From 8b48fa72d359de89215f50cbf6ac8c77ae5de9b4 Mon Sep 17 00:00:00 2001 From: Comtea04 Date: Sun, 27 Sep 2026 15:06:22 +0900 Subject: ptrarray: Handle realloc() failure in ptr_array_insert() ptr_array_insert() assigned the result of realloc() directly to pa->pdata and bumped the capacity without checking for failure, so on out-of-memory the old buffer was leaked and the following store or memmove() wrote through a NULL pointer. Keep the old buffer on failure and return -1 from ptr_array_insert() and ptr_array_add(). The callers now handle the error: - the array lookup cache (plist.c) is dropped instead of silently going out of sync with the node list; lookups then fall back to walking the children, as they do before the cache exists - bplist parsing (used_indexes) and serialization (objects) return PLIST_ERR_NO_MEM; ignoring the error in parse_bin_node_at_index() would otherwise loop forever since the array never grows Co-Authored-By: Claude Opus 5.5 --- src/ptrarray.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) (limited to 'src/ptrarray.h') diff --git a/src/ptrarray.h b/src/ptrarray.h index ed67351..28a521f 100644 --- a/src/ptrarray.h +++ b/src/ptrarray.h @@ -31,8 +31,8 @@ typedef struct ptrarray_t { ptrarray_t *ptr_array_new(int capacity); void ptr_array_free(ptrarray_t *pa); -void ptr_array_add(ptrarray_t *pa, void *data); -void ptr_array_insert(ptrarray_t *pa, void *data, long index); +int ptr_array_add(ptrarray_t *pa, void *data); +int ptr_array_insert(ptrarray_t *pa, void *data, long index); void ptr_array_remove(ptrarray_t *pa, long index); void ptr_array_set(ptrarray_t *pa, void *data, long index); void* ptr_array_index(ptrarray_t *pa, long index); -- cgit v1.1-32-gdbae