[bug #68558] [PATCH] [troff] assertion failure in `do` request handler when given an invalid identifier

"G. Branden Robinson" <[email protected]> Fri, 24 Jul 2026 17:15:18 -0400 (EDT)
Newsgroups gmane.comp.printing.groff.bugs
Message-ID <[email protected]>
--8323329-1714636915-1784927718=:3270187
Content-Type: TEXT/plain; CHARSET=utf-8
Content-Transfer-Encoding: QUOTED-PRINTABLE
Content-Disposition: inline

URL:=0A  <https://savannah.gnu.org/bugs/?68558>=0A=0A                 Summa=
ry: [PATCH] [troff] assertion failure in  `do` request=0Ahandler when given=
 an invalid identifier=0A                   Group: GNU roff=0A             =
  Submitter: gbranden=0A               Submitted: Fri 24 Jul 2026 09:15:13 =
PM UTC=0A                Category: Core=0A                Severity: 4 - Imp=
ortant=0A              Item Group: Crash/Unresponsive=0A                  S=
tatus: In Progress=0A                 Privacy: Public=0A             Assign=
ed to: gbranden=0A             Open/Closed: Open=0A         Discussion Lock=
: Unlocked=0A         Planned Release: None=0A=0A=0A    ___________________=
____________________________________=0A=0AFollow-up Comments:=0A=0A=0A-----=
--------------------------------------------------=0ADate: Fri 24 Jul 2026 =
09:15:13 PM UTC By: G. Branden Robinson <gbranden>=0ADiscovered by inspecti=
on while investigating bug #68552.=0A=0AI was emotionally preparing myself =
to fall upon my sword, present my palms for=0Athe nails, rend my garments, =
and so on.=0A=0ABut it turns out this bad boy is **old**.=0A=0A=0A$ printf =
'.do \\a\n' | ~/groff-1.24.1/bin/groff=0Atroff:<standard input>:1: error: e=
xpected identifier, got a non-interpreted=0Acharacter node token; treated a=
s missing=0Atroff: ../src/roff/troff/input.cpp:10349: request_or_macro*=0Al=
ookup_request(symbol): Assertion `!nm.is_null()' failed.=0A/home/branden/gr=
off-1.24.1/bin/groff: error: troff: Aborted (core dumped)=0A$ printf '.do \=
\a\n' | ~/groff-1.24.0/bin/groff=0Atroff:<standard input>:1: error: expecte=
d identifier, got a non-interpreted=0Acharacter node token; treated as miss=
ing=0Atroff: ../src/roff/troff/input.cpp:10339: request_or_macro*=0Alookup_=
request(symbol): Assertion `!nm.is_null()' failed.=0A/home/branden/groff-1.=
24.0/bin/groff: error: troff: Aborted (core dumped)=0A$ printf '.do \\a\n' =
| ~/groff-1.23.0/bin/groff=0Atroff:<standard input>:1: error: expected iden=
tifier, got a node; treated as=0Amissing=0Atroff: src/roff/troff/input.cpp:=
8510: request_or_macro*=0Alookup_request(symbol): Assertion `!nm.is_null()'=
 failed.=0A/home/branden/groff-1.23.0/bin/groff: error: troff: Aborted (cor=
e dumped)=0A$ printf '.do \\a\n' | ~/groff-1.22.4/bin/groff=0Atroff: <stand=
ard input>:1: name expected (got a node): treated as missing=0Atroff: Faile=
d assertion at line 8286, file 'src/roff/troff/input.cpp'.=0A/home/branden/=
groff-1.22.4/bin/groff: troff: Signal 6 (core dumped)=0A$ printf '.do \\a\n=
' | ~/groff-1.22.3/bin/groff=0A<standard input>:1: name expected (got a nod=
e): treated as missing=0Atroff: Failed assertion at line 8342, file `input.=
cpp'.=0A/home/branden/groff-1.22.3/bin/groff: troff: Signal 6 (core dumped)=
=0A=0A=0ABusting the _groff_ 1.25.0 code freeze for this.  I have a fix.=0A=
=0A=0Adiff --git a/src/roff/troff/input.cpp b/src/roff/troff/input.cpp=0Ain=
dex f3657fc99..f63de35e5 100644=0A--- a/src/roff/troff/input.cpp=0A+++ b/sr=
c/roff/troff/input.cpp=0A@@ -3494,11 +3494,18 @@ static void do_request() /=
/ .do=0A     skip_line();=0A     return;=0A   }=0A+  // We must attempt to =
read the first request argument--a request or=0A+  // macro identifier--wit=
h compatibility mode _off_, but if the user=0A+  // doesn't supply a valid =
one, we must unwind.=0A   want_att_compat_stack.push(want_att_compat);=0A  =
 want_att_compat =3D false;=0A   symbol nm =3D read_identifier();=0A-  if (=
nm.is_null())=0A+  if (nm.is_null()) {=0A+    want_att_compat =3D want_att_=
compat_stack.top();=0A+    want_att_compat_stack.pop();=0A     skip_line();=
=0A+    return;=0A+  }=0A   else=0A     interpolate_macro_or_invoke_request=
(nm, true /* don't want next token=0A*/);=0A   assert(!want_att_compat_stac=
k.empty());=0A=0A=0AI do deserve _some_ blame.  I lovingly refactored this =
thing to migrate it to=0Ause an STL container to stack nested compatibility=
 mode enablement values, and=0Acarefully preserved the bug this whole time.=
=0A=0A=0A=0A=0A=0A=0A=0A    _______________________________________________=
________=0A=0AReply to this item at:=0A=0A  <https://savannah.gnu.org/bugs/=
?68558>=0A=0A_______________________________________________=0AMessage sent=
 via Savannah=0Ahttps://savannah.gnu.org/=0A
--8323329-1714636915-1784927718=:3270187
Content-Type: APPLICATION/pgp-signature; name=signature.asc

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQQk97aszIMMAvLLwm6qLAuaBUf3TgUCamPV5gAKCRCqLAuaBUf3
TtTEAP9cXV2VyGyv2tbJaYUyUdloF45rexAkZ+k7XyKtUgTdQAEA0iuLmRPAOWbP
hyWOLw6VqR3oHSP2uIXRht672nlN4QY=
=rmPg
-----END PGP SIGNATURE-----

--8323329-1714636915-1784927718=:3270187--