diff panics (`into_string().unwrap()`) on a non-UTF-8 argument ending in `--width=N`

未关闭 适合新手
#247 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
2/5
预计耗时
1-3 小时
新手友好度
85/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
冷清
技术栈
rust
领域
cli

调研方向

从 src/params.rs 中第 62-63 行附近的 width 和 tabsize 正则表达式开始,然后检查第 116 行附近的参数处理。使用 issue 中所示的非 UTF-8 --width 参数进行复现,并验证该参数会被当作文件操作数处理,而不是导致 panic 或被接受为选项;同时检查 xyz--width=5 的情况。

由索引模型根据 Issue 内容生成。

描述

Steps to reproduce

$ printf 'a\nb\nc\n' > A; printf 'a\nX\nc\n' > B
$ diffutils diff $'\xff--width=5' A B
thread 'main' panicked at src/params.rs:116:45:
called `Result::unwrap()` on an `Err` value: "\xFF--width=5"
$ echo $?
134

diff aborts (panic, exit 134) when given a non-UTF-8 argument whose lossy form ends in --width=<digits> — e.g. an argument with a leading invalid byte like $'\xff--width=5'.

Expected behavior

Match GNU: the unrecognized argument is a file operand; with three operands diff reports the extra operand and exits 2.

$ /usr/bin/diff $'\xff--width=5' A B
diff: extra operand 'B'
$ echo $?
2

Root cause

The --width regex lacks a start anchor, unlike the sibling --tabsize one:

// src/params.rs:62-63
let tabsize_re = Regex::new(r"^--tabsize=(?<num>\d+)$").unwrap();   // anchored — safe
let width_re   = Regex::new(r"--width=(?P<long>\d+)$").unwrap();    // no leading ^

// src/params.rs:115-116
if width_re.is_match(param.to_string_lossy().as_ref()) {   // matches lossy form
    let param = param.into_string().unwrap();              // line 116: Err on non-UTF-8

to_string_lossy() maps invalid bytes to U+FFFD, so a non-UTF-8 argument whose tail is --width=N still matches; into_string() then fails on the real bytes.
Fix: anchor the regex at the start (^--width=…$, matching tabsize_re), and/or match on the bytes / avoid into_string().unwrap() so a non-UTF-8 argument falls through to the operand path. (The unanchored regex also makes diff xyz--width=5 silently accept a width option instead of treating it as a filename — same root cause, non-panic symptom.)

Found by our static analysis tooling.

主要语言
Rust
星标
276
派生
39
平均合并
3 小时 27 分钟
30 天内合并 PR
3

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

uutils/diffutils 的其他 Issue

查看 uutils/diffutils 的全部 Issue

相似的 Issue

更多 Rust Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。