Attached debdiff cfortran_20210827-1.1ubuntu1 for stonking.

Changes:
- debian/rules: pass -std=gnu17 in DEB_CFLAGS_MAINT_APPEND to restore C17 
function prototype semantics for the package testsuite under GCC 15.
- debian/patches/0002-fix-fstr-test-buffer-overflow.patch: allocate + 1 byte in 
eg/fstr/fstr.c to fix heap buffer overflow when strcpy writes the terminating 
NUL byte under _FORTIFY_SOURCE=3.

Tested on Ubuntu stonking (GCC 15.2.0, glibc 2.43):
- dpkg-buildpackage builds cleanly.
- dh_auto_test passes all 41 testsuites in eg/ (abc, cf14, e2, easy, eq, f0, 
f20, f27, fa, fb, fc, fcb, fd, fe, ff, fg, fh, fi, fj, fk, fl, fm, fn, forr, 
fstr, ft, fun, fz, pz, q, rev, rr, ss1, strtok, sub, subt, sz, sz1, user, v7, 
vv).
- cfortran_20210827-1.1ubuntu1_all.deb package generated successfully.

Forwarded to Debian BTS:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1114078

Upstream PR for buffer overflow:
https://github.com/bastien-roucaries/cfortran/pull/3


** Description changed:

+ [ Impact ]
+ cfortran 20210827-1.1 fails to build from source (FTBFS) in Ubuntu stonking 
under GCC 15. This blocks cfortran from migrating to stonking and holds up 
autopkgtests for reverse dependencies.
+ 
+ During package build, the testsuite fails with two distinct errors:
+ 1. GCC 15 defaults to C23, where empty parameter lists in prototypes mean 
strictly 0 arguments. The package testsuite exercises function pointer casts 
and legacy wrappers, failing with:
+    e2/e2.c:10:28: error: too many arguments to function 'easy_'; expected 0, 
have 2
+    q/q.c:15: error: passing 'int (*)(void)' to parameter of type 
'__compar_fn_t'
+ 2. Under default Ubuntu -D_FORTIFY_SOURCE=3, eg/fstr/fstr.c triggers heap 
buffer overflow termination because malloc(ls>lsave?ls:lsave) misses + 1 byte 
for the terminating NUL byte before strcpy.
+ 
+ [ Fix ]
+ 1. debian/rules: pass export DEB_CFLAGS_MAINT_APPEND = -std=gnu17 so the 
internal testsuite builds with C17 semantics.
+ 2. debian/patches/0002-fix-fstr-test-buffer-overflow.patch: allocate + 1 byte 
in eg/fstr/fstr.c to accommodate the terminating NUL byte under 
_FORTIFY_SOURCE=3.
+ 
+ [ Test Plan ]
+ 1. Build cfortran in stonking container with GCC 15:
+    dpkg-buildpackage -us -uc -b
+ 2. Verify all test binaries in eg/ are compiled and executed during 
dh_auto_test:
+    abc, cf14, e2, easy, eq, f0, f20, f27, fa, fb, fc, fcb, fd, fe, ff, fg, 
fh, fi, fj, fk, fl, fm, fn, forr, fstr, ft, fun, fz, pz, q, rev, rr, ss1, 
strtok, sub, subt, sz, sz1, user, v7, vv.
+ 3. Verify test exit code is 0 and cfortran_20210827-1.1ubuntu1_all.deb is 
generated cleanly.
+ 
+ [ Where problems could occur ]
+ - Scope is minimal: cfortran is an Architecture: all package distributing the 
header file /usr/include/cfortran/cfortran.h and examples.
+ - -std=gnu17 is appended to DEB_CFLAGS_MAINT_APPEND in debian/rules, 
affecting only the package build and its internal testsuite, with zero adverse 
impact on installed header files.
+ - The fstr test patch only affects the example test executable.
+ 
+ [ Other Info ]
+ - Debian Bug: #1114078 
(https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1114078). Patch forwarded to 
Debian BTS.
+ - Upstream PR for buffer overflow: 
https://github.com/bastien-roucaries/cfortran/pull/3
+ - Target series: stonking (Ubuntu 26.10 devel series).
+ - All 41 testsuites pass with 0 regressions.
+ 
+ --- [ Original Report ]
  cfortran 20210827-1.1 fails to build from source in stonking.
  
  Regressing architectures (built before, fail now): amd64.
  Build log(s):
    - 
https://launchpad.net/ubuntu/+source/cfortran/20210827-1.1/+build/32793393/+files/buildlog_ubuntu-stonking-amd64.cfortran_20210827-1.1_BUILDING.txt.gz
- Diagnosis (deterministic matcher): testsuite-failure — dh_auto_test.
+ Diagnosis (deterministic matcher): testsuite-failure - dh_auto_test.
  
  Root cause: GCC 15 defaults to C23, where an empty parameter list `()`
  means "no arguments". cfortran.h's PROTOCCALLSFFUN* macros
  (PROTOCCALLSFFUN2 -> VOID_cfG -> VOID_cfGZ -> CFC_, cfortran.h:1482/1494)
  declare Fortran routines as e.g. `easy_()` and then call them with
  arguments, so `make check` fails:
  
    e2/e2.c:10:28: error: too many arguments to function 'easy_'; expected
  0, have 2
  
  This is a toolchain-induced regression (20210827-1 last built with an
  older GCC); the source itself did not change in a relevant way.
  
  Existing reports:
    - Debian: https://bugs.debian.org/1114078 (serious, same error)
    - Debian (autopkgtest, same root cause): https://bugs.debian.org/1119857
    - Upstream: https://github.com/bastien-roucaries/cfortran/issues/2 (open, 
no fix)
    - Possibly also needed afterwards: 
https://github.com/bastien-roucaries/cfortran/pull/3
      (fstr_test coredump with -D_FORTIFY_SOURCE=3 -O2)
  
  Suggested workaround: build with -std=gnu17, e.g.
    export DEB_CFLAGS_MAINT_APPEND = -std=gnu17
  in debian/rules. Since cfortran.h is a header consumed by reverse
  dependencies, a proper fix needs cfortran.h to emit full prototypes.
  The autopkgtest block ("arch:all not built yet") will clear once the
  package builds.

** Changed in: cfortran (Ubuntu)
       Status: New => Confirmed

** Tags added: patch

** Patch added: "cfortran 20210827-1.1ubuntu1 debdiff for stonking"
   
https://bugs.launchpad.net/ubuntu/+source/cfortran/+bug/2168915/+attachment/6005168/+files/cfortran_20210827-1.1ubuntu1.debdiff

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2168915

Title:
  cfortran 20210827-1.1 FTBFS: C23 (GCC 15) rejects K&R-style prototypes
  in cfortran.h

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cfortran/+bug/2168915/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to