From 29950654067525c2895f2a10a39e3d0d732bce29 Mon Sep 17 00:00:00 2001 From: hanjinpeng Date: Thu, 17 Sep 2026 02:34:28 -0400 Subject: [PATCH] outer.c: fix recode_declare_single error path recode_find_alias returns NULL when it cannot allocate a new symbol, but its result was dereferenced before being checked. The cleanup code that followed was also wrong: it deleted an alias (and its symbol) still referenced by the alias table and symbol list, and it unlinked the single step without decrementing number_of_singles, so that recode_delete_outer would later walk past the end of the list. Check the aliases before using them, leave them to the alias table, and keep number_of_singles consistent. --- src/outer.c | 15 +++++++-------- 1 file changed, 7 insertions(+), 8 deletions(-) diff --git a/src/outer.c b/src/outer.c index 651162b..847a595 100644 --- a/src/outer.c +++ b/src/outer.c @@ -78,29 +78,28 @@ recode_declare_single (RECODE_OUTER outer, { single->before = outer->data_symbol; after = recode_find_alias (outer, after_name, SYMBOL_CREATE_DATA_SURFACE); - single->after = after->symbol; + single->after = after ? after->symbol : NULL; } else if (strcmp(after_name, "data") == 0) { before = recode_find_alias (outer, before_name, SYMBOL_CREATE_DATA_SURFACE); - single->before = before->symbol; + single->before = before ? before->symbol : NULL; single->after = outer->data_symbol; } else { before = recode_find_alias (outer, before_name, SYMBOL_CREATE_CHARSET); - single->before = before->symbol; + single->before = before ? before->symbol : NULL; after = recode_find_alias (outer, after_name, SYMBOL_CREATE_CHARSET); - single->after = after->symbol; + single->after = after ? after->symbol : NULL; } if (!single->before || !single->after) { - if (before) - recode_delete_alias (before); - if (after) - recode_delete_alias (after); + /* The aliases, if any, are owned by the alias table, which releases + them together with the outer. */ outer->single_list = single->next; + outer->number_of_singles--; free (single); return NULL; }