Skip to content

Guard GPOS mark attachment against attach_chain overflow - #480

Merged
behdad merged 1 commit into
harfbuzz:mainfrom
youdie006:mark-attach-chain-overflow
Oct 1, 2026
Merged

behdad merged 1 commit into
harfbuzz:mainfrom
youdie006:mark-attach-chain-overflow

Conversation

@youdie006

Copy link
Copy Markdown
Contributor

Mark attachment stores the distance to the base in attach_chain with (glyph_pos as isize - idx as isize) as i16 (harfrust/src/hb/ot/gpos/mark.rs:85), which truncates when a mark is more than i16::MAX glyphs after its base. HarfBuzz checks this in MarkArray::apply (MarkArray.hh, from harfbuzz#5636) and leaves the mark unattached; #411 ported the cursive half of that change.

x followed by 33000 U+0301 with --features=-mkmk and tests/fonts/rb_custom/BungeeTint-Regular.ttf: HarfBuzz 14.5 attaches the first 32768 marks at @-369,0 and leaves the remaining 232 at @0,0; main places those 232 at @368,0 (the chain wraps to a later glyph).

This checks the distance with i16::try_from before writing the offsets and, on overflow, sets attach_chain to 0 and moves on, as HarfBuzz does. Marks within range are unchanged.

mark_too_far_from_its_base_is_left_unattached sits next to the issue 384 tests in tests/shaping/regressions.rs; it fails on main. cargo fmt --check, cargo clippy -p harfrust --all-features --all-targets -D warnings and cargo test -p harfrust pass; I did not run the MSRV, no-default-features, icu or thumbv7em jobs. CHANGELOG entry added under Unreleased, as in #411.

Written with AI assistance (Claude); I have reviewed the change.

A mark more than i16::MAX glyphs after its base stored a truncated
attach_chain and was positioned relative to the wrong glyph. HarfBuzz
checks for this and leaves the mark unattached (MarkArray.hh). Do the
same, as harfbuzz#411 does for cursive attachment.
@behdad
behdad merged commit b609640 into harfbuzz:main Oct 1, 2026
3 checks passed
@behdad

behdad commented Oct 1, 2026

Copy link
Copy Markdown
Member

Thanks.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants