tree-diff: catch integer overflow in combine_diff_path allocation
A combine_diff_path struct has two "flex" members allocated alongside the struct: a string to hold the pathname, and an array of parent pointers. We use an "int" to compute this, meaning we may easily overflow it if the pathname is extremely long. We can fix this by using size_t, and checking for overflow with the st_add helper. Signed-off-by: Jeff King <peff@peff.net> Signed-off-by: Junio C Hamano <gitster@pobox.com>
Jeff King committed
Feb 19, 2016 at 06:21 UTC
d770187872e8408a8e4c0533cf6e6913776882b0
2 files changed
+4
-4
diff.h
+2
-2
@@ -215,8 +215,8 @@ struct combine_diff_path {
215
} parent[FLEX_ARRAY];
216
};
217
#define combine_diff_path_size(n, l) \
218
- (sizeof(struct combine_diff_path) + \
219
- sizeof(struct combine_diff_parent) * (n) + (l) + 1)
218
+ st_add4(sizeof(struct combine_diff_path), (l), 1, \
219
+ st_mult(sizeof(struct combine_diff_parent), (n)))
220
221
extern void show_combined_diff(struct combine_diff_path *elem, int num_parent,
222
int dense, struct rev_info *);
tree-diff.c
+2
-2
@@ -124,8 +124,8 @@ static struct combine_diff_path *path_appendnew(struct combine_diff_path *last,
124
unsigned mode, const unsigned char *sha1)
125
{
126
struct combine_diff_path *p;
127
- int len = base->len + pathlen;
128
- int alloclen = combine_diff_path_size(nparent, len);
127
+ size_t len = st_add(base->len, pathlen);
128
+ size_t alloclen = combine_diff_path_size(nparent, len);
129
130
/* if last->next is !NULL - it is a pre-allocated memory, we can reuse */
131
p = last->next;