From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mailgw.kylinos.cn (mailgw.kylinos.cn [124.126.103.232]) by sourceware.org (Postfix) with ESMTPS id 6BF394BA2E2A for ; Thu, 2 Apr 2026 06:26:13 +0000 (GMT) DMARC-Filter: OpenDMARC Filter v1.4.2 sourceware.org 6BF394BA2E2A Authentication-Results: sourceware.org; dmarc=none (p=none dis=none) header.from=kylinos.cn Authentication-Results: sourceware.org; spf=pass smtp.mailfrom=kylinos.cn ARC-Filter: OpenARC Filter v1.0.0 sourceware.org 6BF394BA2E2A Authentication-Results: server2.sourceware.org; arc=none smtp.remote-ip=124.126.103.232 ARC-Seal: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1775111174; cv=none; b=SIDqlykGAuRhMzgEIX61kMoJBcDbvMZT/6jLfp60dt9f1v10DUNiHlsOgxlA6J3Uc6N6gnf57X8BVf+UPJMKO4N3D7ToRzS7PY2gRvB0dD3z86D53pmiQeGmBgr46v8VAfO5MEHHFI8aXeKkenUSqfbU1Nj901hQktJM0VZkAeU= ARC-Message-Signature: i=1; a=rsa-sha256; d=sourceware.org; s=key; t=1775111174; c=relaxed/simple; bh=d2WORHAvW+1JX1gh/kS1L1nyV/VMkVRLYYi6eWuoMdY=; h=From:To:Subject:Date:Message-ID:MIME-Version; b=oiTLuaHK7K1bmxKVXr2N98Y3Lg2W0Xx6256VupHkrH78KIwrGmTv7982EOqBZK8e7tjiCgLQE/VoYW4wJiIQdD5udZa3mo0J2L2OxdcsqmWOhjhqlL2m5Wa35J129JSIKAhmg30nqdv75aHz1Pl7OsYnjnmTYAcbz/JGDejn2U4= ARC-Authentication-Results: i=1; server2.sourceware.org DKIM-Filter: OpenDKIM Filter v2.11.0 sourceware.org 6BF394BA2E2A X-UUID: d1a8c6642e5c11f1aa26b74ffac11d73-20260402 X-CTIC-Tags: HR_CC_COUNT, HR_CC_DOMAIN_COUNT, HR_CC_NAME, HR_CC_NO_NAME, HR_CTE_8B HR_CTT_MISS, HR_DATE_H, HR_DATE_WKD, HR_DATE_ZONE, HR_FROM_NAME HR_SJ_DIGIT_LEN, HR_SJ_LANG, HR_SJ_LEN, HR_SJ_LETTER, HR_SJ_NOR_SYM HR_SJ_PHRASE, HR_SJ_PHRASE_LEN, HR_SJ_WS, HR_TO_COUNT, HR_TO_DOMAIN_COUNT HR_TO_NO_NAME, IP_TRUSTED, SRC_TRUSTED, DN_TRUSTED, SA_TRUSTED SA_EXISTED, SN_TRUSTED, SN_EXISTED, SPF_NOPASS, DKIM_NOPASS DMARC_NOPASS, UD_TRUSTED, CIE_BAD, CIE_GOOD, CIE_GOOD_SPF GTI_FG_BS, GTI_C_CI, GTI_FG_IT, GTI_RG_INFO, GTI_C_BU AMN_GOOD, ABX_BLACK, ABX_EXPLOIT, ABX_MISS_RDNS X-CID-O-RULE: Release_Ham X-CID-RULE: Release_Ham X-CID-O-INFO: VERSION:1.3.12,REQID:b1e15022-9e49-4c0b-b649-4d68ec8d98d6,IP:20, URL:0,TC:0,Content:0,EDM:25,RT:0,SF:-5,FILE:0,BULK:0,RULE:Release_Ham,ACTI ON:release,TS:40 X-CID-INFO: VERSION:1.3.12,REQID:b1e15022-9e49-4c0b-b649-4d68ec8d98d6,IP:20,UR L:0,TC:0,Content:0,EDM:25,RT:0,SF:-5,FILE:0,BULK:0,RULE:Release_Ham,ACTION :release,TS:40 X-CID-META: VersionHash:e7bac3a,CLOUDID:7a6674ef9a43271d0e6b94dc0b14192e,BulkI D:260402142603WUH1M9FE,BulkQuantity:0,Recheck:0,SF:17|19|66|78|81|82|102|1 27|898,TC:nil,Content:0|15|50,EDM:5,IP:-2,URL:99|1,File:nil,RT:nil,Bulk:ni l,QS:nil,BEC:nil,COL:0,OSI:0,OSA:0,AV:0,LES:1,SPR:NO,DKR:0,DKP:0,BRR:0,BRE :0,ARC:0 X-CID-BVR: 2,SSN|SDN X-CID-BAS: 2,SSN|SDN,0,_ X-CID-FACTOR: TF_CID_SPAM_FSD,TF_CID_SPAM_ULS,TF_CID_SPAM_SNR,TF_CID_SPAM_FAS X-CID-RHF: D41D8CD98F00B204E9800998ECF8427E X-UUID: d1a8c6642e5c11f1aa26b74ffac11d73-20260402 X-User: gaoxiang@kylinos.cn Received: from fedora [(183.242.174.21)] by mailgw.kylinos.cn (envelope-from ) (Generic MTA with TLSv1.3 TLS_AES_256_GCM_SHA384 256/256) with ESMTP id 2030050291; Thu, 02 Apr 2026 14:26:01 +0800 From: Gao Xiang To: schwab@suse.de Cc: libc-alpha@sourceware.org, Xiang Gao Subject: [PATCH v3] libio: Fix wide stream backup buffer leak on fclose [BZ #33999] Date: Thu, 2 Apr 2026 14:25:44 +0800 Message-ID: <20260402062544.322321-1-gaoxiang@kylinos.cn> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spam-Status: No, score=-12.4 required=5.0 tests=BAYES_00,GIT_PATCH_0,KAM_DMARC_STATUS,SPF_HELO_NONE,SPF_PASS,TXREP,UNPARSEABLE_RELAY autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on sourceware.org List-Id: From: Xiang Gao This patch fixes a memory leak when ungetwc is used on a wide oriented stream. The backup buffer was never freed on fclose, causing a memory leak per ungetwc/fclose call. The leak has two causes: In iofclose.c, for wide streams (fp->mode > 0), _IO_new_fclose never calls _IO_free_wbackup_area. Fixed by adding the missing call. In wgenops.c, _IO_wdefault_finish checks fp->_IO_save_base (the narrow field, always NULL for wide streams) instead of fp->_wide_data->_IO_save_base, and uses a bare free() that leaves _IO_save_end and _IO_backup_base dangling. Replace the hand-rolled cleanup with _IO_have_wbackup/_IO_free_wbackup_area, which handles backup-mode switching and clears all three pointers. This was independently reported by Rocket Ma [1], whose patch corrects the condition but still uses the manual free path. Apply the same _IO_have_backup condition in genops.c for consistency. Tested by: make test t=libio/tst-wbackup-leak [1] https://patchwork.sourceware.org/project/glibc/patch/20260323171742.1039768-1-marocketbd@gmail.com/ Signed-off-by: Xiang Gao --- Thanks for the review, Andreas. The non-breaking spaces in the comment block were caused by a misconfigured vim setting on my local Fedora submission environment. Fixed now. I added a note in the test explaining that it relies on open_wmemstream not setting _IO_NO_READS on the stream. I will keep an eye on any future discussion or changes around open_wmemstream. Changes since v2: - Use regular spaces in comment block. - Notes the open_wmemstream limit in the test comment to make clear the assumption the test depends on. - Updates condition check on wide stream path in iofclose.c. - Adjust surrounding indentation to meet coding style. --- libio/Makefile | 1 + libio/genops.c | 7 ++---- libio/iofclose.c | 2 ++ libio/tst-wbackup-leak.c | 50 ++++++++++++++++++++++++++++++++++++++++ libio/wgenops.c | 7 ++---- 5 files changed, 57 insertions(+), 10 deletions(-) create mode 100644 libio/tst-wbackup-leak.c diff --git a/libio/Makefile b/libio/Makefile index 08e1e0ec25..93656466df 100644 --- a/libio/Makefile +++ b/libio/Makefile @@ -135,6 +135,7 @@ tests = \ tst-swscanf \ tst-ungetwc1 \ tst-ungetwc2 \ + tst-wbackup-leak \ tst-wfile-sync \ tst-wfiledoallocate-static \ tst-widetext \ diff --git a/libio/genops.c b/libio/genops.c index cc1684e00a..90e08e6571 100644 --- a/libio/genops.c +++ b/libio/genops.c @@ -636,11 +636,8 @@ _IO_default_finish (FILE *fp, int dummy) for (mark = fp->_markers; mark != NULL; mark = mark->_next) mark->_sbuf = NULL; - if (fp->_IO_save_base) - { - _IO_free_backup_buf (fp, fp->_IO_save_base); - fp->_IO_save_base = NULL; - } + if (_IO_have_backup (fp)) + _IO_free_backup_area (fp); _IO_un_link ((struct _IO_FILE_plus *) fp); diff --git a/libio/iofclose.c b/libio/iofclose.c index 89782e99d7..0ba85955bf 100644 --- a/libio/iofclose.c +++ b/libio/iofclose.c @@ -67,6 +67,8 @@ _IO_new_fclose (FILE *fp) _IO_FINISH (fp); if (fp->_mode > 0) { + if (_IO_have_wbackup (fp)) + _IO_free_wbackup_area (fp); /* This stream has a wide orientation. This means we have to free the conversion functions. */ struct _IO_codecvt *cc = fp->_codecvt; diff --git a/libio/tst-wbackup-leak.c b/libio/tst-wbackup-leak.c new file mode 100644 index 0000000000..8a3e0fc1ed --- /dev/null +++ b/libio/tst-wbackup-leak.c @@ -0,0 +1,50 @@ +/* Test _IO_wdefault_finish frees wide backup buffer [BZ #33999]. */ + +#include +#include +#include +#include + +static void +one_round (void) +{ + wchar_t *buf = NULL; + size_t size = 0; + + FILE *fp = open_wmemstream (&buf, &size); + TEST_VERIFY_EXIT (fp != NULL); + fputwc (L'A', fp); + fflush (fp); + /* Push back without prior read. read_ptr == read_base, so + _IO_wdefault_pbackfail skips the buggy narrow read_ptr access + (BZ #33998) and goes straight to allocating a wide backup + buffer at fp->_wide_data->_IO_save_base. + + Note: this testcase relies on the fact that open_wmemstream + does not set _IO_NO_READS on the stream. If that implementation + is changed, this test would need a different stream type to verify + the leak. */ + ungetwc (L'Z', fp); + fclose (fp); + free (buf); +} + +static int +do_test (void) +{ + /* Warm up to stabilize allocator state. */ + one_round (); + + struct mallinfo2 before = mallinfo2 (); + for (int i = 0; i < 1000; i++) + one_round (); + struct mallinfo2 after = mallinfo2 (); + + /* Each leak is 128 * sizeof(wchar_t) = 512 bytes. + * 1000 iterations would leak ~512 KB. Allow 4 KB noise. */ + TEST_VERIFY (after.uordblks - before.uordblks < 4096); + + return 0; +} + +#include diff --git a/libio/wgenops.c b/libio/wgenops.c index 064d71266d..6829477e0c 100644 --- a/libio/wgenops.c +++ b/libio/wgenops.c @@ -181,11 +181,8 @@ _IO_wdefault_finish (FILE *fp, int dummy) for (mark = fp->_markers; mark != NULL; mark = mark->_next) mark->_sbuf = NULL; - if (fp->_IO_save_base) - { - free (fp->_wide_data->_IO_save_base); - fp->_IO_save_base = NULL; - } + if (_IO_have_wbackup (fp)) + _IO_free_wbackup_area (fp); #ifdef _IO_MTSAFE_IO if (fp->_lock != NULL) -- 2.53.0