diff options
| author | Paul Eggert | 2014-09-07 00:04:01 -0700 |
|---|---|---|
| committer | Paul Eggert | 2014-09-07 00:04:01 -0700 |
| commit | b3bf18b3b87ac8f00857b8bfc3f2c74cf0e2fb7d (patch) | |
| tree | cf138164e4f8887394f52cb22da594d1713da316 /src/xmenu.c | |
| parent | 930fb80f9e2815e599eb1de699668d42e305fa21 (diff) | |
| download | emacs-b3bf18b3b87ac8f00857b8bfc3f2c74cf0e2fb7d.tar.gz emacs-b3bf18b3b87ac8f00857b8bfc3f2c74cf0e2fb7d.zip | |
Use SAFE_ALLOCA etc. to avoid unbounded stack allocation.
This follows up on the recent thread in emacs-devel on alloca; see:
http://lists.gnu.org/archive/html/emacs-devel/2014-09/msg00042.html
This patch also cleans up alloca-related glitches noted while
examining the code looking for unbounded alloca.
* alloc.c (listn):
* callproc.c (init_callproc):
Rewrite to avoid need for alloca.
* buffer.c (mouse_face_overlay_overlaps)
(report_overlay_modification):
* buffer.h (GET_OVERLAYS_AT):
* coding.c (make_subsidiaries):
* doc.c (Fsnarf_documentation):
* editfns.c (Fuser_full_name):
* fileio.c (Ffile_name_directory, Fexpand_file_name)
(search_embedded_absfilename, Fsubstitute_in_file_name):
* fns.c (Fmake_hash_table):
* font.c (font_vconcat_entity_vectors, font_update_drivers):
* fontset.c (fontset_pattern_regexp, Ffontset_info):
* frame.c (Fmake_terminal_frame, x_set_frame_parameters)
(xrdb_get_resource, x_get_resource_string):
* ftfont.c (ftfont_get_charset, ftfont_check_otf, ftfont_drive_otf):
* ftxfont.c (ftxfont_draw):
* image.c (xbm_load, xpm_load, jpeg_load_body):
* keyboard.c (echo_add_key, menu_bar_items, tool_bar_items):
* keymap.c (Fdescribe_buffer_bindings, describe_map):
* lread.c (openp):
* menu.c (digest_single_submenu, find_and_call_menu_selection)
(find_and_return_menu_selection):
* print.c (PRINTFINISH):
* process.c (Fformat_network_address):
* scroll.c (do_scrolling, do_direct_scrolling, scrolling_1):
* search.c (search_buffer, Fmatch_data, Fregexp_quote):
* sound.c (wav_play, au_play):
* syntax.c (skip_chars):
* term.c (tty_menu_activate, tty_menu_show):
* textprop.c (get_char_property_and_overlay):
* window.c (Fset_window_configuration):
* xdisp.c (safe__call, next_overlay_change, vmessage)
(compute_overhangs_and_x, draw_glyphs, note_mouse_highlight):
* xfaces.c (face_at_buffer_position):
* xmenu.c (x_menu_show):
Use SAFE_ALLOCA etc. instead of plain alloca, since the
allocation size isn't bounded.
* callint.c (Fcall_interactively): Redo memory_full check
so that it can be done at compile-time on some platforms.
* coding.c (MAX_LOOKUP_MAX): New constant.
(get_translation_table): Use it.
* callproc.c (call_process): Use SAFE_NALLOCA instead of
SAFE_ALLOCA, to catch integer overflows on size calculation.
(exec_failed) [!DOS_NT]: New function.
(child_setup) [!DOS_NT]: Use it.
* editfns.c (Ftranspose_regions):
Hoist USE_SAFE_ALLOC + SAFE_FREE out of 'if'.
* editfns.c (check_translation):
Allocate larger buffers on the heap.
* eval.c (internal_lisp_condition_case):
Check for MAX_ALLOCA overflow.
* fns.c (sort_vector): Use SAFE_ALLOCA_LISP rather than Fmake_vector.
(Fbase64_encode_region, Fbase64_decode_region):
Avoid unnecessary calls to SAFE_FREE before 'error'.
* buffer.c (mouse_face_overlay_overlaps):
* editfns.c (Fget_pos_property, check_translation):
* eval.c (Ffuncall):
* font.c (font_unparse_xlfd, font_find_for_lface):
* ftfont.c (ftfont_drive_otf):
* keyboard.c (echo_add_key, read_decoded_event_from_main_queue)
(menu_bar_items, tool_bar_items):
* sound.c (Fplay_sound_internal):
* xdisp.c (load_overlay_strings, dump_glyph_row):
Use an ordinary auto buffer rather than alloca, since the
allocation size is fixed and small.
* ftfont.c: Include <c-strcase.h>.
(matching_prefix): New function.
(get_adstyle_property): Use it, to avoid need for alloca.
* keyboard.c (echo_add_key):
* keymap.c (describe_map): Use ptrdiff_t, not int.
* keyboard.c (echo_add_key): Prefer sizeof to strlen.
* keymap.c (Fdescribe_buffer_bindings): Use SBYTES, not SCHARS,
when counting bytes.
* lisp.h (xlispstrdupa): Remove, replacing with ...
(SAFE_ALLOCA_STRING): ... new macro with different API.
This fixes a portability problem, namely, alloca result
passed to another function. All uses changed.
(SAFE_ALLOCA, SAFE_ALLOCA_LISP): Check for MAX_ALLOCA,
not MAX_ALLOCA - 1.
* regex.c (REGEX_USE_SAFE_ALLOCA, REGEX_SAFE_FREE)
(REGEX_ALLOCATE): New macros.
(REGEX_REALLOCATE, REGEX_ALLOCATE_STACK, REGEX_REALLOCATE_STACK)
(REGEX_FREE_STACK, FREE_VARIABLES, re_match_2_internal):
Use them.
* xdisp.c (message3): Use SAFE_ALLOCA_STRING rather than doing it
by hand.
(decode_mode_spec_coding): Store directly into buf rather than
into an alloca temporary and copying the temporary to the buf.
Fixes: debbugs:18410
Diffstat (limited to 'src/xmenu.c')
| -rw-r--r-- | src/xmenu.c | 25 |
1 files changed, 11 insertions, 14 deletions
diff --git a/src/xmenu.c b/src/xmenu.c index a7d47188ef5..8bb8d17369c 100644 --- a/src/xmenu.c +++ b/src/xmenu.c | |||
| @@ -2023,7 +2023,8 @@ x_menu_show (struct frame *f, int x, int y, int menuflags, | |||
| 2023 | Window root; | 2023 | Window root; |
| 2024 | XMenu *menu; | 2024 | XMenu *menu; |
| 2025 | int pane, selidx, lpane, status; | 2025 | int pane, selidx, lpane, status; |
| 2026 | Lisp_Object entry, pane_prefix; | 2026 | Lisp_Object entry = Qnil; |
| 2027 | Lisp_Object pane_prefix; | ||
| 2027 | char *datap; | 2028 | char *datap; |
| 2028 | int ulx, uly, width, height; | 2029 | int ulx, uly, width, height; |
| 2029 | int dispwidth, dispheight; | 2030 | int dispwidth, dispheight; |
| @@ -2045,6 +2046,7 @@ x_menu_show (struct frame *f, int x, int y, int menuflags, | |||
| 2045 | return Qnil; | 2046 | return Qnil; |
| 2046 | } | 2047 | } |
| 2047 | 2048 | ||
| 2049 | USE_SAFE_ALLOCA; | ||
| 2048 | block_input (); | 2050 | block_input (); |
| 2049 | 2051 | ||
| 2050 | /* Figure out which root window F is on. */ | 2052 | /* Figure out which root window F is on. */ |
| @@ -2057,8 +2059,7 @@ x_menu_show (struct frame *f, int x, int y, int menuflags, | |||
| 2057 | if (menu == NULL) | 2059 | if (menu == NULL) |
| 2058 | { | 2060 | { |
| 2059 | *error_name = "Can't create menu"; | 2061 | *error_name = "Can't create menu"; |
| 2060 | unblock_input (); | 2062 | goto return_entry; |
| 2061 | return Qnil; | ||
| 2062 | } | 2063 | } |
| 2063 | 2064 | ||
| 2064 | /* Don't GC while we prepare and show the menu, | 2065 | /* Don't GC while we prepare and show the menu, |
| @@ -2101,8 +2102,7 @@ x_menu_show (struct frame *f, int x, int y, int menuflags, | |||
| 2101 | { | 2102 | { |
| 2102 | XMenuDestroy (FRAME_X_DISPLAY (f), menu); | 2103 | XMenuDestroy (FRAME_X_DISPLAY (f), menu); |
| 2103 | *error_name = "Can't create pane"; | 2104 | *error_name = "Can't create pane"; |
| 2104 | unblock_input (); | 2105 | goto return_entry; |
| 2105 | return Qnil; | ||
| 2106 | } | 2106 | } |
| 2107 | i += MENU_ITEMS_PANE_LENGTH; | 2107 | i += MENU_ITEMS_PANE_LENGTH; |
| 2108 | 2108 | ||
| @@ -2146,9 +2146,7 @@ x_menu_show (struct frame *f, int x, int y, int menuflags, | |||
| 2146 | 2146 | ||
| 2147 | if (!NILP (descrip)) | 2147 | if (!NILP (descrip)) |
| 2148 | { | 2148 | { |
| 2149 | /* if alloca is fast, use that to make the space, | 2149 | item_data = SAFE_ALLOCA (maxwidth + SBYTES (descrip) + 1); |
| 2150 | to reduce gc needs. */ | ||
| 2151 | item_data = alloca (maxwidth + SBYTES (descrip) + 1); | ||
| 2152 | memcpy (item_data, SSDATA (item_name), SBYTES (item_name)); | 2150 | memcpy (item_data, SSDATA (item_name), SBYTES (item_name)); |
| 2153 | for (j = SCHARS (item_name); j < maxwidth; j++) | 2151 | for (j = SCHARS (item_name); j < maxwidth; j++) |
| 2154 | item_data[j] = ' '; | 2152 | item_data[j] = ' '; |
| @@ -2166,8 +2164,7 @@ x_menu_show (struct frame *f, int x, int y, int menuflags, | |||
| 2166 | { | 2164 | { |
| 2167 | XMenuDestroy (FRAME_X_DISPLAY (f), menu); | 2165 | XMenuDestroy (FRAME_X_DISPLAY (f), menu); |
| 2168 | *error_name = "Can't add selection to menu"; | 2166 | *error_name = "Can't add selection to menu"; |
| 2169 | unblock_input (); | 2167 | goto return_entry; |
| 2170 | return Qnil; | ||
| 2171 | } | 2168 | } |
| 2172 | i += MENU_ITEMS_ITEM_LENGTH; | 2169 | i += MENU_ITEMS_ITEM_LENGTH; |
| 2173 | lines++; | 2170 | lines++; |
| @@ -2241,7 +2238,7 @@ x_menu_show (struct frame *f, int x, int y, int menuflags, | |||
| 2241 | status = XMenuActivate (FRAME_X_DISPLAY (f), menu, &pane, &selidx, | 2238 | status = XMenuActivate (FRAME_X_DISPLAY (f), menu, &pane, &selidx, |
| 2242 | x, y, ButtonReleaseMask, &datap, | 2239 | x, y, ButtonReleaseMask, &datap, |
| 2243 | menu_help_callback); | 2240 | menu_help_callback); |
| 2244 | entry = pane_prefix = Qnil; | 2241 | pane_prefix = Qnil; |
| 2245 | 2242 | ||
| 2246 | switch (status) | 2243 | switch (status) |
| 2247 | { | 2244 | { |
| @@ -2300,10 +2297,10 @@ x_menu_show (struct frame *f, int x, int y, int menuflags, | |||
| 2300 | break; | 2297 | break; |
| 2301 | } | 2298 | } |
| 2302 | 2299 | ||
| 2300 | return_entry: | ||
| 2303 | unblock_input (); | 2301 | unblock_input (); |
| 2304 | unbind_to (specpdl_count, Qnil); | 2302 | SAFE_FREE (); |
| 2305 | 2303 | return unbind_to (specpdl_count, entry); | |
| 2306 | return entry; | ||
| 2307 | } | 2304 | } |
| 2308 | 2305 | ||
| 2309 | #endif /* not USE_X_TOOLKIT */ | 2306 | #endif /* not USE_X_TOOLKIT */ |