diff options
author | Kirill Simonov <xi@resolvent.net> | 2014-02-02 23:41:44 -0600 |
---|---|---|
committer | Kirill Simonov <xi@resolvent.net> | 2014-02-02 23:41:44 -0600 |
commit | c201bf64fa16fb65b11624dacc24d96a46604f02 (patch) | |
tree | 100539bb27c3ea16e8d94cb92e766b5bbc3f9211 /src | |
parent | bb8ab829a252b2ecf328df9c152a96198e4cc8f6 (diff) | |
download | libyaml-git-c201bf64fa16fb65b11624dacc24d96a46604f02.tar.gz |
Guard against overflows in indent and flow_level.
Diffstat (limited to 'src')
-rw-r--r-- | src/scanner.c | 20 | ||||
-rw-r--r-- | src/yaml_private.h | 1 |
2 files changed, 14 insertions, 7 deletions
diff --git a/src/scanner.c b/src/scanner.c index 68fc002..cf68d97 100644 --- a/src/scanner.c +++ b/src/scanner.c @@ -615,11 +615,11 @@ yaml_parser_decrease_flow_level(yaml_parser_t *parser); */ static int -yaml_parser_roll_indent(yaml_parser_t *parser, int column, - int number, yaml_token_type_t type, yaml_mark_t mark); +yaml_parser_roll_indent(yaml_parser_t *parser, ptrdiff_t column, + ptrdiff_t number, yaml_token_type_t type, yaml_mark_t mark); static int -yaml_parser_unroll_indent(yaml_parser_t *parser, int column); +yaml_parser_unroll_indent(yaml_parser_t *parser, ptrdiff_t column); /* * Token fetchers. @@ -1103,7 +1103,7 @@ yaml_parser_save_simple_key(yaml_parser_t *parser) */ int required = (!parser->flow_level - && parser->indent == (int)parser->mark.column); + && parser->indent == (ptrdiff_t)parser->mark.column); /* * A simple key is required only when it is the first token in the current @@ -1176,6 +1176,9 @@ yaml_parser_increase_flow_level(yaml_parser_t *parser) /* Increase the flow level. */ + if (parser->flow_level == INT_MAX) + return 0; + parser->flow_level++; return 1; @@ -1206,8 +1209,8 @@ yaml_parser_decrease_flow_level(yaml_parser_t *parser) */ static int -yaml_parser_roll_indent(yaml_parser_t *parser, int column, - int number, yaml_token_type_t type, yaml_mark_t mark) +yaml_parser_roll_indent(yaml_parser_t *parser, ptrdiff_t column, + ptrdiff_t number, yaml_token_type_t type, yaml_mark_t mark) { yaml_token_t token; @@ -1226,6 +1229,9 @@ yaml_parser_roll_indent(yaml_parser_t *parser, int column, if (!PUSH(parser, parser->indents, parser->indent)) return 0; + if (column > INT_MAX) + return 0; + parser->indent = column; /* Create a token and insert it into the queue. */ @@ -1254,7 +1260,7 @@ yaml_parser_roll_indent(yaml_parser_t *parser, int column, static int -yaml_parser_unroll_indent(yaml_parser_t *parser, int column) +yaml_parser_unroll_indent(yaml_parser_t *parser, ptrdiff_t column) { yaml_token_t token; diff --git a/src/yaml_private.h b/src/yaml_private.h index f835d3d..f248383 100644 --- a/src/yaml_private.h +++ b/src/yaml_private.h @@ -7,6 +7,7 @@ #include <assert.h> #include <limits.h> +#include <stddef.h> /* * Memory management. |