From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (qmail 16707 invoked by alias); 8 May 2017 18:43:14 -0000 Mailing-List: contact zsh-workers-help@zsh.org; run by ezmlm Precedence: bulk X-No-Archive: yes List-Id: Zsh Workers List List-Post: List-Help: X-Seq: 41076 Received: (qmail 19428 invoked from network); 8 May 2017 18:43:14 -0000 X-Qmail-Scanner-Diagnostics: from mail-io0-f173.google.com by f.primenet.com.au (envelope-from , uid 7791) with qmail-scanner-2.11 (clamdscan: 0.99.2/21882. spamassassin: 3.4.1. Clear:RC:0(209.85.223.173):SA:0(-2.3/5.0):. Processed in 1.346509 secs); 08 May 2017 18:43:14 -0000 X-Spam-Checker-Version: SpamAssassin 3.4.1 (2015-04-28) on f.primenet.com.au X-Spam-Level: X-Spam-Status: No, score=-2.3 required=5.0 tests=FREEMAIL_FROM, RCVD_IN_DNSWL_NONE,RCVD_IN_MSPIKE_H2,RCVD_IN_SORBS_SPAM,SPF_PASS, T_DKIM_INVALID autolearn=unavailable autolearn_force=no version=3.4.1 X-Envelope-From: dualbus@gmail.com X-Qmail-Scanner-Mime-Attachments: |segfault| X-Qmail-Scanner-Zip-Files: | Received-SPF: pass (ns1.primenet.com.au: SPF record at _netblocks.google.com designates 209.85.223.173 as permitted sender) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to:cc; bh=+Spwu8nw7LuYVCHrnNCWq+0ZfqSx6fKiPt4O1bUkem8=; b=Lf6z86diEYIQ4hjJMVGW6lwy9vmujSoUiBjGNcu6bdkgpPqFSSyE6FGXmPDNCBEfEY 9IpKlQoPfzDW7cuXx9yoM4Dy5yVb9PRLYBz5wfRmIg7thYSI1fCOnT6bn2Hpunw3E1Oa 0IdP6CR0ZVhc7K2GUzeb5w9Y1nf9c6cJVae7mF3Wjm78+SvH1XEEFzAvhK4FIEmE9xpw kC3A7pxQetGwjUZjMlb+pg6ibN6JzuRfDWI2jZIg5hYSKc9LZAq1L30M1Dc/lV6fFp8+ RwwJyQT37f2xjWB/cc356PaohL5OhH5FZaQZEmfn5nBrmBISpBaAsRsvGEYSUhL4oV7x n+rA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to:cc; bh=+Spwu8nw7LuYVCHrnNCWq+0ZfqSx6fKiPt4O1bUkem8=; b=jsZCsYJX51cMu8iYHawE9ZiyhDlvvq1sM2D5GlUV43X3vyv8PglUew2KBxKp/Xtog8 APont/Dx/Tx9QKLRcPvJo1a+09leWpbMCJTo0FSEnPhx4pmOyOl8CI0vaA3HZxX6G1y0 0nyRwKrQOK2upqEf/TENb/sNw9bKr77cdHqls595OmiP5Gx/iSE5wn9EFZt48CODyBz3 SxMke/v+Vehf9GJHE/mW2qxrOTnLCElGhZMEb0R49poyhqfG4R6aPhtXVlukJ9C1xWcV pjIVpRhY8m2CpjdwySFEBVMD7UnEG4hVWtfm1YCj+JRg0V0pYbAFFQOfjhzNy2A3/rMn veEA== X-Gm-Message-State: AODbwcBaH5Os1wTRrfGocrSkTOmoT+OVnE8aCJUfed+2d4k+Xrcx7Ccy JpeXy8Aw58O/DSwL2K9UO4CkBZB52Q== X-Received: by 10.107.35.75 with SMTP id j72mr14778697ioj.180.1494268987053; Mon, 08 May 2017 11:43:07 -0700 (PDT) MIME-Version: 1.0 From: Eduardo Bustamante Date: Mon, 8 May 2017 13:42:46 -0500 Message-ID: Subject: Zsh parser segmentation fault in putpromptchar putpromptchar at prompt.c To: zsh-workers@zsh.org Cc: =?UTF-8?Q?Eduardo_A=2E_Bustamante_L=C3=B3pez?= Content-Type: multipart/mixed; boundary=001a1141b3622d8a03054f079cf1 --001a1141b3622d8a03054f079cf1 Content-Type: text/plain; charset=UTF-8 dualbus@debian:~/bash-fuzzing/zsh-parser$ base64 segfault JHsoJVUpWS0lKHZ9 dualbus@debian:~/bash-fuzzing/zsh-parser$ md5sum segfault 0d79a8c613315f32a453d5aa07a7de65 segfault dualbus@debian:~/bash-fuzzing/zsh-parser$ cat -v segfault ${(%U)Y-%(v} (gdb) r -n segfault Starting program: /home/dualbus/src/zsh/zsh/Src/zsh -n segfault [Thread debugging using libthread_db enabled] Using host libthread_db library "/lib/x86_64-linux-gnu/libthread_db.so.1". Program received signal SIGSEGV, Segmentation fault. 0x00000000004aab3e in putpromptchar (doprint=1, endchar=0, txtchangep=0x0) at prompt.c:403 403 if (*psvar[(arg ? arg : 1) - 1]) (gdb) bt #0 0x00000000004aab3e in putpromptchar (doprint=1, endchar=0, txtchangep=0x0) at prompt.c:403 #1 0x00000000004aa170 in promptexpand (s=0x7ffff7e5b3f8 "%(V", ns=0, rs=0x0, Rs=0x0, txtchangep=0x0) at prompt.c:215 #2 0x00000000004bd792 in paramsubst (l=0x7fffffffbfa0, n=0x7ffff7e5b3d8, str=0x7fffffffb950, qt=0, pf_flags=0, ret_flags=0x7fffffffbf2c) at subst.c:3589 #3 0x00000000004b4fe3 in stringsubst (list=0x7fffffffbfa0, node=0x7ffff7e5b3d8, pf_flags=0, ret_flags=0x7fffffffbf2c, asssub=0) at subst.c:247 #4 0x00000000004b4395 in prefork (list=0x7fffffffbfa0, flags=0, ret_flags=0x7fffffffbf2c) at subst.c:85 #5 0x0000000000440df5 in execcmd_getargs (preargs=0x7ffff7e5b3c0, args=0x7ffff7e5b380, expand=1) at exec.c:2659 #6 0x000000000043c1eb in execcmd_exec (state=0x7fffffffde40, eparams=0x7fffffffcd00, input=0, output=0, how=18, last1=2) at exec.c:2765 #7 0x000000000043b804 in execpline2 (state=0x7fffffffde40, pcode=131, how=18, input=0, output=0, last1=0) at exec.c:1873 #8 0x0000000000433f6e in execpline (state=0x7fffffffde40, slcode=3074, how=18, last1=0) at exec.c:1602 #9 0x0000000000432dfe in execlist (state=0x7fffffffde40, dont_change_job=0, exiting=0) at exec.c:1360 #10 0x000000000043277e in execode (p=0x7ffff7e5b320, dont_change_job=0, exiting=0, context=0x4d9174 "toplevel") at exec.c:1141 #11 0x000000000045e366 in loop (toplevel=1, justonce=0) at init.c:208 #12 0x00000000004627d6 in zsh_main (argc=3, argv=0x7fffffffe468) at init.c:1692 #13 0x0000000000411a32 in main (argc=3, argv=0x7fffffffe468) at ./main.c:93 --001a1141b3622d8a03054f079cf1 Content-Type: application/octet-stream; name=segfault Content-Disposition: attachment; filename=segfault Content-Transfer-Encoding: base64 X-Attachment-Id: f_j2gh570m0 JHsoJVUpWS0lKHZ9 --001a1141b3622d8a03054f079cf1--