diff options
author | jilles <jilles@FreeBSD.org> | 2015-08-23 20:44:53 +0000 |
---|---|---|
committer | jilles <jilles@FreeBSD.org> | 2015-08-23 20:44:53 +0000 |
commit | f504ca457f15fb7151537bd610d757a4d8163951 (patch) | |
tree | 7649da2c39f43e98eb79a974979a3f8d15039d3a | |
parent | 9dba4c6890736d6ff29340b1a48dd5e2f99d8539 (diff) | |
download | FreeBSD-src-f504ca457f15fb7151537bd610d757a4d8163951.zip FreeBSD-src-f504ca457f15fb7151537bd610d757a4d8163951.tar.gz |
sh: Don't create bad parse result when postponing a bad substitution error.
An invalid substitution like ${var@} does not cause a parse error but is
stored in the intermediate representation, to be written as part of the
error message. If there is a CTL* byte in the stored part, this confuses
some code such as the code to skip an unused alternative such as in
${var-alternative}.
To keep things simple, do not store CTL* bytes.
Found with afl-fuzz.
MFC after: 1 week
-rw-r--r-- | bin/sh/parser.c | 5 | ||||
-rw-r--r-- | bin/sh/tests/errors/Makefile | 2 | ||||
-rw-r--r-- | bin/sh/tests/errors/bad-parm-exp7.0 | 4 | ||||
-rw-r--r-- | bin/sh/tests/errors/bad-parm-exp8.0 | 4 |
4 files changed, 13 insertions, 2 deletions
diff --git a/bin/sh/parser.c b/bin/sh/parser.c index e7ec010..98b8791 100644 --- a/bin/sh/parser.c +++ b/bin/sh/parser.c @@ -1662,7 +1662,7 @@ varname: pungetc(); else if (c == '\n' || c == PEOF) synerror("Unexpected end of line in substitution"); - else + else if (BASESYNTAX[c] != CCTL) USTPUTC(c, out); } if (subtype == 0) { @@ -1678,7 +1678,8 @@ varname: synerror("Unexpected end of line in substitution"); if (flags == VSNUL) STPUTC(':', out); - STPUTC(c, out); + if (BASESYNTAX[c] != CCTL) + STPUTC(c, out); subtype = VSERROR; } else subtype = p - types + VSNORMAL; diff --git a/bin/sh/tests/errors/Makefile b/bin/sh/tests/errors/Makefile index ace9a01..51a766f 100644 --- a/bin/sh/tests/errors/Makefile +++ b/bin/sh/tests/errors/Makefile @@ -19,6 +19,8 @@ FILES+= bad-parm-exp3.2 bad-parm-exp3.2.stderr FILES+= bad-parm-exp4.2 bad-parm-exp4.2.stderr FILES+= bad-parm-exp5.2 bad-parm-exp5.2.stderr FILES+= bad-parm-exp6.2 bad-parm-exp6.2.stderr +FILES+= bad-parm-exp7.0 +FILES+= bad-parm-exp8.0 FILES+= option-error.0 FILES+= redirection-error.0 FILES+= redirection-error2.2 diff --git a/bin/sh/tests/errors/bad-parm-exp7.0 b/bin/sh/tests/errors/bad-parm-exp7.0 new file mode 100644 index 0000000..b8562fb --- /dev/null +++ b/bin/sh/tests/errors/bad-parm-exp7.0 @@ -0,0 +1,4 @@ +# $FreeBSD$ + +v=1 +eval ": $(printf '${v-${\372}}')" diff --git a/bin/sh/tests/errors/bad-parm-exp8.0 b/bin/sh/tests/errors/bad-parm-exp8.0 new file mode 100644 index 0000000..28f00cd --- /dev/null +++ b/bin/sh/tests/errors/bad-parm-exp8.0 @@ -0,0 +1,4 @@ +# $FreeBSD$ + +v=1 +eval ": $(printf '${v-${w\372}}')" |