basic_command_line_parser::options() may store address of temporary

Open
#73 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
48/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
cpp
Domain
cli

Research direction

Start with include/boost/program_options/detail/parsers.hpp at the cited line and run the provided example, which passes a temporary from create() to options(). Compare the proposed copy and non-const-reference approaches for options() and positional(), then verify that the chosen behavior no longer permits a dangling reference or clearly documents the required lifetime.

Written by the indexing model from the issue text.

Description

Hi,

I've stambled accross a bug in my application about unrecognized options. After several minutes and checks I've realized it comes from Boost Program_Options because the basic_command_line_parser::options function store the address of a const-reference passed as argument. And since temporaries can bind to const-reference the library did use a dangling pointer.

It is not mentioned in the documentation that user must specify a valid reference.

I propose that options() and positional() make a copy (as it's backward compatible) or to take a non-const reference as it explains correctly the ownership to the caller (but not backward compatible)

Example of code that may reproduce the bug:

#include <boost/program_options.hpp>

namespace po = boost::program_options;

po::options_description create()
{
	po::options_description desc;

	desc.add_options()
		("verbose", po::bool_switch());

	return desc;
}

int main(int argc, char** argv)
{
	po::variables_map vm;
	po::store(po::command_line_parser(argc, argv).options(create()).run(), vm);
	po::notify(vm);
}

Offending code https://github.com/boostorg/program_options/blob/develop/include/boost/program_options/detail/parsers.hpp#L37

Dominant language
C++
Stars
136
Forks
117
PR merge metrics
No merged PRs in 30d

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from boostorg/program_options

All issues in boostorg/program_options

Similar issues

More C++ issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.