[bug #68585] [eqn, pic, tbl] code not "ASAN_OPTIONS=alloc_dealloc_mismatch=1" clean

"G. Branden Robinson" <[email protected]>
Newsgroups gmane.comp.printing.groff.bugs
Message-ID <[email protected]>
Update of bug #68585 (group groff):

                  Status:             In Progress => Fixed
             Open/Closed:                    Open => Closed

    _______________________________________________________

Follow-up Comment #6:


commit 8ef98cfb067b249e7a34568062027e0ccdba7b1f
Author: Bruno Haible <[email protected]>
Date:   Sun Aug 2 13:54:32 2026 +0200

    tbl: Fix undefined behaviour.
    
    This change fixes ASAN findings such as:
    
    ERROR: AddressSanitizer: alloc-dealloc-mismatch (malloc vs operator delete
[]) on 0x6f5aaafeb4e0
        #0 0x5a98c9ab586d in operator delete[](void*)
/home/runner/work/llvm-project/llvm-project/compiler-rt/lib/asan/asan_new_delete.cpp:179:46
        #1 0x5a98c9ad6eaf in block_entry::~block_entry()
/devel/groff/src/preproc/tbl/table.cpp:667:3
        #2 0x5a98c9b0cad4 in left_block_entry::~left_block_entry()
/devel/groff/src/preproc/tbl/table.cpp:334:7
        #3 0x5a98c9b0cb24 in left_block_entry::~left_block_entry()
/devel/groff/src/preproc/tbl/table.cpp:334:7
        #4 0x5a98c9ae6f36 in table::~table()
/devel/groff/src/preproc/tbl/table.cpp:1310:5
        #5 0x5a98c9ab89fc in process_table(table_input&)
/devel/groff/src/preproc/tbl/main.cpp:1677:5
        #6 0x5a98c9ab7da7 in process_input_file(_IO_FILE*)
/devel/groff/src/preproc/tbl/main.cpp:270:4
        #7 0x5a98c9acdc9e in main
/devel/groff/src/preproc/tbl/main.cpp:1792:5
    
    0x6f5aaafeb4e0 is located 0 bytes inside of 62-byte region
[0x6f5aaafeb4e0,0x6f5aaafeb51e)
    allocated by thread T0 here:
        #0 0x5a98c9a71f39 in calloc
/home/runner/work/llvm-project/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:74:3
        #1 0x5a98c9b15f2a in string::extract() const
/devel/groff/src/libs/libgroff/string.cpp:384:33
        #2 0x5a98c9aed448 in table::add_entry(int, int, string const&,
entry_format const*, char const*, int)
/devel/groff/src/preproc/tbl/table.cpp:1546:17
        #3 0x5a98c9acabf6 in process_data(table_input&, format*, options*)
/devel/groff/src/preproc/tbl/main.cpp:1577:13
        #4 0x5a98c9ab8972 in process_table(table_input&)
/devel/groff/src/preproc/tbl/main.cpp:1675:17
        #5 0x5a98c9ab7da7 in process_input_file(_IO_FILE*)
/devel/groff/src/preproc/tbl/main.cpp:270:4
        #6 0x5a98c9acdc9e in main
/devel/groff/src/preproc/tbl/main.cpp:1792:5
    
    SUMMARY: AddressSanitizer: alloc-dealloc-mismatch
/devel/groff/src/preproc/tbl/table.cpp:667:3 in block_entry::~block_entry()
    
    * src/preproc/tbl/table.cpp (block_entry::~block_entry): Free the
contents
    field using free(), not delete[].

commit 0f74adb4190f25238b7c1f49462added35471363
Author: Bruno Haible <[email protected]>
Date:   Sun Aug 2 13:54:38 2026 +0200

    eqn: Fix undefined behaviour, part 1.
    
    This change fixes this ASAN finding:
    
    ERROR: AddressSanitizer: alloc-dealloc-mismatch (malloc vs operator delete
[]) on 0x6d5acafe9730
        #0 0x582e73588e9d in operator delete[](void*)
/home/runner/work/llvm-project/llvm-project/compiler-rt/lib/asan/asan_new_delete.cpp:179:46
        #1 0x582e735d26af in delim_box::~delim_box()
/devel/groff/src/preproc/eqn/delim.cpp:205:3
        #2 0x582e735d27f4 in delim_box::~delim_box()
/devel/groff/src/preproc/eqn/delim.cpp:204:1
        #3 0x582e735a2949 in box_list::~box_list()
/devel/groff/src/preproc/eqn/box.cpp:524:5
        #4 0x582e735b15f0 in list_box::~list_box()
/devel/groff/src/preproc/eqn/box.h:69:7
        #5 0x582e735b1644 in list_box::~list_box()
/devel/groff/src/preproc/eqn/box.h:69:7
        #6 0x582e735a1768 in box::top_level()
/devel/groff/src/preproc/eqn/box.cpp:415:3
        #7 0x582e735e4502 in yyparse()
/devel/groff/src/preproc/eqn/eqn.ypp:132:33
        #8 0x582e7358d33d in do_file(_IO_FILE*, char const*)
/devel/groff/src/preproc/eqn/main.cpp:155:7
        #9 0x582e7358b338 in main /devel/groff/src/preproc/eqn/main.cpp:483:5
    
    0x6d5acafe9730 is located 0 bytes inside of 2-byte region
[0x6d5acafe9730,0x6d5acafe9732)
    allocated by thread T0 here:
        #0 0x582e73545394 in malloc
/home/runner/work/llvm-project/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3
        #1 0x582e735fd4b7 in strsave(char const*)
/devel/groff/src/libs/libgroff/strsave.cpp:36:33
        #2 0x582e735eb13c in yyparse()
/devel/groff/src/preproc/eqn/eqn.ypp:332:33
        #3 0x582e7358d33d in do_file(_IO_FILE*, char const*)
/devel/groff/src/preproc/eqn/main.cpp:155:7
        #4 0x582e7358b338 in main /devel/groff/src/preproc/eqn/main.cpp:483:5
    
    SUMMARY: AddressSanitizer: alloc-dealloc-mismatch
/devel/groff/src/preproc/eqn/delim.cpp:205:3 in delim_box::~delim_box()
    
    * src/preproc/eqn/delim.cpp (delim_box::~delim_box): Free the left and
right
    fields using free(), not delete[].
    * src/preproc/eqn/special.cpp (special_box::~special_box): Free the
macro_name
    field using free(), not delete[].

commit 17883bb19d37a873d0a8f036dabfffaf489ff592
Author: Bruno Haible <[email protected]>
Date:   Sun Aug 2 13:54:42 2026 +0200

    eqn: Fix undefined behaviour, part 2.
    
    This change fixes these two ASAN findings:
    
    ERROR: AddressSanitizer: alloc-dealloc-mismatch (malloc vs operator delete
[]) on 0x751c9b5e1010
        #0 0x5943b9f60e9d in operator delete[](void*)
/home/runner/work/llvm-project/llvm-project/compiler-rt/lib/asan/asan_new_delete.cpp:179:46
        #1 0x5943b9f6fb6c in argument_macro_input::~argument_macro_input()
/devel/groff/src/preproc/eqn/lex.cpp:558:5
        #2 0x5943b9f6fc14 in argument_macro_input::~argument_macro_input()
/devel/groff/src/preproc/eqn/lex.cpp:556:1
        #3 0x5943b9f713b9 in get_char()
/devel/groff/src/preproc/eqn/lex.cpp:619:7
        #4 0x5943b9f71c33 in get_token(int)
/devel/groff/src/preproc/eqn/lex.cpp:817:11
        #5 0x5943b9f71979 in yylex()
/devel/groff/src/preproc/eqn/lex.cpp:1198:14
        #6 0x5943b9fbbb20 in yyparse()
/devel/groff/src/preproc/eqn/eqn.cpp:1390:16
        #7 0x5943b9f6533d in do_file(_IO_FILE*, char const*)
/devel/groff/src/preproc/eqn/main.cpp:155:7
        #8 0x5943b9f63338 in main /devel/groff/src/preproc/eqn/main.cpp:483:5
    
    0x751c9b5e1010 is located 0 bytes inside of 35-byte region
[0x751c9b5e1010,0x751c9b5e1033)
    allocated by thread T0 here:
        #0 0x5943b9f1d394 in malloc
/home/runner/work/llvm-project/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3
        #1 0x5943b9fd5497 in strsave(char const*)
/devel/groff/src/libs/libgroff/strsave.cpp:36:33
        #2 0x5943b9f758c3 in interpolate_macro_with_args(char const*)
/devel/groff/src/preproc/eqn/lex.cpp:790:17
        #3 0x5943b9f721e6 in get_token(int)
/devel/groff/src/preproc/eqn/lex.cpp:876:8
        #4 0x5943b9f71979 in yylex()
/devel/groff/src/preproc/eqn/lex.cpp:1198:14
        #5 0x5943b9fbbb20 in yyparse()
/devel/groff/src/preproc/eqn/eqn.cpp:1390:16
        #6 0x5943b9f6533d in do_file(_IO_FILE*, char const*)
/devel/groff/src/preproc/eqn/main.cpp:155:7
        #7 0x5943b9f63338 in main /devel/groff/src/preproc/eqn/main.cpp:483:5
    
    SUMMARY: AddressSanitizer: alloc-dealloc-mismatch
/devel/groff/src/preproc/eqn/lex.cpp:558:5 in
argument_macro_input::~argument_macro_input()
    
    ERROR: AddressSanitizer: alloc-dealloc-mismatch (malloc vs operator delete
[]) on 0x7425fc5e3df0
        #0 0x5f7f9297fe9d in operator delete[](void*)
/home/runner/work/llvm-project/llvm-project/compiler-rt/lib/asan/asan_new_delete.cpp:179:46
        #1 0x5f7f9298ebab in argument_macro_input::~argument_macro_input()
/devel/groff/src/preproc/eqn/lex.cpp:559:3
        #2 0x5f7f9298ec04 in argument_macro_input::~argument_macro_input()
/devel/groff/src/preproc/eqn/lex.cpp:556:1
        #3 0x5f7f929903a9 in get_char()
/devel/groff/src/preproc/eqn/lex.cpp:619:7
        #4 0x5f7f92990c23 in get_token(int)
/devel/groff/src/preproc/eqn/lex.cpp:817:11
        #5 0x5f7f92990969 in yylex()
/devel/groff/src/preproc/eqn/lex.cpp:1198:14
        #6 0x5f7f929dab10 in yyparse()
/devel/groff/src/preproc/eqn/eqn.cpp:1390:16
        #7 0x5f7f9298433d in do_file(_IO_FILE*, char const*)
/devel/groff/src/preproc/eqn/main.cpp:155:7
        #8 0x5f7f92982338 in main /devel/groff/src/preproc/eqn/main.cpp:483:5
    
    0x7425fc5e3df0 is located 0 bytes inside of 21-byte region
[0x7425fc5e3df0,0x7425fc5e3e05)
    allocated by thread T0 here:
        #0 0x5f7f9293c394 in malloc
/home/runner/work/llvm-project/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3
        #1 0x5f7f929f4487 in strsave(char const*)
/devel/groff/src/libs/libgroff/strsave.cpp:36:33
        #2 0x5f7f9298ded4 in argument_macro_input::argument_macro_input(char
const*, unsigned long, char**, input*)
/devel/groff/src/preproc/eqn/lex.cpp:542:11
        #3 0x5f7f92994ae7 in interpolate_macro_with_args(char const*)
/devel/groff/src/preproc/eqn/lex.cpp:804:23
        #4 0x5f7f929911d6 in get_token(int)
/devel/groff/src/preproc/eqn/lex.cpp:876:8
        #5 0x5f7f92990969 in yylex()
/devel/groff/src/preproc/eqn/lex.cpp:1198:14
        #6 0x5f7f929dab10 in yyparse()
/devel/groff/src/preproc/eqn/eqn.cpp:1390:16
        #7 0x5f7f9298433d in do_file(_IO_FILE*, char const*)
/devel/groff/src/preproc/eqn/main.cpp:155:7
        #8 0x5f7f92982338 in main /devel/groff/src/preproc/eqn/main.cpp:483:5
    
    SUMMARY: AddressSanitizer: alloc-dealloc-mismatch
/devel/groff/src/preproc/eqn/lex.cpp:559:3 in
argument_macro_input::~argument_macro_input()
    
    * src/preproc/eqn/lex.cpp (argument_macro_input::~argument_macro_input):
Free
    the s field and the elements of the argv field using free(), not
delete[].

commit 36b1672086ba968676d15555a51d8e4a6f6f26c6
Author: Bruno Haible <[email protected]>
Date:   Sun Aug 2 13:54:48 2026 +0200

    pic: Fix undefined behaviour, part 1.
    
    This change fixes this ASAN finding:
    
    ERROR: AddressSanitizer: alloc-dealloc-mismatch (malloc vs operator delete
[]) on 0x76fae07e0330
        #0 0x56401fe1d9ed in operator delete[](void*)
/home/runner/work/llvm-project/llvm-project/compiler-rt/lib/asan/asan_new_delete.cpp:179:46
        #1 0x56401fe67b0f in output::~output()
/devel/groff/src/preproc/pic/object.cpp:47:3
        #2 0x56401fea35a4 in common_output::~common_output()
/devel/groff/src/preproc/pic/common.h:20:7
        #3 0x56401feab614 in simple_output::~simple_output()
/devel/groff/src/preproc/pic/troff.cpp:37:7
        #4 0x56401fea657a in troff_output::~troff_output()
/devel/groff/src/preproc/pic/troff.cpp:276:1
        #5 0x56401fea65d4 in troff_output::~troff_output()
/devel/groff/src/preproc/pic/troff.cpp:274:1
        #6 0x56401fe67423 in main /devel/groff/src/preproc/pic/main.cpp:698:3
    
    0x76fae07e0330 is located 0 bytes inside of 7-byte region
[0x76fae07e0330,0x76fae07e0337)
    allocated by thread T0 here:
        #0 0x56401fdd9ee4 in malloc
/home/runner/work/llvm-project/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3
        #1 0x56401febb677 in strsave(char const*)
/devel/groff/src/libs/libgroff/strsave.cpp:36:33
        #2 0x56401fe67d41 in output::set_args(char const*)
/devel/groff/src/preproc/pic/object.cpp:62:12
        #3 0x56401fe66356 in do_picture(_IO_FILE*)
/devel/groff/src/preproc/pic/main.cpp:297:10
        #4 0x56401fe64f4f in do_file(char const*)
/devel/groff/src/preproc/pic/main.cpp:395:2
        #5 0x56401fe67241 in main /devel/groff/src/preproc/pic/main.cpp:691:7
    
    SUMMARY: AddressSanitizer: alloc-dealloc-mismatch
/devel/groff/src/preproc/pic/object.cpp:47:3 in output::~output()
    
    * src/preproc/pic/object.cpp (output::~output, output::set_args): Free
the
    args field using free(), not delete[].

commit e8e78aad57634640d1cab556cadc2ca800cca220
Author: Bruno Haible <[email protected]>
Date:   Sun Aug 2 13:54:53 2026 +0200

    pic: Fix undefined behaviour, part 2.
    
    This change fixes this ASAN finding:
    
    ERROR: AddressSanitizer: alloc-dealloc-mismatch (malloc vs operator delete
[]) on 0x6db4f9de0790
        #0 0x609b694769ed in operator delete[](void*)
/home/runner/work/llvm-project/llvm-project/compiler-rt/lib/asan/asan_new_delete.cpp:179:46
        #1 0x609b694c553f in command_object::~command_object()
/devel/groff/src/preproc/pic/object.cpp:488:3
        #2 0x609b694c5594 in command_object::~command_object()
/devel/groff/src/preproc/pic/object.cpp:487:1
        #3 0x609b694a7450 in parse_cleanup()
/devel/groff/src/preproc/pic/pic.ypp:1918:5
        #4 0x609b694bf43e in do_picture(_IO_FILE*)
/devel/groff/src/preproc/pic/main.cpp:303:5
        #5 0x609b694bdf4f in do_file(char const*)
/devel/groff/src/preproc/pic/main.cpp:395:2
        #6 0x609b694c0241 in main /devel/groff/src/preproc/pic/main.cpp:691:7
    
    0x6db4f9de0790 is located 0 bytes inside of 7-byte region
[0x6db4f9de0790,0x6db4f9de0797)
    allocated by thread T0 here:
        #0 0x609b69432ee4 in malloc
/home/runner/work/llvm-project/llvm-project/compiler-rt/lib/asan/asan_malloc_linux.cpp:67:3
        #1 0x609b69514657 in strsave(char const*)
/devel/groff/src/libs/libgroff/strsave.cpp:36:33
        #2 0x609b694b6c03 in yylex()
/devel/groff/src/preproc/pic/lex.cpp:1916:25
        #3 0x609b6947b944 in yyparse()
/devel/groff/src/preproc/pic/pic.cpp:2354:16
        #4 0x609b694bf3e0 in do_picture(_IO_FILE*)
/devel/groff/src/preproc/pic/main.cpp:299:9
        #5 0x609b694bdf4f in do_file(char const*)
/devel/groff/src/preproc/pic/main.cpp:395:2
        #6 0x609b694c0241 in main /devel/groff/src/preproc/pic/main.cpp:691:7
    
    SUMMARY: AddressSanitizer: alloc-dealloc-mismatch
/devel/groff/src/preproc/pic/object.cpp:488:3 in
command_object::~command_object()
    
    * src/preproc/pic/object.cpp (command_object::~command_object): Free the
    s field using free(), not delete[].

commit 240d9379b83775c65b878ccf599a41787d7977c6
Author: G. Branden Robinson <[email protected]>
Date:   Sun Aug 2 22:18:03 2026 -0500

    ChangeLog: Add entry for Savannah #68585 fix.
    
    Adapt Bruno's commit log messages to how we apply the GNU Coding
    Standards' prescribed format for change log entries.




    _______________________________________________________

Reply to this item at:

  <https://savannah.gnu.org/bugs/?68585>

_______________________________________________
Message sent via Savannah
https://savannah.gnu.org/
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQQk97aszIMMAvLLwm6qLAuaBUf3TgUCanhnNQAKCRCqLAuaBUf3
TuUBAQD35IzMAP0optb0lFF7ovCG8zRgN3dXkXMepsep+YBrywD/XToCHiWkZl6s
jOvYhcWy0uSNEpkLbxyNvcfBSI0Sywg=
=6jTv
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.