zsh-workers
 help / color / mirror / code / Atom feed
From: Roman Perepelitsa <roman.perepelitsa@gmail.com>
To: Zsh hackers list <zsh-workers@zsh.org>
Subject: PATCH: bug fix: infinite loop in sysread
Date: Wed, 5 Feb 2020 15:19:26 +0100	[thread overview]
Message-ID: <CAN=4vMqkV3uf3Ki4221k_HpYaqNmTq_msD7kv_Eg-5rg5=MDhA@mail.gmail.com> (raw)

[-- Attachment #1: Type: text/plain, Size: 915 bytes --]

The attached patch fixes a bug in sysread from zsh/system. The bug
triggers in the following case:

1. zsh has been compiled with HAVE_SELECT and without HAVE_POLL
2. sysread is called with timeout (-t)
3. the input file descriptor is valid but there is no data to read
4. errno happens to be EINTR prior to the call to sysread

This results in an infinite loop in sysread:

  while ((ret = select(infd+1, (SELECT_ARG_2_T) &fds,
                       NULL, NULL,&select_tv)) < 1) {
      if (errno != EINTR || errflag || retflag || breaks || contflag)
          break;
  }

Here select() keeps returning 0, indicating timeout. This is not an
error, so errno doesn't get set. If it was EINTR prior to the call,
it stays EINTR, and the loop keeps spinning.

The fix is to replace `< 1` with `< 0` in the loop condition.

On GitHub:
https://github.com/zsh-users/zsh/compare/master...romkatv:fix-sysread-tmout

Roman.

[-- Attachment #2: fix-sysread-tmout.patch.txt --]
[-- Type: text/plain, Size: 456 bytes --]

diff --git a/Src/Modules/system.c b/Src/Modules/system.c
index 50de59cf9..fb3d80773 100644
--- a/Src/Modules/system.c
+++ b/Src/Modules/system.c
@@ -174,7 +174,7 @@ bin_sysread(char *nam, char **args, Options ops, UNUSED(int func))
 	}
 
 	while ((ret = select(infd+1, (SELECT_ARG_2_T) &fds,
-			     NULL, NULL,&select_tv)) < 1) {
+			     NULL, NULL,&select_tv)) < 0) {
 	    if (errno != EINTR || errflag || retflag || breaks || contflag)
 		break;
 	}

             reply	other threads:[~2020-02-05 14:20 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2020-02-05 14:19 Roman Perepelitsa [this message]
2020-02-05 20:55 ` Bart Schaefer
2020-02-05 21:04   ` Roman Perepelitsa
2020-02-06 19:52 ` dana
2020-02-06 20:01   ` Peter Stephenson
2020-02-07 11:26   ` Roman Perepelitsa
2020-02-07 16:49     ` dana

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='CAN=4vMqkV3uf3Ki4221k_HpYaqNmTq_msD7kv_Eg-5rg5=MDhA@mail.gmail.com' \
    --to=roman.perepelitsa@gmail.com \
    --cc=zsh-workers@zsh.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
Code repositories for project(s) associated with this public inbox

	https://git.vuxu.org/mirror/zsh/

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).