[Phoenix-pm] Fwd: [perl #40427] Segfault in pack

Scott Walters scott at slowass.net
Fri Sep 29 12:44:56 PDT 2006

Subject: [perl #40427] Segfault in pack 
# New Ticket Created by  dgay at acm.org 
# Please include the string:  [perl #40427]
# in the subject line of all future correspondence about this issue. 
# <URL: http://rt.perl.org/rt3/Ticket/Display.html?id=40427 >

This is a bug report for perl from dgay at acm.org,
generated with the help of perlbug 1.35 running under perl v5.8.5.

[Please enter your report here]

The following program will cause a segfault on perl 5.8.5 and 5.9.4:
  @l = ("aa", "bb");
  $fun = pack "(A)30 N4", @l;
  print "$fun\n";

The following patch (for, and tested on, 5.9.4) fixes this:
--- pp_pack.c	2006-09-28 17:21:31.000000000 -0700
+++ pp_pack.c.new 2006-09-28 16:56:14.000000000 -0700
@@ -2630,6 +2630,7 @@
 		if (savsym.howlen == e_star && beglist == endlist)
 		    break;		/* No way to continue */
+	    items = endlist - beglist;
 	    lookahead.flags  = symptr->flags & ~group_modifiers;
 	    goto no_change;

The problem is that the items consumed by the recursive pack are
not counted in the outer pack, so accesses to random parts of the
stack beyond the top are possible. The fix simply updates the
items local variable after the recursive packs ("make test" reports
no failures).

----- End forwarded message -----

