From 11b369925287a7706e8d6cab759263ef9192c5f3 Mon Sep 17 00:00:00 2001 From: zeertzjq Date: Thu, 15 Jan 2026 13:53:39 +0800 Subject: [PATCH 1/4] vim-patch:9.1.0700: crash with 2byte encoding and glob2regpat() Problem: possible crash with 2byte encoding and glob2regpat() Solution: Skip over character, if it is multi-byte character https://github.com/vim/vim/commit/1c815b54bbaf872c271d58043e51e56b908c1a20 Co-authored-by: Christian Brabandt --- src/nvim/fileio.c | 1 - test/old/testdir/crash/heap_overflow_glob2regpat | Bin 0 -> 200 bytes test/old/testdir/test_crash.vim | 6 ++++++ 3 files changed, 6 insertions(+), 1 deletion(-) create mode 100644 test/old/testdir/crash/heap_overflow_glob2regpat diff --git a/src/nvim/fileio.c b/src/nvim/fileio.c index 403f455b89..afd1d6d1a4 100644 --- a/src/nvim/fileio.c +++ b/src/nvim/fileio.c @@ -3754,7 +3754,6 @@ char *file_pat_to_reg_pat(const char *pat, const char *pat_end, char *allow_dirs *allow_dirs = true; } reg_pat[i++] = '\\'; - reg_pat[i++] = *p; } break; #ifdef BACKSLASH_IN_FILENAME diff --git a/test/old/testdir/crash/heap_overflow_glob2regpat b/test/old/testdir/crash/heap_overflow_glob2regpat new file mode 100644 index 0000000000000000000000000000000000000000..8baf6f32533cc548c58dcc6152292e7f23b59345 GIT binary patch literal 200 zcmcC2PE|xpGxfnKO%iGyGTK%1L5mU|=Zb%56<$a{B+DD@n1gx;iH*zoaNL uJ)=amI*9p2O3Z&9t^Yp3K0O77i46=444Ju!ISk!lsimc*!KI}IG28&Su0MPL literal 0 HcmV?d00001 diff --git a/test/old/testdir/test_crash.vim b/test/old/testdir/test_crash.vim index 80b0d3f722..4f13949fc6 100644 --- a/test/old/testdir/test_crash.vim +++ b/test/old/testdir/test_crash.vim @@ -226,6 +226,12 @@ func Test_crash1_3() call term_sendkeys(buf, args) call TermWait(buf, 150) + let file = 'crash/heap_overflow_glob2regpat' + let cmn_args = "%s -u NONE -i NONE -n -X -m -n -e -s -S %s -c ':qa!'" + let args = printf(cmn_args, vim, file) + call term_sendkeys(buf, args) + call TermWait(buf, 50) + " clean up exe buf .. "bw!" From 0de85e322a83282ad63fb07014a8530bbe05c6e3 Mon Sep 17 00:00:00 2001 From: zeertzjq Date: Thu, 15 Jan 2026 13:56:05 +0800 Subject: [PATCH 2/4] vim-patch:9.1.0701: crash with NFA regex engine when searching for composing chars Problem: crash with NFA regex engine when searching for composing chars (SuyueGuo) Solution: When there is no composing character, break out of the loop and check that out1 state is not null fixes: vim/vim#15583 https://github.com/vim/vim/commit/c3a02d78bd7a4622e85af348b24fb1388d160de1 Test uses DBCS 'encoding', which is N/A. Co-authored-by: Christian Brabandt --- src/nvim/regexp.c | 3 ++- test/old/testdir/crash/nullptr_regexp_nfa | Bin 0 -> 429 bytes test/old/testdir/test_crash.vim | 5 +++++ 3 files changed, 7 insertions(+), 1 deletion(-) create mode 100644 test/old/testdir/crash/nullptr_regexp_nfa diff --git a/src/nvim/regexp.c b/src/nvim/regexp.c index 9a0c424011..451debf940 100644 --- a/src/nvim/regexp.c +++ b/src/nvim/regexp.c @@ -14799,7 +14799,8 @@ static int nfa_regmatch(nfa_regprog_T *prog, nfa_state_T *start, regsubs_T *subm result = FAIL; } - if (t->state->out->out1->c == NFA_END_COMPOSING) { + if (t->state->out->out1 != NULL + && t->state->out->out1->c == NFA_END_COMPOSING) { end = t->state->out->out1; ADD_STATE_IF_MATCH(end); } diff --git a/test/old/testdir/crash/nullptr_regexp_nfa b/test/old/testdir/crash/nullptr_regexp_nfa new file mode 100644 index 0000000000000000000000000000000000000000..6b2edc62a36f64d27231ae5eb2b7959cbcbd4510 GIT binary patch literal 429 zcmdPXOU-=29HYRM_rF-!!rab}t2i?!HLpZ5FTW^veGtn_ku%%2ZQCZmRh(a>P+FwG zz?JtuB__GFs656pCNI^YI90)+COVDFsyJ04H7_|oB{MJG)+nj6BvrSxBu&@QOd(Z4 z*HA&*(C|N3JVRJ2SCk=FPB8;liZ%>1{MT)mq^+%;Iny#PzeG1tw$>Q0|!NBo;HY!YG^9N(2Sf^?UYg{brr}>sOB4LgPa%*abhl5zd>$Iv;hFtnUWg- literal 0 HcmV?d00001 diff --git a/test/old/testdir/test_crash.vim b/test/old/testdir/test_crash.vim index 4f13949fc6..ba11a94e06 100644 --- a/test/old/testdir/test_crash.vim +++ b/test/old/testdir/test_crash.vim @@ -232,6 +232,11 @@ func Test_crash1_3() call term_sendkeys(buf, args) call TermWait(buf, 50) + let file = 'crash/nullptr_regexp_nfa' + let cmn_args = "%s -u NONE -i NONE -n -X -m -n -e -s -S %s -c ':qa!'" + let args = printf(cmn_args, vim, file) + call term_sendkeys(buf, args) + call TermWait(buf, 50) " clean up exe buf .. "bw!" From 8c31b3eeac4ea5be964dda8c33c7675c657ba5c0 Mon Sep 17 00:00:00 2001 From: zeertzjq Date: Thu, 15 Jan 2026 14:00:25 +0800 Subject: [PATCH 3/4] vim-patch:9.1.0702: Patch 9.1.0700 broke CI Problem: Patch 9.1.0700 broke CI Solution: Revert for now https://github.com/vim/vim/commit/f459d68ecfe40875da863bee100c45cb80e19b87 Co-authored-by: Christian Brabandt --- src/nvim/fileio.c | 1 + test/old/testdir/test_crash.vim | 10 +++++----- 2 files changed, 6 insertions(+), 5 deletions(-) diff --git a/src/nvim/fileio.c b/src/nvim/fileio.c index afd1d6d1a4..403f455b89 100644 --- a/src/nvim/fileio.c +++ b/src/nvim/fileio.c @@ -3754,6 +3754,7 @@ char *file_pat_to_reg_pat(const char *pat, const char *pat_end, char *allow_dirs *allow_dirs = true; } reg_pat[i++] = '\\'; + reg_pat[i++] = *p; } break; #ifdef BACKSLASH_IN_FILENAME diff --git a/test/old/testdir/test_crash.vim b/test/old/testdir/test_crash.vim index ba11a94e06..8425166bd6 100644 --- a/test/old/testdir/test_crash.vim +++ b/test/old/testdir/test_crash.vim @@ -226,11 +226,11 @@ func Test_crash1_3() call term_sendkeys(buf, args) call TermWait(buf, 150) - let file = 'crash/heap_overflow_glob2regpat' - let cmn_args = "%s -u NONE -i NONE -n -X -m -n -e -s -S %s -c ':qa!'" - let args = printf(cmn_args, vim, file) - call term_sendkeys(buf, args) - call TermWait(buf, 50) + " let file = 'crash/heap_overflow_glob2regpat' + " let cmn_args = "%s -u NONE -i NONE -n -X -m -n -e -s -S %s -c ':qa!'" + " let args = printf(cmn_args, vim, file) + " call term_sendkeys(buf, args) + " call TermWait(buf, 50) let file = 'crash/nullptr_regexp_nfa' let cmn_args = "%s -u NONE -i NONE -n -X -m -n -e -s -S %s -c ':qa!'" From 094d3dd3d41365061949cefc7eec105867869652 Mon Sep 17 00:00:00 2001 From: zeertzjq Date: Thu, 15 Jan 2026 14:03:04 +0800 Subject: [PATCH 4/4] vim-patch:9.1.0703: crash with 2byte encoding and glob2regpat() Problem: possible crash with 2-byte encoding and glob2regpat() (after v9.1.0700, v9.1.0702) Solution: include both bytes for a multi-byte character for an escaped character closes: vim/vim#15590 https://github.com/vim/vim/commit/c9bfed2fda8c23cc02325b1a7a6d84dc62bbea4b DBCS 'encoding' is N/A. Co-authored-by: Christian Brabandt --- test/old/testdir/test_crash.vim | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/test/old/testdir/test_crash.vim b/test/old/testdir/test_crash.vim index 8425166bd6..ba11a94e06 100644 --- a/test/old/testdir/test_crash.vim +++ b/test/old/testdir/test_crash.vim @@ -226,11 +226,11 @@ func Test_crash1_3() call term_sendkeys(buf, args) call TermWait(buf, 150) - " let file = 'crash/heap_overflow_glob2regpat' - " let cmn_args = "%s -u NONE -i NONE -n -X -m -n -e -s -S %s -c ':qa!'" - " let args = printf(cmn_args, vim, file) - " call term_sendkeys(buf, args) - " call TermWait(buf, 50) + let file = 'crash/heap_overflow_glob2regpat' + let cmn_args = "%s -u NONE -i NONE -n -X -m -n -e -s -S %s -c ':qa!'" + let args = printf(cmn_args, vim, file) + call term_sendkeys(buf, args) + call TermWait(buf, 50) let file = 'crash/nullptr_regexp_nfa' let cmn_args = "%s -u NONE -i NONE -n -X -m -n -e -s -S %s -c ':qa!'"