diff options
| author | 2026-09-27 15:06:22 +0900 | |
|---|---|---|
| committer | 2026-09-29 16:39:28 +0200 | |
| commit | f168c10b52325b00da6355989a18a11743b33f89 (patch) | |
| tree | 186ef3afe45963fcfca15daf8efebf0f2151360e /src/xplist.c | |
| parent | 8b48fa72d359de89215f50cbf6ac8c77ae5de9b4 (diff) | |
| download | libplist-f168c10b52325b00da6355989a18a11743b33f89.tar.gz libplist-f168c10b52325b00da6355989a18a11743b33f89.tar.bz2 | |
bytearray: Handle realloc() failure in byte_array_grow()
byte_array_grow() assigned the result of realloc() directly to
ba->data and increased the capacity even if realloc() failed, so the
following memcpy() in byte_array_append() wrote to NULL + len.
On failure, free the old buffer and leave the byte array in a failed
state (data == NULL), which byte_array_append() already ignores. The
callers check for that state:
- the writers (bin, xml, json, openstep and the text output formats)
return PLIST_ERR_NO_MEM instead of handing out a NULL/truncated buffer
- node_to_xml() base64-encodes <data> directly into the grown buffer,
so it must bail out there (only guarded by assert() before)
- the OpenStep parser returns PLIST_ERR_NO_MEM for <hex data> instead of
silently returning truncated data
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'src/xplist.c')
| -rw-r--r-- | src/xplist.c | 10 |
1 files changed, 10 insertions, 0 deletions
diff --git a/src/xplist.c b/src/xplist.c index b2c134e..4e6e009 100644 --- a/src/xplist.c +++ b/src/xplist.c @@ -279,6 +279,9 @@ static plist_err_t node_to_xml(node_t node, bytearray_t **outbuf, uint32_t depth size_t amount = (node_data->length / 3 * 4) + 4 + (((node_data->length / maxread) + 1) * (indent+1)); if ((*outbuf)->len + amount > (*outbuf)->capacity) { str_buf_grow(*outbuf, amount); + if (!(*outbuf)->data) { + return PLIST_ERR_NO_MEM; + } } while (j < node_data->length) { for (i = 0; i < indent; i++) { @@ -545,6 +548,13 @@ plist_err_t plist_to_xml(plist_t plist, char **plist_xml, uint32_t * length) str_buf_append(outbuf, XML_PLIST_EPILOG, sizeof(XML_PLIST_EPILOG)); + if (!outbuf->data) { + str_buf_free(outbuf); + *plist_xml = NULL; + *length = 0; + return PLIST_ERR_NO_MEM; + } + *plist_xml = (char*)outbuf->data; *length = outbuf->len - 1; |
