Lines 36-56
Link Here
|
36 |
* Developed by Arnaud Le Hors * |
36 |
* Developed by Arnaud Le Hors * |
37 |
\*****************************************************************************/ |
37 |
\*****************************************************************************/ |
38 |
|
38 |
|
|
|
39 |
/* October 2004, source code review by Thomas Biege <thomas@suse.de> */ |
40 |
|
41 |
|
39 |
#include "XpmI.h" |
42 |
#include "XpmI.h" |
40 |
|
43 |
|
41 |
LFUNC(WriteColors, int, (char **dataptr, unsigned int *data_size, |
44 |
LFUNC(WriteColors, int, (char **dataptr, unsigned int *data_size, |
42 |
unsigned int *used_size, XpmColor *colors, |
45 |
unsigned int *used_size, XpmColor *colors, |
43 |
unsigned int ncolors, unsigned int cpp)); |
46 |
unsigned int ncolors, unsigned int cpp)); |
44 |
|
47 |
|
45 |
LFUNC(WritePixels, void, (char *dataptr, unsigned int *used_size, |
48 |
LFUNC(WritePixels, void, (char *dataptr, unsigned int data_size, |
|
|
49 |
unsigned int *used_size, |
46 |
unsigned int width, unsigned int height, |
50 |
unsigned int width, unsigned int height, |
47 |
unsigned int cpp, unsigned int *pixels, |
51 |
unsigned int cpp, unsigned int *pixels, |
48 |
XpmColor *colors)); |
52 |
XpmColor *colors)); |
49 |
|
53 |
|
50 |
LFUNC(WriteExtensions, void, (char *dataptr, unsigned int *used_size, |
54 |
LFUNC(WriteExtensions, void, (char *dataptr, unsigned int data_size, |
|
|
55 |
unsigned int *used_size, |
51 |
XpmExtension *ext, unsigned int num)); |
56 |
XpmExtension *ext, unsigned int num)); |
52 |
|
57 |
|
53 |
LFUNC(ExtensionsSize, int, (XpmExtension *ext, unsigned int num)); |
58 |
LFUNC(ExtensionsSize, unsigned int, (XpmExtension *ext, unsigned int num)); |
54 |
LFUNC(CommentsSize, int, (XpmInfo *info)); |
59 |
LFUNC(CommentsSize, int, (XpmInfo *info)); |
55 |
|
60 |
|
56 |
int |
61 |
int |
Lines 93-103
Link Here
|
93 |
|
98 |
|
94 |
#undef RETURN |
99 |
#undef RETURN |
95 |
#define RETURN(status) \ |
100 |
#define RETURN(status) \ |
|
|
101 |
do \ |
96 |
{ \ |
102 |
{ \ |
97 |
if (ptr) \ |
103 |
if (ptr) \ |
98 |
XpmFree(ptr); \ |
104 |
XpmFree(ptr); \ |
99 |
return(status); \ |
105 |
return(status); \ |
100 |
} |
106 |
} while(0) |
101 |
|
107 |
|
102 |
int |
108 |
int |
103 |
XpmCreateBufferFromXpmImage(buffer_return, image, info) |
109 |
XpmCreateBufferFromXpmImage(buffer_return, image, info) |
Lines 111-117
Link Here
|
111 |
unsigned int cmts, extensions, ext_size = 0; |
117 |
unsigned int cmts, extensions, ext_size = 0; |
112 |
unsigned int l, cmt_size = 0; |
118 |
unsigned int l, cmt_size = 0; |
113 |
char *ptr = NULL, *p; |
119 |
char *ptr = NULL, *p; |
114 |
unsigned int ptr_size, used_size; |
120 |
unsigned int ptr_size, used_size, tmp; |
115 |
|
121 |
|
116 |
*buffer_return = NULL; |
122 |
*buffer_return = NULL; |
117 |
|
123 |
|
Lines 133-139
Link Here
|
133 |
#ifdef VOID_SPRINTF |
139 |
#ifdef VOID_SPRINTF |
134 |
used_size = strlen(buf); |
140 |
used_size = strlen(buf); |
135 |
#endif |
141 |
#endif |
136 |
ptr_size = used_size + ext_size + cmt_size + 1; |
142 |
ptr_size = used_size + ext_size + cmt_size + 1; /* ptr_size can't be 0 */ |
|
|
143 |
if(ptr_size <= used_size || |
144 |
ptr_size <= ext_size || |
145 |
ptr_size <= cmt_size) |
146 |
{ |
147 |
return XpmNoMemory; |
148 |
} |
137 |
ptr = (char *) XpmMalloc(ptr_size); |
149 |
ptr = (char *) XpmMalloc(ptr_size); |
138 |
if (!ptr) |
150 |
if (!ptr) |
139 |
return XpmNoMemory; |
151 |
return XpmNoMemory; |
Lines 144-150
Link Here
|
144 |
#ifndef VOID_SPRINTF |
156 |
#ifndef VOID_SPRINTF |
145 |
used_size += |
157 |
used_size += |
146 |
#endif |
158 |
#endif |
147 |
sprintf(ptr + used_size, "/*%s*/\n", info->hints_cmt); |
159 |
snprintf(ptr + used_size, ptr_size-used_size, "/*%s*/\n", info->hints_cmt); |
148 |
#ifdef VOID_SPRINTF |
160 |
#ifdef VOID_SPRINTF |
149 |
used_size += strlen(info->hints_cmt) + 5; |
161 |
used_size += strlen(info->hints_cmt) + 5; |
150 |
#endif |
162 |
#endif |
Lines 162-168
Link Here
|
162 |
#ifndef VOID_SPRINTF |
174 |
#ifndef VOID_SPRINTF |
163 |
l += |
175 |
l += |
164 |
#endif |
176 |
#endif |
165 |
sprintf(buf + l, " %d %d", info->x_hotspot, info->y_hotspot); |
177 |
snprintf(buf + l, sizeof(buf)-l, " %d %d", info->x_hotspot, info->y_hotspot); |
166 |
#ifdef VOID_SPRINTF |
178 |
#ifdef VOID_SPRINTF |
167 |
l = strlen(buf); |
179 |
l = strlen(buf); |
168 |
#endif |
180 |
#endif |
Lines 184-189
Link Here
|
184 |
l = strlen(buf); |
196 |
l = strlen(buf); |
185 |
#endif |
197 |
#endif |
186 |
ptr_size += l; |
198 |
ptr_size += l; |
|
|
199 |
if(ptr_size <= l) |
200 |
RETURN(XpmNoMemory); |
187 |
p = (char *) XpmRealloc(ptr, ptr_size); |
201 |
p = (char *) XpmRealloc(ptr, ptr_size); |
188 |
if (!p) |
202 |
if (!p) |
189 |
RETURN(XpmNoMemory); |
203 |
RETURN(XpmNoMemory); |
Lines 196-202
Link Here
|
196 |
#ifndef VOID_SPRINTF |
210 |
#ifndef VOID_SPRINTF |
197 |
used_size += |
211 |
used_size += |
198 |
#endif |
212 |
#endif |
199 |
sprintf(ptr + used_size, "/*%s*/\n", info->colors_cmt); |
213 |
snprintf(ptr + used_size, ptr_size-used_size, "/*%s*/\n", info->colors_cmt); |
200 |
#ifdef VOID_SPRINTF |
214 |
#ifdef VOID_SPRINTF |
201 |
used_size += strlen(info->colors_cmt) + 5; |
215 |
used_size += strlen(info->colors_cmt) + 5; |
202 |
#endif |
216 |
#endif |
Lines 212-218
Link Here
|
212 |
* 4 = 1 (for '"') + 3 (for '",\n') |
226 |
* 4 = 1 (for '"') + 3 (for '",\n') |
213 |
* 1 = - 2 (because the last line does not end with ',\n') + 3 (for '};\n') |
227 |
* 1 = - 2 (because the last line does not end with ',\n') + 3 (for '};\n') |
214 |
*/ |
228 |
*/ |
215 |
ptr_size += image->height * (image->width * image->cpp + 4) + 1; |
229 |
if(image->width > UINT_MAX / image->cpp || |
|
|
230 |
(tmp = image->width * image->cpp + 4) <= 4 || |
231 |
image->height > UINT_MAX / tmp || |
232 |
(tmp = image->height * tmp + 1) <= 1 || |
233 |
(ptr_size += tmp) <= tmp) |
234 |
RETURN(XpmNoMemory); |
216 |
|
235 |
|
217 |
p = (char *) XpmRealloc(ptr, ptr_size); |
236 |
p = (char *) XpmRealloc(ptr, ptr_size); |
218 |
if (!p) |
237 |
if (!p) |
Lines 224-240
Link Here
|
224 |
#ifndef VOID_SPRINTF |
243 |
#ifndef VOID_SPRINTF |
225 |
used_size += |
244 |
used_size += |
226 |
#endif |
245 |
#endif |
227 |
sprintf(ptr + used_size, "/*%s*/\n", info->pixels_cmt); |
246 |
snprintf(ptr + used_size, ptr_size-used_size, "/*%s*/\n", info->pixels_cmt); |
228 |
#ifdef VOID_SPRINTF |
247 |
#ifdef VOID_SPRINTF |
229 |
used_size += strlen(info->pixels_cmt) + 5; |
248 |
used_size += strlen(info->pixels_cmt) + 5; |
230 |
#endif |
249 |
#endif |
231 |
} |
250 |
} |
232 |
WritePixels(ptr + used_size, &used_size, image->width, image->height, |
251 |
WritePixels(ptr + used_size, ptr_size - used_size, &used_size, image->width, image->height, |
233 |
image->cpp, image->data, image->colorTable); |
252 |
image->cpp, image->data, image->colorTable); |
234 |
|
253 |
|
235 |
/* print extensions */ |
254 |
/* print extensions */ |
236 |
if (extensions) |
255 |
if (extensions) |
237 |
WriteExtensions(ptr + used_size, &used_size, |
256 |
WriteExtensions(ptr + used_size, ptr_size-used_size, &used_size, |
238 |
info->extensions, info->nextensions); |
257 |
info->extensions, info->nextensions); |
239 |
|
258 |
|
240 |
/* close the array */ |
259 |
/* close the array */ |
Lines 245-250
Link Here
|
245 |
return (XpmSuccess); |
264 |
return (XpmSuccess); |
246 |
} |
265 |
} |
247 |
|
266 |
|
|
|
267 |
|
248 |
static int |
268 |
static int |
249 |
WriteColors(dataptr, data_size, used_size, colors, ncolors, cpp) |
269 |
WriteColors(dataptr, data_size, used_size, colors, ncolors, cpp) |
250 |
char **dataptr; |
270 |
char **dataptr; |
Lines 254-260
Link Here
|
254 |
unsigned int ncolors; |
274 |
unsigned int ncolors; |
255 |
unsigned int cpp; |
275 |
unsigned int cpp; |
256 |
{ |
276 |
{ |
257 |
char buf[BUFSIZ]; |
277 |
char buf[BUFSIZ] = {0}; |
258 |
unsigned int a, key, l; |
278 |
unsigned int a, key, l; |
259 |
char *s, *s2; |
279 |
char *s, *s2; |
260 |
char **defaults; |
280 |
char **defaults; |
Lines 264-285
Link Here
|
264 |
|
284 |
|
265 |
defaults = (char **) colors; |
285 |
defaults = (char **) colors; |
266 |
s = buf + 1; |
286 |
s = buf + 1; |
|
|
287 |
if(cpp > (sizeof(buf) - (s-buf))) |
288 |
return(XpmNoMemory); |
267 |
strncpy(s, *defaults++, cpp); |
289 |
strncpy(s, *defaults++, cpp); |
268 |
s += cpp; |
290 |
s += cpp; |
269 |
|
291 |
|
270 |
for (key = 1; key <= NKEYS; key++, defaults++) { |
292 |
for (key = 1; key <= NKEYS; key++, defaults++) { |
271 |
if (s2 = *defaults) { |
293 |
if ((s2 = *defaults)) { |
272 |
#ifndef VOID_SPRINTF |
294 |
#ifndef VOID_SPRINTF |
273 |
s += |
295 |
s += |
274 |
#endif |
296 |
#endif |
275 |
sprintf(s, "\t%s %s", xpmColorKeys[key - 1], s2); |
297 |
/* assume C99 compliance */ |
|
|
298 |
snprintf(s, sizeof(buf) - (s-buf), "\t%s %s", xpmColorKeys[key - 1], s2); |
276 |
#ifdef VOID_SPRINTF |
299 |
#ifdef VOID_SPRINTF |
277 |
s += strlen(s); |
300 |
s += strlen(s); |
278 |
#endif |
301 |
#endif |
|
|
302 |
/* now let's check if s points out-of-bounds */ |
303 |
if((s-buf) > sizeof(buf)) |
304 |
return(XpmNoMemory); |
279 |
} |
305 |
} |
280 |
} |
306 |
} |
|
|
307 |
if(sizeof(buf) - (s-buf) < 4) |
308 |
return(XpmNoMemory); |
281 |
strcpy(s, "\",\n"); |
309 |
strcpy(s, "\",\n"); |
282 |
l = s + 3 - buf; |
310 |
l = s + 3 - buf; |
|
|
311 |
if( *data_size >= UINT_MAX-l || |
312 |
*data_size + l <= *used_size || |
313 |
(*data_size + l - *used_size) <= sizeof(buf)) |
314 |
return(XpmNoMemory); |
283 |
s = (char *) XpmRealloc(*dataptr, *data_size + l); |
315 |
s = (char *) XpmRealloc(*dataptr, *data_size + l); |
284 |
if (!s) |
316 |
if (!s) |
285 |
return (XpmNoMemory); |
317 |
return (XpmNoMemory); |
Lines 292-299
Link Here
|
292 |
} |
324 |
} |
293 |
|
325 |
|
294 |
static void |
326 |
static void |
295 |
WritePixels(dataptr, used_size, width, height, cpp, pixels, colors) |
327 |
WritePixels(dataptr, data_size, used_size, width, height, cpp, pixels, colors) |
296 |
char *dataptr; |
328 |
char *dataptr; |
|
|
329 |
unsigned int data_size; |
297 |
unsigned int *used_size; |
330 |
unsigned int *used_size; |
298 |
unsigned int width; |
331 |
unsigned int width; |
299 |
unsigned int height; |
332 |
unsigned int height; |
Lines 304-330
Link Here
|
304 |
char *s = dataptr; |
337 |
char *s = dataptr; |
305 |
unsigned int x, y, h; |
338 |
unsigned int x, y, h; |
306 |
|
339 |
|
|
|
340 |
if(height <= 1) |
341 |
return; |
342 |
|
307 |
h = height - 1; |
343 |
h = height - 1; |
308 |
for (y = 0; y < h; y++) { |
344 |
for (y = 0; y < h; y++) { |
309 |
*s++ = '"'; |
345 |
*s++ = '"'; |
310 |
for (x = 0; x < width; x++, pixels++) { |
346 |
for (x = 0; x < width; x++, pixels++) { |
311 |
strncpy(s, colors[*pixels].string, cpp); |
347 |
if(cpp >= (data_size - (s-dataptr))) |
|
|
348 |
return; |
349 |
strncpy(s, colors[*pixels].string, cpp); /* how can we trust *pixels? :-\ */ |
312 |
s += cpp; |
350 |
s += cpp; |
313 |
} |
351 |
} |
|
|
352 |
if((data_size - (s-dataptr)) < 4) |
353 |
return; |
314 |
strcpy(s, "\",\n"); |
354 |
strcpy(s, "\",\n"); |
315 |
s += 3; |
355 |
s += 3; |
316 |
} |
356 |
} |
317 |
/* duplicate some code to avoid a test in the loop */ |
357 |
/* duplicate some code to avoid a test in the loop */ |
318 |
*s++ = '"'; |
358 |
*s++ = '"'; |
319 |
for (x = 0; x < width; x++, pixels++) { |
359 |
for (x = 0; x < width; x++, pixels++) { |
320 |
strncpy(s, colors[*pixels].string, cpp); |
360 |
if(cpp >= (data_size - (s-dataptr))) |
|
|
361 |
return; |
362 |
strncpy(s, colors[*pixels].string, cpp); /* how can we trust *pixels? */ |
321 |
s += cpp; |
363 |
s += cpp; |
322 |
} |
364 |
} |
323 |
*s++ = '"'; |
365 |
*s++ = '"'; |
324 |
*used_size += s - dataptr; |
366 |
*used_size += s - dataptr; |
325 |
} |
367 |
} |
326 |
|
368 |
|
327 |
static int |
369 |
static unsigned int |
328 |
ExtensionsSize(ext, num) |
370 |
ExtensionsSize(ext, num) |
329 |
XpmExtension *ext; |
371 |
XpmExtension *ext; |
330 |
unsigned int num; |
372 |
unsigned int num; |
Lines 333-353
Link Here
|
333 |
char **line; |
375 |
char **line; |
334 |
|
376 |
|
335 |
size = 0; |
377 |
size = 0; |
|
|
378 |
if(num == 0) |
379 |
return(0); /* ok? */ |
336 |
for (x = 0; x < num; x++, ext++) { |
380 |
for (x = 0; x < num; x++, ext++) { |
337 |
/* 11 = 10 (for ',\n"XPMEXT ') + 1 (for '"') */ |
381 |
/* 11 = 10 (for ',\n"XPMEXT ') + 1 (for '"') */ |
338 |
size += strlen(ext->name) + 11; |
382 |
size += strlen(ext->name) + 11; |
339 |
a = ext->nlines; |
383 |
a = ext->nlines; /* how can we trust ext->nlines to be not out-of-bounds? */ |
340 |
for (y = 0, line = ext->lines; y < a; y++, line++) |
384 |
for (y = 0, line = ext->lines; y < a; y++, line++) |
341 |
/* 4 = 3 (for ',\n"') + 1 (for '"') */ |
385 |
/* 4 = 3 (for ',\n"') + 1 (for '"') */ |
342 |
size += strlen(*line) + 4; |
386 |
size += strlen(*line) + 4; |
343 |
} |
387 |
} |
344 |
/* 13 is for ',\n"XPMENDEXT"' */ |
388 |
/* 13 is for ',\n"XPMENDEXT"' */ |
|
|
389 |
if(size > UINT_MAX - 13) /* unlikely */ |
390 |
return(0); |
345 |
return size + 13; |
391 |
return size + 13; |
346 |
} |
392 |
} |
347 |
|
393 |
|
348 |
static void |
394 |
static void |
349 |
WriteExtensions(dataptr, used_size, ext, num) |
395 |
WriteExtensions(dataptr, data_size, used_size, ext, num) |
350 |
char *dataptr; |
396 |
char *dataptr; |
|
|
397 |
unsigned int data_size; |
351 |
unsigned int *used_size; |
398 |
unsigned int *used_size; |
352 |
XpmExtension *ext; |
399 |
XpmExtension *ext; |
353 |
unsigned int num; |
400 |
unsigned int num; |
Lines 358-381
Link Here
|
358 |
|
405 |
|
359 |
for (x = 0; x < num; x++, ext++) { |
406 |
for (x = 0; x < num; x++, ext++) { |
360 |
#ifndef VOID_SPRINTF |
407 |
#ifndef VOID_SPRINTF |
361 |
s += 11 + |
408 |
s += |
362 |
#endif |
409 |
#endif |
363 |
sprintf(s, ",\n\"XPMEXT %s\"", ext->name); |
410 |
snprintf(s, data_size - (s-dataptr), ",\n\"XPMEXT %s\"", ext->name); |
364 |
#ifdef VOID_SPRINTF |
411 |
#ifdef VOID_SPRINTF |
365 |
s += strlen(ext->name) + 11; |
412 |
s += strlen(ext->name) + 11; |
366 |
#endif |
413 |
#endif |
367 |
a = ext->nlines; |
414 |
a = ext->nlines; |
368 |
for (y = 0, line = ext->lines; y < a; y++, line++) { |
415 |
for (y = 0, line = ext->lines; y < a; y++, line++) { |
369 |
#ifndef VOID_SPRINTF |
416 |
#ifndef VOID_SPRINTF |
370 |
s += 4 + |
417 |
s += |
371 |
#endif |
418 |
#endif |
372 |
sprintf(s, ",\n\"%s\"", *line); |
419 |
snprintf(s, data_size - (s-dataptr), ",\n\"%s\"", *line); |
373 |
#ifdef VOID_SPRINTF |
420 |
#ifdef VOID_SPRINTF |
374 |
s += strlen(*line) + 4; |
421 |
s += strlen(*line) + 4; |
375 |
#endif |
422 |
#endif |
376 |
} |
423 |
} |
377 |
} |
424 |
} |
378 |
strcpy(s, ",\n\"XPMENDEXT\""); |
425 |
strncpy(s, ",\n\"XPMENDEXT\"", data_size - (s-dataptr)-1); |
379 |
*used_size += s - dataptr + 13; |
426 |
*used_size += s - dataptr + 13; |
380 |
} |
427 |
} |
381 |
|
428 |
|
Lines 386-391
Link Here
|
386 |
int size = 0; |
433 |
int size = 0; |
387 |
|
434 |
|
388 |
/* 5 = 2 (for "/_*") + 3 (for "*_/\n") */ |
435 |
/* 5 = 2 (for "/_*") + 3 (for "*_/\n") */ |
|
|
436 |
/* wrap possible but *very* unlikely */ |
389 |
if (info->hints_cmt) |
437 |
if (info->hints_cmt) |
390 |
size += 5 + strlen(info->hints_cmt); |
438 |
size += 5 + strlen(info->hints_cmt); |
391 |
|
439 |
|