Merge pull request #40952 from zeertzjq/vim-9.2.0846

vim-patch:9.2.{0846,0854}
This commit is contained in:
zeertzjq
2026-07-25 08:25:58 +08:00
committed by GitHub
3 changed files with 19 additions and 3 deletions

View File

@@ -1678,6 +1678,14 @@ static void free_salitem(salitem_T *smp)
xfree(smp->sm_to_w);
}
/// Free the salitem_T entries in a "sl_sal" garray (the SN_SAL form) and
/// clear the garray. Used by slang_clear() and when set_sofo() reuses
/// sl_sal for the SN_SOFO form.
void free_sal_items(garray_T *gap)
{
GA_DEEP_CLEAR(gap, salitem_T, free_salitem);
}
/// Frees a fromto_T
static void free_fromto(fromto_T *ftp)
{
@@ -1706,8 +1714,7 @@ void slang_clear(slang_T *lp)
// "ga_len" is set to 1 without adding an item for latin1
GA_DEEP_CLEAR_PTR(gap);
} else {
// SAL items: free salitem_T items
GA_DEEP_CLEAR(gap, salitem_T, free_salitem);
free_sal_items(gap);
}
for (int i = 0; i < lp->sl_prefixcnt; i++) {

View File

@@ -1541,6 +1541,8 @@ static int set_sofo(slang_T *lp, const char *from, const char *to)
const char *s;
const char *p;
free_sal_items(&lp->sl_sal);
// Use "sl_sal" as an array with 256 pointers to a list of wide
// characters. The index is the low byte of the character.
// The list contains from-to pairs with a terminating NUL.
@@ -1553,7 +1555,9 @@ static int set_sofo(slang_T *lp, const char *from, const char *to)
lp->sl_sofo = true;
// First count the number of items for each list. Temporarily use
// sl_sal_first[] for this.
// sl_sal_first[] for this. Reset it first: a preceding SN_SAL section
// may have set the entries to -1 via set_sal_first().
memset(lp->sl_sal_first, 0, sizeof(salfirst_T) * 256);
for (p = from, s = to; *p != NUL && *s != NUL;) {
const int c = mb_cptr2char_adv(&p);
s += utf_ptr2len(s);

View File

@@ -322,6 +322,11 @@ func Test_spellfile_format_error()
" SN_SOFO: multi-byte characters in sofofrom and sofoto
call Spellfile_Test(0z0600000000080002CF810002CF82FF000000000000000000000000, '')
" SN_SAL (empty) followed by SN_SOFO with two multi-byte 'from' characters
" sharing the same low byte. A preceding SN_SAL poisons sl_sal_first[], so
" without a reset set_sofo() under-counts and writes out of bounds.
call Spellfile_Test(0z05000000000300000006000000000A0004CAABCEAB00024142FF000000000000000000000000, '')
" SN_COMPOUND: compmax is less than 2
call Spellfile_Test(0z08000000000101, 'E759:')