summaryrefslogtreecommitdiffstats
path: root/include/plist/String.h
diff options
context:
space:
mode:
authorGravatar Comtea042026-09-27 15:06:22 +0900
committerGravatar Comtea042026-09-27 15:06:22 +0900
commit8b48fa72d359de89215f50cbf6ac8c77ae5de9b4 (patch)
tree07c02aa1437e53e0994ef0ec89edf752c4b309a8 /include/plist/String.h
parent32428abacb909988e8e960a8845a6430b17b6a60 (diff)
downloadlibplist-8b48fa72d359de89215f50cbf6ac8c77ae5de9b4.tar.gz
libplist-8b48fa72d359de89215f50cbf6ac8c77ae5de9b4.tar.bz2
ptrarray: Handle realloc() failure in ptr_array_insert()
ptr_array_insert() assigned the result of realloc() directly to pa->pdata and bumped the capacity without checking for failure, so on out-of-memory the old buffer was leaked and the following store or memmove() wrote through a NULL pointer. Keep the old buffer on failure and return -1 from ptr_array_insert() and ptr_array_add(). The callers now handle the error: - the array lookup cache (plist.c) is dropped instead of silently going out of sync with the node list; lookups then fall back to walking the children, as they do before the cache exists - bplist parsing (used_indexes) and serialization (objects) return PLIST_ERR_NO_MEM; ignoring the error in parse_bin_node_at_index() would otherwise loop forever since the array never grows Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'include/plist/String.h')
0 files changed, 0 insertions, 0 deletions