| Age | Commit message (Collapse) | Author | Files | Lines |
|
byte_array_grow() assigned the result of realloc() directly to
ba->data and increased the capacity even if realloc() failed, so the
following memcpy() in byte_array_append() wrote to NULL + len.
On failure, free the old buffer and leave the byte array in a failed
state (data == NULL), which byte_array_append() already ignores. The
callers check for that state:
- the writers (bin, xml, json, openstep and the text output formats)
return PLIST_ERR_NO_MEM instead of handing out a NULL/truncated buffer
- node_to_xml() base64-encodes <data> directly into the grown buffer,
so it must bail out there (only guarded by assert() before)
- the OpenStep parser returns PLIST_ERR_NO_MEM for <hex data> instead of
silently returning truncated data
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
|
ptr_array_insert() assigned the result of realloc() directly to
pa->pdata and bumped the capacity without checking for failure, so on
out-of-memory the old buffer was leaked and the following store or
memmove() wrote through a NULL pointer.
Keep the old buffer on failure and return -1 from ptr_array_insert()
and ptr_array_add(). The callers now handle the error:
- the array lookup cache (plist.c) is dropped instead of silently going
out of sync with the node list; lookups then fall back to walking
the children, as they do before the cache exists
- bplist parsing (used_indexes) and serialization (objects) return
PLIST_ERR_NO_MEM; ignoring the error in parse_bin_node_at_index()
would otherwise loop forever since the array never grows
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
|
|
|
Credit to OSSFuzz
|
|
|
|
Credit to @ylwango613
|
|
Fixes #285
Credit to @ylwango613 for reporting.
|
|
- Treat input as unsigned bytes
- Correct UTF-8 bit decoding for 2/3/4-byte sequences
- Add overlong, surrogate, and range checks
- Enforce lead/continuation byte constraints
This addresses issue #283.
Credit to @hgarrereyn for reporting.
|
|
|
|
Thanks to @unbengable12 for reporting. Addresses #288, #289, #290, #291, and #292.
|
|
|
|
Thanks to @LkkkLxy for pointing out the issue.
|
|
Credit to OSS-Fuzz
|
|
|
|
|
|
|
|
This prevents a bug class where we bswap things when __LITTLE_ENDIAN__ is not defined.
Almost all modern systems are little endian, so detecting __BIG_ENDIAN__ is a better strategy.
|
|
|
|
|
|
It is very confusing to handle the reallocation (buffer shrinking)
outside of the actual conversion function.
|
|
|
|
Credit to OSS-Fuzz
|
|
|
|
the format parses
This makes the `-d` option work in plistutil that wasn't doing anything
|
|
This makes the code more readable. Obviously all the code that uses it
is also updated.
|
|
|
|
This properly supports getting and setting signed or unsigned integer values.
Also, a new helper function plist_int_val_is_negative() was added to determine if
a given #PLIST_INT node has a negative value or not.
The old type PLIST_UINT is defined as a macro with the value of PLIST_INT for
backwards compatibility.
This commit also adds int vs. uint support to the C++ interface, and the python
bindings in a hopefully useful way.
|
|
This causes a warning if `-Wbad-function-cast` is enabled on a build.
|
|
Casting a float pointer to an int pointer is a strict aliasing
violation (-Wstrict-aliasing) and is undefined behaviour (although, it
did not seem to cause any real issues).
An optimising compiler should elide the memcopies added by this commit.
|
|
This way it can be easier determined why an import/export operation failed
instead of just having a NULL result.
|
|
|
|
Thanks to @azerg for bringing this to my attention.
Instead of having multiple (internally identical) plist_*_free() functions,
this commit introduces a single plist_mem_free() that can be used to free
the memory allocated by plist_to_xml(), plist_to_bin(), plist_get_key_val(),
plist_get_string_val(), and plist_get_data_val().
Note: This commit REMOVES plist_to_bin_free() and plist_to_xml_free().
|
|
[clang-tidy] Found with bugprone-macro-parentheses
Signed-off-by: Rosen Penev <rosenp@gmail.com>
|
|
|
|
|
|
[clang-tidy] Found with readability-redundant-control-flow
Signed-off-by: Rosen Penev <rosenp@gmail.com>
|
|
|
|
|
|
|
|
check
|
|
recursing check
This improves performance by at least 30% for large files, and also reduces the memory
footprint.
|
|
allocated by plist_to_bin()/plist_to_xml()
|
|
|
|
|
|
|
|
|
|
|
|
ASAN reported possible undefined behaviour when writing float/double
values to misaligned addresses.
|
|
These misaligned reads reported by ASAN might lead to undefined behavior.
|
|
Credit to Christophe Fergeau
|