[llvm] [flang-rt] Fix out of bounds read in ExternalIOTest.cpp (PR #218966)
David Spickett via llvm-commits
llvm-commits at lists.llvm.org
Wed Aug 26 08:49:09 PDT 2026
https://github.com/DavidSpickett created https://github.com/llvm/llvm-project/pull/218966
The test added by 076da86cd35aa58759c9be7d23ba4cd8693b7414 fails when run with ASAN:
```
==339162==ERROR: AddressSanitizer: global-buffer-overflow on address 0xc565e049c86e at pc 0xc565e0ee9268 bp 0xffffd5d7de20 sp 0xffffd5d7de18
READ of size 1 at 0xc565e049c86e thread T0
#0 0xc565e0ee9264 in Fortran::runtime::TrimTrailingSpaces(char const*, unsigned long) /home/davspi01/llvm-project/flang-rt/lib/runtime/tools.cpp:21:19
#1 0xc565e0e41d7c in Fortran::runtime::io::OpenStatementState::set_path(char const*, unsigned long) /home/davspi01/llvm-project/flang-rt/lib/runtime/io-stmt.cpp:291:17
#2 0xc565e0d56a84 in _FortranAioSetFile /home/davspi01/llvm-project/flang-rt/lib/runtime/io-api.cpp:1072:11
<...>
0xc565e049c86e is located 0 bytes after global variable '.str.263' defined in '/home/davspi01/llvm-project/flang-rt/unittests/Runtime/ExternalIOTest.cpp' (0xc565e049c860) of size 14
'.str.263' is ascii string 'opennewextant'
```
The test calls SetFile with "opennewextant" and a length of 15, but the length of that string is 13 (characters). TrimTrailingSpaces trusts that length and does `s[n - 1]`, which accesses out of bounds.
Fix this by using the correct length of the string.
>From 1bb79ae4b592b6d3f10f2360c39686e3ab05586f Mon Sep 17 00:00:00 2001
From: David Spickett <david.spickett at arm.com>
Date: Wed, 26 Aug 2026 15:36:23 +0000
Subject: [PATCH] [flang-rt] Fix out of bounds read in ExternalIOTest.cpp
The test added by 076da86cd35aa58759c9be7d23ba4cd8693b7414
fails when run with ASAN:
```
==339162==ERROR: AddressSanitizer: global-buffer-overflow on address 0xc565e049c86e at pc 0xc565e0ee9268 bp 0xffffd5d7de20 sp 0xffffd5d7de18
READ of size 1 at 0xc565e049c86e thread T0
#0 0xc565e0ee9264 in Fortran::runtime::TrimTrailingSpaces(char const*, unsigned long) /home/davspi01/llvm-project/flang-rt/lib/runtime/tools.cpp:21:19
#1 0xc565e0e41d7c in Fortran::runtime::io::OpenStatementState::set_path(char const*, unsigned long) /home/davspi01/llvm-project/flang-rt/lib/runtime/io-stmt.cpp:291:17
#2 0xc565e0d56a84 in _FortranAioSetFile /home/davspi01/llvm-project/flang-rt/lib/runtime/io-api.cpp:1072:11
<...>
0xc565e049c86e is located 0 bytes after global variable '.str.263' defined in '/home/davspi01/llvm-project/flang-rt/unittests/Runtime/ExternalIOTest.cpp' (0xc565e049c860) of size 14
'.str.263' is ascii string 'opennewextant'
```
The test calls SetFile with "opennewextant" and a length of 15,
but the length of that string is 13 (characters). TrimTrailingSpaces
trusts that length and does `s[n - 1]`, which accesses out of bounds.
---
flang-rt/unittests/Runtime/ExternalIOTest.cpp | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/flang-rt/unittests/Runtime/ExternalIOTest.cpp b/flang-rt/unittests/Runtime/ExternalIOTest.cpp
index 1414dede7a2d1..1fe3b08126c5d 100644
--- a/flang-rt/unittests/Runtime/ExternalIOTest.cpp
+++ b/flang-rt/unittests/Runtime/ExternalIOTest.cpp
@@ -1063,7 +1063,7 @@ TEST(ExternalIOTests, OpenNewExtant) {
<< "EndIoStatement() for OpenUnit(NEW)";
// OPEN(10,STATUS='OLD')
io = IONAME(BeginOpenUnit)(10, __FILE__, __LINE__);
- ASSERT_TRUE(IONAME(SetFile)(io, "opennewextant", 15))
+ ASSERT_TRUE(IONAME(SetFile)(io, "opennewextant", 13))
<< "SetFile(opennewextant)";
ASSERT_TRUE(IONAME(SetStatus)(io, "OLD", 3)) << "SetStatus(OLD)";
ASSERT_EQ(IONAME(EndIoStatement)(io), IostatOk)
More information about the llvm-commits
mailing list