diff options
| author | Paul Eggert | 2014-09-07 00:04:01 -0700 |
|---|---|---|
| committer | Paul Eggert | 2014-09-07 00:04:01 -0700 |
| commit | b3bf18b3b87ac8f00857b8bfc3f2c74cf0e2fb7d (patch) | |
| tree | cf138164e4f8887394f52cb22da594d1713da316 /src/menu.c | |
| parent | 930fb80f9e2815e599eb1de699668d42e305fa21 (diff) | |
| download | emacs-b3bf18b3b87ac8f00857b8bfc3f2c74cf0e2fb7d.tar.gz emacs-b3bf18b3b87ac8f00857b8bfc3f2c74cf0e2fb7d.zip | |
Use SAFE_ALLOCA etc. to avoid unbounded stack allocation.
This follows up on the recent thread in emacs-devel on alloca; see:
http://lists.gnu.org/archive/html/emacs-devel/2014-09/msg00042.html
This patch also cleans up alloca-related glitches noted while
examining the code looking for unbounded alloca.
* alloc.c (listn):
* callproc.c (init_callproc):
Rewrite to avoid need for alloca.
* buffer.c (mouse_face_overlay_overlaps)
(report_overlay_modification):
* buffer.h (GET_OVERLAYS_AT):
* coding.c (make_subsidiaries):
* doc.c (Fsnarf_documentation):
* editfns.c (Fuser_full_name):
* fileio.c (Ffile_name_directory, Fexpand_file_name)
(search_embedded_absfilename, Fsubstitute_in_file_name):
* fns.c (Fmake_hash_table):
* font.c (font_vconcat_entity_vectors, font_update_drivers):
* fontset.c (fontset_pattern_regexp, Ffontset_info):
* frame.c (Fmake_terminal_frame, x_set_frame_parameters)
(xrdb_get_resource, x_get_resource_string):
* ftfont.c (ftfont_get_charset, ftfont_check_otf, ftfont_drive_otf):
* ftxfont.c (ftxfont_draw):
* image.c (xbm_load, xpm_load, jpeg_load_body):
* keyboard.c (echo_add_key, menu_bar_items, tool_bar_items):
* keymap.c (Fdescribe_buffer_bindings, describe_map):
* lread.c (openp):
* menu.c (digest_single_submenu, find_and_call_menu_selection)
(find_and_return_menu_selection):
* print.c (PRINTFINISH):
* process.c (Fformat_network_address):
* scroll.c (do_scrolling, do_direct_scrolling, scrolling_1):
* search.c (search_buffer, Fmatch_data, Fregexp_quote):
* sound.c (wav_play, au_play):
* syntax.c (skip_chars):
* term.c (tty_menu_activate, tty_menu_show):
* textprop.c (get_char_property_and_overlay):
* window.c (Fset_window_configuration):
* xdisp.c (safe__call, next_overlay_change, vmessage)
(compute_overhangs_and_x, draw_glyphs, note_mouse_highlight):
* xfaces.c (face_at_buffer_position):
* xmenu.c (x_menu_show):
Use SAFE_ALLOCA etc. instead of plain alloca, since the
allocation size isn't bounded.
* callint.c (Fcall_interactively): Redo memory_full check
so that it can be done at compile-time on some platforms.
* coding.c (MAX_LOOKUP_MAX): New constant.
(get_translation_table): Use it.
* callproc.c (call_process): Use SAFE_NALLOCA instead of
SAFE_ALLOCA, to catch integer overflows on size calculation.
(exec_failed) [!DOS_NT]: New function.
(child_setup) [!DOS_NT]: Use it.
* editfns.c (Ftranspose_regions):
Hoist USE_SAFE_ALLOC + SAFE_FREE out of 'if'.
* editfns.c (check_translation):
Allocate larger buffers on the heap.
* eval.c (internal_lisp_condition_case):
Check for MAX_ALLOCA overflow.
* fns.c (sort_vector): Use SAFE_ALLOCA_LISP rather than Fmake_vector.
(Fbase64_encode_region, Fbase64_decode_region):
Avoid unnecessary calls to SAFE_FREE before 'error'.
* buffer.c (mouse_face_overlay_overlaps):
* editfns.c (Fget_pos_property, check_translation):
* eval.c (Ffuncall):
* font.c (font_unparse_xlfd, font_find_for_lface):
* ftfont.c (ftfont_drive_otf):
* keyboard.c (echo_add_key, read_decoded_event_from_main_queue)
(menu_bar_items, tool_bar_items):
* sound.c (Fplay_sound_internal):
* xdisp.c (load_overlay_strings, dump_glyph_row):
Use an ordinary auto buffer rather than alloca, since the
allocation size is fixed and small.
* ftfont.c: Include <c-strcase.h>.
(matching_prefix): New function.
(get_adstyle_property): Use it, to avoid need for alloca.
* keyboard.c (echo_add_key):
* keymap.c (describe_map): Use ptrdiff_t, not int.
* keyboard.c (echo_add_key): Prefer sizeof to strlen.
* keymap.c (Fdescribe_buffer_bindings): Use SBYTES, not SCHARS,
when counting bytes.
* lisp.h (xlispstrdupa): Remove, replacing with ...
(SAFE_ALLOCA_STRING): ... new macro with different API.
This fixes a portability problem, namely, alloca result
passed to another function. All uses changed.
(SAFE_ALLOCA, SAFE_ALLOCA_LISP): Check for MAX_ALLOCA,
not MAX_ALLOCA - 1.
* regex.c (REGEX_USE_SAFE_ALLOCA, REGEX_SAFE_FREE)
(REGEX_ALLOCATE): New macros.
(REGEX_REALLOCATE, REGEX_ALLOCATE_STACK, REGEX_REALLOCATE_STACK)
(REGEX_FREE_STACK, FREE_VARIABLES, re_match_2_internal):
Use them.
* xdisp.c (message3): Use SAFE_ALLOCA_STRING rather than doing it
by hand.
(decode_mode_spec_coding): Store directly into buf rather than
into an alloca temporary and copying the temporary to the buf.
Fixes: debbugs:18410
Diffstat (limited to 'src/menu.c')
| -rw-r--r-- | src/menu.c | 22 |
1 files changed, 15 insertions, 7 deletions
diff --git a/src/menu.c b/src/menu.c index 66247c713a2..8c624f758a9 100644 --- a/src/menu.c +++ b/src/menu.c | |||
| @@ -632,8 +632,9 @@ digest_single_submenu (int start, int end, bool top_level_items) | |||
| 632 | widget_value **submenu_stack; | 632 | widget_value **submenu_stack; |
| 633 | bool panes_seen = 0; | 633 | bool panes_seen = 0; |
| 634 | struct frame *f = XFRAME (Vmenu_updating_frame); | 634 | struct frame *f = XFRAME (Vmenu_updating_frame); |
| 635 | USE_SAFE_ALLOCA; | ||
| 635 | 636 | ||
| 636 | submenu_stack = alloca (menu_items_used * sizeof *submenu_stack); | 637 | SAFE_NALLOCA (submenu_stack, 1, menu_items_used); |
| 637 | wv = make_widget_value ("menu", NULL, true, Qnil); | 638 | wv = make_widget_value ("menu", NULL, true, Qnil); |
| 638 | wv->button_type = BUTTON_TYPE_NONE; | 639 | wv->button_type = BUTTON_TYPE_NONE; |
| 639 | first_wv = wv; | 640 | first_wv = wv; |
| @@ -835,11 +836,12 @@ digest_single_submenu (int start, int end, bool top_level_items) | |||
| 835 | that was originally a button, return it by itself. */ | 836 | that was originally a button, return it by itself. */ |
| 836 | if (top_level_items && first_wv->contents && first_wv->contents->next == 0) | 837 | if (top_level_items && first_wv->contents && first_wv->contents->next == 0) |
| 837 | { | 838 | { |
| 838 | wv = first_wv->contents; | 839 | wv = first_wv; |
| 839 | xfree (first_wv); | 840 | first_wv = first_wv->contents; |
| 840 | return wv; | 841 | xfree (wv); |
| 841 | } | 842 | } |
| 842 | 843 | ||
| 844 | SAFE_FREE (); | ||
| 843 | return first_wv; | 845 | return first_wv; |
| 844 | } | 846 | } |
| 845 | 847 | ||
| @@ -890,9 +892,10 @@ find_and_call_menu_selection (struct frame *f, int menu_bar_items_used, | |||
| 890 | Lisp_Object *subprefix_stack; | 892 | Lisp_Object *subprefix_stack; |
| 891 | int submenu_depth = 0; | 893 | int submenu_depth = 0; |
| 892 | int i; | 894 | int i; |
| 895 | USE_SAFE_ALLOCA; | ||
| 893 | 896 | ||
| 894 | entry = Qnil; | 897 | entry = Qnil; |
| 895 | subprefix_stack = alloca (menu_bar_items_used * sizeof *subprefix_stack); | 898 | SAFE_NALLOCA (subprefix_stack, 1, menu_bar_items_used); |
| 896 | prefix = Qnil; | 899 | prefix = Qnil; |
| 897 | i = 0; | 900 | i = 0; |
| 898 | 901 | ||
| @@ -954,11 +957,13 @@ find_and_call_menu_selection (struct frame *f, int menu_bar_items_used, | |||
| 954 | buf.arg = entry; | 957 | buf.arg = entry; |
| 955 | kbd_buffer_store_event (&buf); | 958 | kbd_buffer_store_event (&buf); |
| 956 | 959 | ||
| 957 | return; | 960 | break; |
| 958 | } | 961 | } |
| 959 | i += MENU_ITEMS_ITEM_LENGTH; | 962 | i += MENU_ITEMS_ITEM_LENGTH; |
| 960 | } | 963 | } |
| 961 | } | 964 | } |
| 965 | |||
| 966 | SAFE_FREE (); | ||
| 962 | } | 967 | } |
| 963 | 968 | ||
| 964 | #endif /* USE_X_TOOLKIT || USE_GTK || HAVE_NS || HAVE_NTGUI */ | 969 | #endif /* USE_X_TOOLKIT || USE_GTK || HAVE_NS || HAVE_NTGUI */ |
| @@ -973,10 +978,11 @@ find_and_return_menu_selection (struct frame *f, bool keymaps, void *client_data | |||
| 973 | int i; | 978 | int i; |
| 974 | Lisp_Object *subprefix_stack; | 979 | Lisp_Object *subprefix_stack; |
| 975 | int submenu_depth = 0; | 980 | int submenu_depth = 0; |
| 981 | USE_SAFE_ALLOCA; | ||
| 976 | 982 | ||
| 977 | prefix = entry = Qnil; | 983 | prefix = entry = Qnil; |
| 978 | i = 0; | 984 | i = 0; |
| 979 | subprefix_stack = alloca (menu_items_used * word_size); | 985 | SAFE_ALLOCA_LISP (subprefix_stack, menu_items_used); |
| 980 | 986 | ||
| 981 | while (i < menu_items_used) | 987 | while (i < menu_items_used) |
| 982 | { | 988 | { |
| @@ -1018,11 +1024,13 @@ find_and_return_menu_selection (struct frame *f, bool keymaps, void *client_data | |||
| 1018 | if (!NILP (subprefix_stack[j])) | 1024 | if (!NILP (subprefix_stack[j])) |
| 1019 | entry = Fcons (subprefix_stack[j], entry); | 1025 | entry = Fcons (subprefix_stack[j], entry); |
| 1020 | } | 1026 | } |
| 1027 | SAFE_FREE (); | ||
| 1021 | return entry; | 1028 | return entry; |
| 1022 | } | 1029 | } |
| 1023 | i += MENU_ITEMS_ITEM_LENGTH; | 1030 | i += MENU_ITEMS_ITEM_LENGTH; |
| 1024 | } | 1031 | } |
| 1025 | } | 1032 | } |
| 1033 | SAFE_FREE (); | ||
| 1026 | return Qnil; | 1034 | return Qnil; |
| 1027 | } | 1035 | } |
| 1028 | #endif /* HAVE_NS */ | 1036 | #endif /* HAVE_NS */ |