mirror of
https://github.com/jmcnamara/libxlsxwriter.git
synced 2026-10-05 06:10:24 -06:00
[GH-ISSUE #525] Segfault: scatter series with no categories, when the ranges are set with chart_series_set_values() #524
Labels
No labels
awaiting user feedback
bug
cmake
cmake
docs
feature request
in progress
long term
medium term
medium term
pull-request
question
question
ready to close
short term
under investigation
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
github-starred/libxlsxwriter#524
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @billdenney on GitHub (Jul 31, 2026).
Original GitHub issue: https://github.com/jmcnamara/libxlsxwriter/issues/525
chart_add_series()guards against a scatter series without categories:The guard only fires when the range is passed as a string.
chart.hdocuments an alternative:With both arguments
NULLthe conditionvalues && !categoriesis false, so the check is skipped. Ifchart_series_set_categories()is then not called,workbook_close()segfaults. This affects worksheets and chartsheets alike:All five scatter subtypes are affected.
Where
_chart_write_x_val()insrc/chart.cpasses the categories range on without checking->formula:leading to
_chart_write_num_ref()→_chart_write_f(self, NULL)→lxw_xml_data_element(..., data = NULL, ...)→_fprint_escaped_data()→strpbrk(NULL, "&<>").The non-scatter path does not crash, because
_chart_write_cat()returns early:Suggested fix
worksheet_insert_chart_opt()andchartsheet_set_chart_opt()each already walk the series list checkingvalues, so the categories check fits in the loop that is already there — three conditions in each of the two functions:and the same in
chartsheet.cwith thechartsheet_set_chart()/_opt():prefix.I built 1.2.4 with both hunks applied and re-ran the attached reprex: the four crashing cases print the warning and
workbook_close()returns 0, a scatter series with categories still writes an identical file, and the other cases are unchanged.Checking the return value is the whole test:
I haven't run your test suite, so I don't know where you'd want that — the unit tests I looked at are XML comparisons, which don't fit a return-code check.
Putting the check at insert time rather than adding a NULL guard to
_chart_write_x_val()is deliberate: a guard in the writer would stop the crash but emit a chart Excel cannot open, which seems worse than refusing.Not raising this as a PR — take or leave the patch.
Reprex
lxw_scatter_segfault.c: 13 cases, one per run, so a crash does not hide the others.
Cases 1, 11, 12 and 13 exit 139; the rest exit 0. The others confirm that the string form of the same mistake, missing values, missing both, NULL sheet names for the three
*_set_name_range()functions, and a NULL custom-label value are all handled — this is the only path I found that crashes.Related: #486 was a different NULL dereference in chart processing (invalid chart type
0), fixed on main.Found while adding chart support to the writexl R package, which builds series through the programmatic idiom throughout.
@billdenney commented on GitHub (Jul 31, 2026):
This is not causing an issue in production; it was noted during the process without major incident.
@jmcnamara commented on GitHub (Jul 31, 2026):
Thanks @billdenney. That looks like a bug. I'll look into it.