Skip to content

fix(teletypewriter): return Err from tty_ptsname on null ptsname() - #1959

Open
tk1475 wants to merge 1 commit into
raphamorim:mainfrom
tk1475:fix-ptsname-null
Open

tk1475 wants to merge 1 commit into
raphamorim:mainfrom
tk1475:fix-ptsname-null

Conversation

@tk1475

@tk1475 tk1475 commented Sep 25, 2026

Copy link
Copy Markdown

tty_ptsname is a safe function, but it passed the result of ptsname() straight to CStr::from_ptr. ptsname() returns null when the fd is not a pty main, so something like tty_ptsname(-1) was undefined behavior from safe code (it segfaults on macOS).

This checks for null first and returns the errno message as an Err. The two existing callers already handle Err with unwrap_or_else, so nothing else changes. I also dropped the stale "Unsafe" note from the doc comment, since the function is not unsafe fn.

Testing

  • Added ptsname_tests in teletypewriter/src/unix/mod.rs: tty_ptsname(-1) returns Err, and a real posix_openpt main returns a /dev/... path.
  • The new invalid_fd_returns_err test crashes with SIGSEGV on current main and passes with the fix.
  • cargo test -p teletypewriter, cargo fmt -- --check, cargo clippy -p teletypewriter --all-targets --all-features all pass (macOS arm64).

I used Claude Code to help with this change and reviewed and tested it myself.

Fixes #1953

🤖 Generated with Claude Code

ptsname() returns a null pointer when the fd is not a pty main, and
tty_ptsname passed it straight to CStr::from_ptr, which is undefined
behavior reachable from safe code (e.g. tty_ptsname(-1) segfaults).
Check for null first and return the errno message as an error.

Fixes raphamorim#1953

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

tty_ptsname is a safe function that builds a CStr from a possibly null ptsname()

1 participant