git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [musl] Re: Regression: git no longer works with musl libc's regex impl

From
RFRich Felker <dalias@libc.org>
Date
Oct 5, 2016, 13:15 UTC
Message-ID
<20161005131559.GG19318@brightrain.aerifal.cx>
In-Reply-To
<alpine.DEB.2.20.1610051250080.35196@virtualbox>
On Wed, Oct 05, 2016 at 01:17:49PM +0200, Johannes Schindelin wrote:
Show 16 quoted lines
> Hi Rich,
> 
> On Tue, 4 Oct 2016, Rich Felker wrote:
> 
> > On Tue, Oct 04, 2016 at 06:08:33PM +0200, Johannes Schindelin wrote:
> >
> > > And lastly, the best alternative would be to teach musl about
> > > REG_STARTEND, as it is rather useful a feature.
> > 
> > Maybe, but it seems fundamentally costly to support -- it's extra
> > state in the inner loops that imposes costly spill/reload on archs
> > with too few registers (x86).
> 
> It is true that it could cause that.
> 
> I had a brief look at the source code (you use backtracking...

Where did you get that idea? Backtracking is the most utterly incompetent way to implement regex -- it throws away the whole property that makes regex useful, being regular. Unfortunately, POSIX BRE is not regular, as it contains backreferences, so any implementation of regcomp/regexec requires at least a minimal backtracking code path for BREs that contain backreferences.

> hopefully
> nobody uses musl to parse regular expressions from untrusted, or

On the contrary, musl's is the only system reccomp/regexec I'm aware of that actually attempts to be safe with untrusted input -- when using REG_EXTENDED (ERE). Other implementations provide backreferences in ERE as an extension, making ERE unsafe just like BRE. musl intentionally disallows them as a feature.

At least until recently, glibc also crashed on malloc failures in regcomp, making it unsafe on untrusted input for that reason too.

Rich
Previous: Szabolcs NagyNext: James B
Message 11 of 28 in “Regression: git no longer works with musl libc's regex impl”
  1. Rich FelkerOct 4, 2016
  2. Jeff KingOct 4, 2016
  3. Rich FelkerOct 4, 2016
  4. Johannes SchindelinOct 4, 2016
  5. Rich FelkerOct 4, 2016
  6. Johannes SchindelinOct 4, 2016
  7. Ray DonnellyOct 4, 2016
  8. Rich FelkerOct 4, 2016
  9. Johannes SchindelinOct 5, 2016
  10. Szabolcs NagyOct 5, 2016
  11. Rich FelkerOct 5, 2016
  12. James BOct 4, 2016
  13. Rich FelkerOct 4, 2016
  14. Junio C HamanoOct 4, 2016
  15. Jakub NarębskiOct 5, 2016
  16. Rich FelkerOct 5, 2016
  17. Johannes SchindelinOct 5, 2016
  18. James BOct 5, 2016
  19. Jeff KingOct 5, 2016
  20. Rich FelkerOct 5, 2016
  21. Johannes SchindelinOct 6, 2016
  22. Ævar Arnfjörð BjarmasonOct 6, 2016
  23. Jeff KingOct 6, 2016
  24. Rich FelkerOct 6, 2016
  25. Jeff KingOct 6, 2016
  26. Ramsay JonesOct 6, 2016
  27. Jakub NarębskiOct 7, 2016
  28. Johannes SchindelinOct 4, 2016

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.