https://gcc.gnu.org/g:5da256175a9f7a5f82afcd475ac71eb5c065fac8

commit r17-3811-g5da256175a9f7a5f82afcd475ac71eb5c065fac8
Author: Jørgen Kvalsvik <[email protected]>
Date:   Tue Sep 1 14:14:13 2026 +0200

    Check past-the-end before dereferencing iterator
    
    Guard the dereference in the case where the current cursor in the
    needle isn't a tombstone in case we're at the end of the
    haystack. Example pair:
    
      NEEDLE:   6 x x 4 6
      HAYSTACK: 4 6 x x 4
    
    We find the subsequence 6 4, but the needle is not yet at end (missing
    6) while the haystack is moved past the end:
    
      NEEDLE:   6 x x 4 6
                        ^
      HAYSTACK: 4 6 x x 4
                          ^
    
    If the haystack (super) is exhausted before the needle (sub) we know
    it isn't a proper subsequence, so this is the correct behaviour.
    
    This example was in the testsuite and caught by ASAN.
    
            PR gcov-profile/127038
    
    gcc/ChangeLog:
    
            * gcov.cc (tombstone_subsequence_p): Guard iterator
            dereference.

Diff:
---
 gcc/gcov.cc | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/gcc/gcov.cc b/gcc/gcov.cc
index 87deeadcc756..0ad48eb1b544 100644
--- a/gcc/gcov.cc
+++ b/gcc/gcov.cc
@@ -1015,7 +1015,7 @@ tombstone_subsequence_p (const vector<unsigned>& sub,
        if (yitr == yend)
          return false;
       }
-    else if (*yitr != *xitr)
+    else if (yitr == yend || *yitr != *xitr)
       return false;
 
   yitr = find_if_not (yitr, yend, tombstone_p);

Reply via email to