input: Fix conversion error in convert_input()

The `rbuffer_consumed` was being passed a consumed count from another buffer,
causing integer overflow in `rbuffer_relocate`.

Fixes #1343
This commit is contained in:
Thiago de Arruda
2014-10-28 09:17:57 -03:00
parent 53ce5493fa
commit c95bc3349b
2 changed files with 12 additions and 5 deletions

View File

@@ -1,3 +1,4 @@
#include <assert.h>
#include <string.h>
#include <stdint.h>
#include <stdbool.h>
@@ -237,18 +238,23 @@ static void convert_input(void)
if (convert) {
// Perform input conversion according to `input_conv`
size_t unconverted_length;
size_t unconverted_length = 0;
data = (char *)string_convert_ext(&input_conv,
(uint8_t *)data,
(int *)&converted_length,
(int *)&unconverted_length);
data_length = rbuffer_pending(read_buffer) - unconverted_length;
data_length -= unconverted_length;
}
// Write processed data to input buffer
size_t consumed = rbuffer_write(input_buffer, data, data_length);
// The conversion code will be gone eventually, for now assume `input_buffer`
// always has space for the converted data(it's many times the size of
// `read_buffer`, so it's hard to imagine a scenario where the converted data
// doesn't fit)
assert(converted_length <= rbuffer_available(input_buffer));
// Write processed data to input buffer.
(void)rbuffer_write(input_buffer, data, converted_length);
// Adjust raw buffer pointers
rbuffer_consumed(read_buffer, consumed);
rbuffer_consumed(read_buffer, data_length);
if (convert) {
// data points to memory allocated by `string_convert_ext`, free it.

View File

@@ -396,6 +396,7 @@ static void close_cb(uv_handle_t *handle)
static void rbuffer_relocate(RBuffer *rbuffer)
{
assert(rbuffer->rpos <= rbuffer->wpos);
// Move data ...
memmove(
rbuffer->data, // ...to the beginning of the buffer(rpos 0)