чување 1798c93a8167147bf3a00be0b1ba8f5910547a5a
родитељ ce81d8bc85cb3b8f5c237283aa0d2e69f174f517
Аутор: Страхиња Радић <contact@strahinja.org>
Датум: Mon, 5 Jul 2021 23:02:31 +0200
Bugfix: prevent stack smashing
Signed-off-by: Страхиња Радић <contact@strahinja.org>
Diffstat:
| M | draw.c | | | 2 | +- |
| M | po.c | | | 44 | ++++++++++++++++++++++++++------------------ |
| M | util.c | | | 23 | ++++++++++++++--------- |
| M | util.h | | | 4 | ++-- |
измењених датотека: 4, додавања: 43(+), брисања: 30(-)
diff --git a/draw.c b/draw.c
@@ -221,7 +221,7 @@ draw_string(const int x, const int y, const uint16_t fg, const uint16_t bg,
uint32_t* us = calloc(strlen(s)+1, sizeof(uint32_t));
if (!us)
return NULL;
- u8_string_to_unicode(us, s);
+ u8_string_to_unicode(us, s, max_cols);
u32_draw_string(x, y, fg, bg, us, max_cols, fill_cols,
padding_left, padding_right, align);
free(us);
diff --git a/po.c b/po.c
@@ -96,7 +96,7 @@ set_msgid(struct PoEntry* entry, const char* msgid, int append)
uint32_t umsgid[MAXMSG];
if (!entry)
return NULL;
- u8_string_to_unicode(umsgid, msgid);
+ u8_string_to_unicode(umsgid, msgid, MAXMSG);
return u32_set_msgid(entry, umsgid, append);
}
@@ -106,7 +106,7 @@ set_msgid_plural(struct PoEntry* entry, const char* msgid_plural, int append)
uint32_t umsgid_plural[MAXMSG];
if (!entry)
return NULL;
- u8_string_to_unicode(umsgid_plural, msgid_plural);
+ u8_string_to_unicode(umsgid_plural, msgid_plural, MAXMSG);
return u32_set_msgid_plural(entry, umsgid_plural, append);
}
@@ -116,7 +116,7 @@ set_plural_forms(struct PoEntry* entry, const char* plural_forms, int append)
uint32_t uplural_forms[MAXMSG];
if (!entry)
return NULL;
- u8_string_to_unicode(uplural_forms, plural_forms);
+ u8_string_to_unicode(uplural_forms, plural_forms, MAXMSG);
return u32_set_plural_forms(entry, uplural_forms, append);
}
@@ -127,7 +127,7 @@ set_msgstr(struct PoEntry* entry, const char* msgstr, int msgstr_index,
uint32_t umsgstr[MAXMSG];
if (!entry)
return NULL;
- u8_string_to_unicode(umsgstr, msgstr);
+ u8_string_to_unicode(umsgstr, msgstr, MAXMSG);
return u32_set_msgstr(entry, umsgstr, msgstr_index, append);
}
@@ -401,7 +401,8 @@ save_file(const struct PoEntry* entries, const size_t msgid_count,
for (size_t c = 0; c < current->comment_lines; c++)
{
unicode_string_to_u8(u8_comment,
- *(current->comments + c));
+ *(current->comments + c),
+ MAXCOMMENTLINE * 6);
fprintf(output, "#%s\n", u8_comment);
}
}
@@ -412,7 +413,8 @@ save_file(const struct PoEntry* entries, const size_t msgid_count,
tc++)
{
unicode_string_to_u8(u8_trans_comment,
- *(current->trans_comments + tc));
+ *(current->trans_comments + tc),
+ MAXCOMMENTLINE * 6);
fprintf(output, "#.%s%s\n",
u8_trans_comment[0] == 0 ? "" :
" ",
@@ -452,7 +454,7 @@ save_file(const struct PoEntry* entries, const size_t msgid_count,
if (current->msgid)
{
char msgid[MAXMSG];
- unicode_string_to_u8(msgid, current->msgid);
+ unicode_string_to_u8(msgid, current->msgid, MAXMSG);
size_t num_lines = u32_lines_in_string(current->msgid);
if (num_lines > 1)
{
@@ -472,7 +474,7 @@ save_file(const struct PoEntry* entries, const size_t msgid_count,
size_t len = u32_strlen(
pmsgid_split->text);
unicode_string_to_u8(u8_msgid,
- pmsgid_split->text);
+ pmsgid_split->text, MAXMSG * 6);
if (!(last && len == 0))
fprintf(output, "\"%s%s\"\n",
u8_msgid, last ? "" :
@@ -488,7 +490,8 @@ save_file(const struct PoEntry* entries, const size_t msgid_count,
else
{
char u8_msgid[MAXMSG*6];
- unicode_string_to_u8(u8_msgid, current->msgid);
+ unicode_string_to_u8(u8_msgid, current->msgid,
+ MAXMSG * 6);
fprintf(output, "msgid \"%s\"\n", u8_msgid);
}
}
@@ -499,7 +502,7 @@ save_file(const struct PoEntry* entries, const size_t msgid_count,
{
char msgid_plural[MAXMSG];
unicode_string_to_u8(msgid_plural,
- current->msgid_plural);
+ current->msgid_plural, MAXMSG);
size_t num_lines = u32_lines_in_string(
current->msgid_plural);
if (num_lines > 1)
@@ -520,7 +523,7 @@ save_file(const struct PoEntry* entries, const size_t msgid_count,
size_t len = u32_strlen(
pmsgid_split->text);
unicode_string_to_u8(u8_msgid,
- pmsgid_split->text);
+ pmsgid_split->text, MAXMSG * 6);
if (!(last && len == 0))
fprintf(output, "\"%s%s\"\n",
u8_msgid, last ? "" :
@@ -537,7 +540,8 @@ save_file(const struct PoEntry* entries, const size_t msgid_count,
{
char u8_msgid[MAXMSG*6];
unicode_string_to_u8(u8_msgid,
- current->msgid_plural);
+ current->msgid_plural,
+ MAXMSG * 6);
fprintf(output, "msgid_plural \"%s\"\n",
u8_msgid);
}
@@ -581,7 +585,8 @@ save_file(const struct PoEntry* entries, const size_t msgid_count,
size_t len = u32_strlen(
pmsgstr_split->text);
unicode_string_to_u8(u8_msgstr,
- pmsgstr_split->text);
+ pmsgstr_split->text,
+ MAXMSG * 6);
if (first_entry && starts_with(
u8_msgstr,
@@ -619,7 +624,8 @@ save_file(const struct PoEntry* entries, const size_t msgid_count,
else
{
char u8_msgstr[MAXMSG*6];
- unicode_string_to_u8(u8_msgstr, *current->msgstr);
+ unicode_string_to_u8(u8_msgstr,
+ *current->msgstr, MAXMSG * 6);
fprintf(output, "msgstr \"%s\"\n", u8_msgstr);
}
}
@@ -649,7 +655,8 @@ save_file(const struct PoEntry* entries, const size_t msgid_count,
size_t len = u32_strlen(
pmsgstr_split->text);
unicode_string_to_u8(u8_msgstr,
- pmsgstr_split->text);
+ pmsgstr_split->text,
+ MAXMSG * 6);
if (!(last && len == 0))
fprintf(output,
"\"%s%s\"\n",
@@ -669,7 +676,8 @@ save_file(const struct PoEntry* entries, const size_t msgid_count,
{
char u8_msgstr[MAXMSG*6];
unicode_string_to_u8(u8_msgstr,
- *(current->msgstr + m));
+ *(current->msgstr + m),
+ MAXMSG * 6);
fprintf(output, "msgstr[%ld] \"%s\"\n",
m, u8_msgstr);
}
@@ -905,13 +913,13 @@ parse_po_line(const char* line, struct PoEntry** entries, size_t* entries_size,
else if (*state & PS_COMMENT)
{
uint32_t u32_token[MAXCOMMENTLINE];
- u8_string_to_unicode(u32_token, token);
+ u8_string_to_unicode(u32_token, token, MAXCOMMENTLINE);
u32_add_comment(*current_entry, u32_token);
}
else if (*state & PS_COMMENT_TRANS)
{
uint32_t u32_token[MAXCOMMENTLINE];
- u8_string_to_unicode(u32_token, token);
+ u8_string_to_unicode(u32_token, token, MAXCOMMENTLINE);
u32_add_trans_comment(*current_entry, u32_token);
}
else if (*state & PS_COMMENT_FLAG)
diff --git a/util.c b/util.c
@@ -11,42 +11,47 @@
#include "util.h"
size_t
-u8_string_to_unicode(uint32_t* us, const char* s)
+u8_string_to_unicode(uint32_t* us, const char* s, const size_t max)
{
uint32_t uch;
uint32_t* pus = us;
int u8_len = 0;
- size_t result = 0;
+ size_t added = 0;
while (s && *s && u8_len != TB_EOF)
{
u8_len = tb_utf8_char_to_unicode(&uch, s);
+ if (added + 2 > max)
+ break;
*pus++ = uch;
if (u8_len != TB_EOF)
{
s += u8_len;
- result++;
+ added++;
}
}
*pus++ = 0;
- return result;
+ return added;
}
-char*
-unicode_string_to_u8(char* s, const uint32_t* us)
+size_t
+unicode_string_to_u8(char* s, const uint32_t* us, const size_t max)
{
char ch[8];
const uint32_t* pus = us;
+ size_t added = 0;
*s = 0;
while (*pus)
{
int len = tb_utf8_unicode_to_char(ch, *pus);
ch[len] = 0;
+ if (added + len + 1 > max)
+ break;
strncat(s, ch, 8);
pus++;
}
- return s;
+ return added;
}
size_t
@@ -178,7 +183,7 @@ u32_u8_strncpy(uint32_t* to, const char* from, size_t max)
uint32_t* ufrom = calloc(strlen(from)+1, sizeof(uint32_t));
if (!ufrom)
return 0;
- u8_string_to_unicode(ufrom, from);
+ u8_string_to_unicode(ufrom, from, max);
size_t len = u32_strncpy(to, ufrom, max);
free(ufrom);
return len;
@@ -190,7 +195,7 @@ u8_u32_strncpy(char* to, const uint32_t* from, size_t max)
char* cfrom = calloc(u32_strlen(from)*6, 1);
if (!cfrom)
return 0;
- unicode_string_to_u8(cfrom, from);
+ unicode_string_to_u8(cfrom, from, max);
strncpy(to, cfrom, max);
to[max-1] = 0;
free(cfrom);
diff --git a/util.h b/util.h
@@ -21,8 +21,8 @@ enum {
#define MAXMSG 1024
#define MAXPATH 1024
-size_t u8_string_to_unicode(uint32_t* us, const char* s);
-char* unicode_string_to_u8(char* s, const uint32_t* us);
+size_t u8_string_to_unicode(uint32_t* us, const char* s, const size_t max);
+size_t unicode_string_to_u8(char* s, const uint32_t* us, const size_t max);
size_t u32_encode_tabs(uint32_t* s, size_t max);
size_t u32_decode_tabs(uint32_t* s, size_t max);
size_t u32_strlen(const uint32_t* s);