Page MenuHomeFreeBSD

bsdgrep(1): Handle special case of pattern being terminated early with a NULL byte
ClosedPublic

Authored by kevans on Mar 22 2017, 8:43 PM.
Tags
None
Referenced Files
Unknown Object (File)
Sat, Nov 9, 11:56 PM
Unknown Object (File)
Thu, Oct 31, 6:46 AM
Unknown Object (File)
Oct 10 2024, 12:29 PM
Unknown Object (File)
Sep 30 2024, 8:07 PM
Unknown Object (File)
Sep 21 2024, 10:14 AM
Unknown Object (File)
Sep 21 2024, 2:50 AM
Unknown Object (File)
Sep 19 2024, 10:15 PM
Unknown Object (File)
Sep 19 2024, 1:40 PM
Subscribers

Details

Summary

Teach bsdgrep(1) how to handle the special case of a pattern being terminated early with a NULL byte. We ignore these patterns, in line with how gnugrep(1) handles the same case.

PR: 202022

Test Plan

Test kcwu@csie.org's original example, ensure no segfault and no matches.
Run kyua tests to check that we've not caused any further regressions.

Diff Detail

Lint
Lint Passed
Unit
No Test Coverage
Build Status
Buildable 8507
Build 8811: arc lint + arc unit

Event Timeline

Practically, when does this happen? Malicious/test inputs only?

Also, what happens with a nul mid-line? Just the first part of the line is used, the second part discarded?

usr.bin/grep/grep.c
318

style(9): space between "if" and "(".

In D10102#212232, @cem wrote:

Practically, when does this happen? Malicious/test inputs only?

Yes, or it could be under the class of rm -rf /$empty problems -- the following produces a perfectly valid pattern file that does exactly what you expect, because getline(3) does the right thing:

printf "BSD\0\nLicensing\0\n" > /tmp/pat
grep -f /tmp/pat /COPYRIGHT

It's a quick step from there to, in some case, printf "$empty\0\n" >> /tmp/pat in some loop to generate a series of expressions to test by. The only problem here is we hadn't taken into consideration what getline(3) does when it comes across a "\0\n" line, which is produce the tested-for above.

Also, what happens with a nul mid-line? Just the first part of the line is used, the second part discarded?

Correct.

ngie added inline comments.
usr.bin/grep/grep.c
318

Could you please check for '\0' instead of 0 for reader/static analysis tool clarity?

  • Check for '\0' instead of 0 for clarity
This revision is now accepted and ready to land.Apr 4 2017, 7:45 PM

Ping @emaste -- any further comments/action required on this one? =)

This revision was automatically updated to reflect the committed changes.