bug-gnu-emacs
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

bug#58042: 29.0.50; ASAN use-after-free in re_match_2_internal


From: Gerd Möllmann
Subject: bug#58042: 29.0.50; ASAN use-after-free in re_match_2_internal
Date: Wed, 05 Oct 2022 12:24:12 +0200
User-agent: Gnus/5.13 (Gnus v5.13)

Gerd Möllmann <gerd.moellmann@gmail.com> writes:

> Eli Zaretskii <eliz@gnu.org> writes:
>
>> So I guess we should do this dance around calls to maybe_quit in
>> regex-emacs.c:
>>
>>   specpdl_ref gc_count = inhibit_garbage_collection ();
>>   maybe_quit ();
>>   unbind_to (gc_count, Qnil);
>>
>> Or maybe even better, do this inside probably_quit (because who knows
>> how many other callers of maybe_quit could be hit by this unexpected
>> GC)?
>>
>> Can you try this?
>
> Isn't the -[EmacsView layoutSublayersOfLayer:] the problem?  AFAICT from
> a web search, this is an event handler method that is also called from
> by the framework?
>
> In the olden days, it was a serious error to call into Lisp from an
> event handler.  All bets were off when that happened, not only related
> to GC.  I believe that hasn't changed much.
>
> That code was introduced by Alan around this time.
>
> 1ba02d85a964e1b2c6a9735cd3decdc524e06dc1
> Author:     Alan Third <alan@idiocy.org>
> AuthorDate: Sat Jun 12 10:25:47 2021 +0100
> Commit:     Alan Third <alan@idiocy.org>
> CommitDate: Sat Jul 31 11:13:05 2021 +0100
>
> Maybe Allen can say something, I've CC'd him.
>
> Or maybe we should add your fix, too?

And a similar question to Po Lu because of

f81065a91be5a54b78e202df6918aff443588ae1
Author:     Po Lu <luangruo@yahoo.com>
AuthorDate: Mon May 30 16:03:11 2022 +0800
Commit:     Po Lu <luangruo@yahoo.com>
CommitDate: Mon May 30 16:03:11 2022 +0800

which added a call to redisplay to - (NSDragOperation) draggingUpdated:
(id <NSDraggingInfo>) sender.  Is that safe here?





reply via email to

[Prev in Thread] Current Thread [Next in Thread]