dash.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Stack overflow on unbounded recursion
@ 2020-05-28  8:17 tiemeezeiv
  0 siblings, 0 replies; only message in thread
From: tiemeezeiv @ 2020-05-28  8:17 UTC (permalink / raw)
  To: dash


[-- Attachment #1.1: Type: text/plain, Size: 798 bytes --]

Tested this against master at commit 3e3e7af1:

    $ src/dash -c 'f(){ f;};f'
    segfault

Of course this is a pathological command string, but it looks like a clear case
of stack overflow:

    Program received signal SIGSEGV, Segmentation fault.
    0x0000000000407762 in argstr (p=0x4204b0 "f", flag=flag@entry=3) at expand.c:249
    249             int breakall = (flag & (EXP_WORD | EXP_QUOTED)) == EXP_WORD;
    (gdb) info proc mappings
          ...
          0x7ffff7ffe000     0x7ffff7fff000     0x1000        0x0
          0x7fffff7ff000     0x7ffffffff000   0x800000        0x0 [stack]
    (gdb) p/x $rsp
    $1 = 0x7fffff7fef50
    (gdb) x/i $rip
    => 0x407762 <argstr+34>:        sete   0x7(%rsp)

Is this a bug or have I just stumbled into a known "feature"?

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 260 bytes --]

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2020-05-28  8:22 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2020-05-28  8:17 Stack overflow on unbounded recursion tiemeezeiv

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).