Zsh Mailing List Archive
Messages sorted by:
Reverse Date,
Date,
Thread,
Author
Fishy code in sticky emulation?
- X-seq: zsh-workers 34095
- From: Mikael Magnusson <mikachu@xxxxxxxxx>
- To: zsh workers <zsh-workers@xxxxxxx>
- Subject: Fishy code in sticky emulation?
- Date: Mon, 5 Jan 2015 15:34:00 +0100
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed;        d=gmail.com; s=20120113;        h=mime-version:date:message-id:subject:from:to:content-type;        bh=dDU6iw2Sh4D1FbGouJucHT2IBDfwQXN2zsmBhCFnn1A=;        b=YKWeV9eNyXlMWVoqkKqp52UBTyBflq0VceFrrbZ2FqmfYqa1UE5xXePY54UL6nC17m         PoOQohWVTAlDijot2U8ptjImwg8ScTiAaIXg1pyXhl7pIW23HuUrYCo9wpckPs567efs         ccIuF5SvsBggnX606LhzsnW9wwCbk1Uu3kMJhSwTVJOs50Lrt9f9InVt25t+WhK17V9r         hUeE1Oi3DUBhRXYskVff2+HcX20tWnthUX+/AU/jV58GV2lrFS3HWKlqPcHMKvzN7kXY         GwOkOqO6UxH5GDjiBc/fUIUFTAF6ogLnaWKo2S7hIwSgMvsBxGk89cmfSxpTK+gdWQHi         GqYg==
- List-help: <mailto:zsh-workers-help@zsh.org>
- List-id: Zsh Workers List <zsh-workers.zsh.org>
- List-post: <mailto:zsh-workers@zsh.org>
- Mailing-list: contact zsh-workers-help@xxxxxxx; run by ezmlm
I'm looking through Coverity issues (some patches to come later), and
it flagged this in builtin.c that I can't quite say for sure if it's
right or wrong about.
int
bin_emulate(UNUSED(char *nam), char **argv, Options ops, UNUSED(int func))
{
...
    if (sticky->n_on_opts)
      on_ptr = sticky->on_opts =
        zhalloc(sticky->n_on_opts * sizeof(*sticky->on_opts));
    else
      on_ptr = NULL;
    if (sticky->n_off_opts)
      off_ptr = sticky->off_opts = zhalloc(sticky->n_off_opts *
                                   sizeof(*sticky->off_opts));
    else
      off_ptr = NULL;
    for (optnode = firstnode(optlist); optnode; incnode(optnode)) {
      /* Data is index into new_opts */
      char *optptr = (char *)getdata(optnode);
      int optno = optptr - new_opts;
      if (*optptr)
        *on_ptr++ = optno;
      else
        *off_ptr++ = optno;
      }
...
In particular, on_ptr and off_ptr can be NULL, but unconditionally one
of them is always incremented in the for loop, which isn't very well
defined for a NULL pointer. Am I missing something, or are these
n_*_opts simply never 0?
-- 
Mikael Magnusson
Messages sorted by:
Reverse Date,
Date,
Thread,
Author