diff options
| author | 2026-09-27 15:06:22 +0900 | |
|---|---|---|
| committer | 2026-09-27 15:06:22 +0900 | |
| commit | 8b48fa72d359de89215f50cbf6ac8c77ae5de9b4 (patch) | |
| tree | 07c02aa1437e53e0994ef0ec89edf752c4b309a8 /src/plist.c | |
| parent | 32428abacb909988e8e960a8845a6430b17b6a60 (diff) | |
| download | libplist-8b48fa72d359de89215f50cbf6ac8c77ae5de9b4.tar.gz libplist-8b48fa72d359de89215f50cbf6ac8c77ae5de9b4.tar.bz2 | |
ptrarray: Handle realloc() failure in ptr_array_insert()
ptr_array_insert() assigned the result of realloc() directly to
pa->pdata and bumped the capacity without checking for failure, so on
out-of-memory the old buffer was leaked and the following store or
memmove() wrote through a NULL pointer.
Keep the old buffer on failure and return -1 from ptr_array_insert()
and ptr_array_add(). The callers now handle the error:
- the array lookup cache (plist.c) is dropped instead of silently going
out of sync with the node list; lookups then fall back to walking
the children, as they do before the cache exists
- bplist parsing (used_indexes) and serialization (objects) return
PLIST_ERR_NO_MEM; ignoring the error in parse_bin_node_at_index()
would otherwise loop forever since the array never grows
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Diffstat (limited to 'src/plist.c')
| -rw-r--r-- | src/plist.c | 16 |
1 files changed, 13 insertions, 3 deletions
diff --git a/src/plist.c b/src/plist.c index 05af457..5ea6c12 100644 --- a/src/plist.c +++ b/src/plist.c @@ -898,7 +898,10 @@ static plist_t plist_copy_node(node_t root) switch (f->type) { case PLIST_ARRAY: if (f->copydata->hashtable) { - ptr_array_add((ptrarray_t*)f->copydata->hashtable, newch); + if (ptr_array_add((ptrarray_t*)f->copydata->hashtable, newch) < 0) { + ptr_array_free((ptrarray_t*)f->copydata->hashtable); + f->copydata->hashtable = NULL; + } } break; @@ -987,7 +990,11 @@ static void _plist_array_post_insert(plist_t node, plist_t item, long n) ptrarray_t *pa = (ptrarray_t*)((plist_data_t)((node_t)node)->data)->hashtable; if (pa) { /* store pointer to item in array */ - ptr_array_insert(pa, item, n); + if (ptr_array_insert(pa, item, n) < 0) { + /* lookup array would be out of sync, drop it */ + ptr_array_free(pa); + ((plist_data_t)((node_t)node)->data)->hashtable = NULL; + } return; } @@ -999,7 +1006,10 @@ static void _plist_array_post_insert(plist_t node, plist_t item, long n) pa && current; current = (plist_t)node_next_sibling((node_t)current)) { - ptr_array_add(pa, current); + if (ptr_array_add(pa, current) < 0) { + ptr_array_free(pa); + pa = NULL; + } } ((plist_data_t)((node_t)node)->data)->hashtable = pa; } |
