Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions lib/clangimport.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -431,6 +431,8 @@ std::string clangimport::AstNode::getSpelling() const
if (typeIndex <= 0)
return "";
}
if (typeIndex <= 0)
return "";
Comment on lines +434 to +435

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is an AI review. Take it with a grain of salt and feel free to reject it by resolving the comment.

The fix looks correct. I verified that the new crash2 test fails on main (built with -D_GLIBCXX_ASSERTIONS: Assertion '__n < this->size()' failed in getSpelling()) and passes with this PR.

The description says the guard is hoisted, but the two existing if (typeIndex <= 0) return ""; checks in the FunctionDecl/CXXConstructorDecl/CXXMethodDecl and DeclRefExpr branches above are kept. They are now redundant, since this new check covers them. Maybe remove them so there is only one guard? I tried that locally and TestClangImport still passes.

const std::string &str = mExtTokens[typeIndex - 1];
if (startsWith(str,"col:"))
return "";
Expand Down
8 changes: 8 additions & 0 deletions test/testclangimport.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -139,6 +139,7 @@ class TestClangImport : public TestFixture {
TEST_CASE(valueType2);

TEST_CASE(crash);
TEST_CASE(crash2);
}

std::string parse(const char clang[]) {
Expand Down Expand Up @@ -1372,6 +1373,13 @@ class TestClangImport : public TestFixture {
" `-CompoundStmt 0x5603791b5700 <col:54, col:55>\n";
(void)parse(clang); // don't crash
}

void crash2() {
// getSpelling() indexed mExtTokens[typeIndex - 1] without a lower-bound
// check, so a node whose line carries no ext tokens (typeIndex <= 0) read
// out of bounds.
(void)parse("`-RecordDecl "); // don't crash
}
};

REGISTER_TEST(TestClangImport)