by
# the Free Software Foundation, either version 3 of the License, or
# (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
#
# basic test for fc -D
: ${TMPDIR:=/tmp}
stream()
{
# something you can see
sed 's/$/ append/' < $1 >$TMPF && mv $TMPF $1
rm -f $TMPF
}
HISTFILE=$TMPDIR/fchist-$BASHPID
TMPF=$TMPDIR/fctmp-$BASHPID
trap 'rm -f "$HISTFILE" "$TMPF"' 0 1 2 3 6 15
cat > $HISTFILE <<EOF
echo first
echo one
echo two
echo three
echo x
echo y
echo z
echo last
EOF
set -o history
history
fc -e stream -D 2 4
history
# simulate readline edit_and_execute_command
echo edit
fc -e stream -D
history