Commit 109eb1e7 authored by Philipp Stephani's avatar Philipp Stephani

Fix undefined behavior when fetching glyphs from the display vector.

You can trigger this rather obscure bug by enabling selective display
if the second glyph in its display vector has an invalid face.  For
example, evaluate

(set-display-table-slot standard-display-table
                        'selective-display [?A (?B . invalid)])

and then enable selective display.

* src/xdisp.c (next_element_from_display_vector): Check whether next
glyph code is valid before accessing it.
parent 78e1646b
Pipeline #7730 failed with stage
in 120 minutes and 1 second
......@@ -8221,10 +8221,10 @@ next_element_from_display_vector (struct it *it)
next_face_id = it->dpvec_face_id;
int lface_id =
GLYPH_CODE_FACE (it->dpvec[it->current.dpvec_index + 1]);
Lisp_Object gc = it->dpvec[it->current.dpvec_index + 1];
int lface_id = GLYPH_CODE_P (gc) ? GLYPH_CODE_FACE (gc) : 0;
if (lface_id > 0)
if (lface_id > 0)
next_face_id = merge_faces (it->w, Qt, lface_id,
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment