Skip to content

Memory unsafety in withFilePath in 2.8.2.0 #295

Description

@bgamari

Your environment

All.

Steps to reproduce

ghci> :set -XOverloadedStrings
ghci> import qualified Data.ByteString.Short as BSS
ghci> import Data.ByteString.Internal (c_strlen)
ghci> BSS.useAsCStringLen "ScriptEnv0.hs" $ \(ptr, len) -> c_strlen ptr >>= \clen -> print (clen, len)

Expected behaviour

(13,13)

Actual behaviour

ghci> :set -XOverloadedStrings
ghci> import qualified Data.ByteString.Short as BSS
ghci> import Data.ByteString.Internal (c_strlen)
ghci> BSS.useAsCStringLen "ScriptEnv0.hs" $ \(ptr, len) -> c_strlen ptr >>= \clen -> print (clen, len)
(13,13)
ghci> BSS.useAsCStringLen "ScriptEnv0.hs" $ \(ptr, len) -> c_strlen ptr >>= \clen -> print (clen, len)
(38,13)
ghci> BSS.useAsCStringLen "ScriptEnv0.hs" $ \(ptr, len) -> c_strlen ptr >>= \clen -> print (clen, len)
(29,13)
ghci> BSS.useAsCStringLen "ScriptEnv0.hs" $ \(ptr, len) -> c_strlen ptr >>= \clen -> print (clen, len)
(38,13)

This is due to https://github.com/haskell/unix/pull/279/files#diff-e155a859a7a42c152728c6296887607bcfe0a7b0213d98573053e137ed8ebb32R157, which incorrectly relies on strlen on a string produced with useCString. This was originally noted in haskell/cabal#9241.

Activity

  1. bgamari commented on Sep 13, 2023

    @bgamari
    ContributorAuthor

    This is fixed in #294.

  2. gbaz commented on Sep 13, 2023

    @gbaz

    Should the bytestring documentation be updated to more clearly warn about this footgun with the useAsCStringLen function?

  3. hasufell commented on Sep 16, 2023

    @hasufell
    Member

    Fixed in #294

    @Bodigrim are you making the 2.8.2.1 release?

  4. Bodigrim commented on Sep 16, 2023

    @Bodigrim
    Contributor

    If you have a moment, please do, otherwise I'll release in the morning.

  5. hasufell commented on Sep 16, 2023

    @hasufell
    Member
  6. hasufell commented on Sep 16, 2023

    @hasufell
    Member
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions