[committed] PR fortran/104849 - ICE in find_array_section, at fortran/expr.cc:1616

Message ID trinity-c26c42b9-b139-4088-bbcc-0f3759b81398-1646859858888@3c-app-gmx-bs60
State Committed
Headers
Series [committed] PR fortran/104849 - ICE in find_array_section, at fortran/expr.cc:1616 |

Commit Message

Harald Anlauf March 9, 2022, 9:04 p.m. UTC
  Dear all,

referencing an invalid array section could lead to a NULL pointer
dereference.  Testcase by Gerhard.

Committed to mainline as obvious after regtesting as

https://gcc.gnu.org/g:22015e77d3e45306077396b9de8a8a28bb67fb20

Thanks,
Harald
  

Patch

From 22015e77d3e45306077396b9de8a8a28bb67fb20 Mon Sep 17 00:00:00 2001
From: Harald Anlauf <anlauf@gmx.de>
Date: Wed, 9 Mar 2022 21:58:26 +0100
Subject: [PATCH] Fortran: improve error recovery on invalid array section

gcc/fortran/ChangeLog:

	PR fortran/104849
	* expr.cc (find_array_section): Avoid NULL pointer dereference on
	invalid array section.

gcc/testsuite/ChangeLog:

	PR fortran/104849
	* gfortran.dg/pr104849.f90: New test.
---
 gcc/fortran/expr.cc                    | 4 +++-
 gcc/testsuite/gfortran.dg/pr104849.f90 | 9 +++++++++
 2 files changed, 12 insertions(+), 1 deletion(-)
 create mode 100644 gcc/testsuite/gfortran.dg/pr104849.f90

diff --git a/gcc/fortran/expr.cc b/gcc/fortran/expr.cc
index c9c0ba4cc2e..86d61fed302 100644
--- a/gcc/fortran/expr.cc
+++ b/gcc/fortran/expr.cc
@@ -1594,7 +1594,9 @@  find_array_section (gfc_expr *expr, gfc_ref *ref)
 	{
 	  if ((begin && begin->expr_type != EXPR_CONSTANT)
 	      || (finish && finish->expr_type != EXPR_CONSTANT)
-	      || (step && step->expr_type != EXPR_CONSTANT))
+	      || (step && step->expr_type != EXPR_CONSTANT)
+	      || (!begin && !lower)
+	      || (!finish && !upper))
 	    {
 	      t = false;
 	      goto cleanup;
diff --git a/gcc/testsuite/gfortran.dg/pr104849.f90 b/gcc/testsuite/gfortran.dg/pr104849.f90
new file mode 100644
index 00000000000..ae221b5ba10
--- /dev/null
+++ b/gcc/testsuite/gfortran.dg/pr104849.f90
@@ -0,0 +1,9 @@ 
+! { dg-do compile }
+! PR fortran/104849 - ICE in find_array_section
+! Contributed by G.Steinmetz
+
+program p
+  integer, parameter :: a(:) = [1, 2] ! { dg-error "deferred shape" }
+  integer :: x(2)
+  data x /a(:)/                       ! { dg-error "Invalid" }
+end
--
2.34.1