summaryrefslogtreecommitdiff
path: root/py/binary.c
diff options
context:
space:
mode:
authorMatt Wozniski <godlygeek+git@gmail.com>2019-05-08 23:50:35 -0400
committerMatt Wozniski <godlygeek+git@gmail.com>2019-05-09 03:22:25 -0400
commit095c844004bcd8680a4bf68901adbd9cac6a4302 (patch)
tree925d3c5941b025ef2642c6a74c7de28fb2c648e5 /py/binary.c
parente041df73bb7bf424bcf571f25e3459359c4f36ed (diff)
Add overflow checks for int to bytes conversions
For both small and long integers, raise an exception if calling struct.pack, adding an element to an array.array, or formatting an int with int.to_bytes would overflow the requested size.
Diffstat (limited to 'py/binary.c')
-rw-r--r--py/binary.c18
1 files changed, 14 insertions, 4 deletions
diff --git a/py/binary.c b/py/binary.c
index 9c3a49e8f..0e4a1d5f6 100644
--- a/py/binary.c
+++ b/py/binary.c
@@ -304,15 +304,18 @@ void mp_binary_set_val(char struct_type, char val_type, mp_obj_t val_in, byte **
break;
}
#endif
- default:
+ default: {
+ bool signed_type = is_signed(val_type);
#if MICROPY_LONGINT_IMPL != MICROPY_LONGINT_IMPL_NONE
if (MP_OBJ_IS_TYPE(val_in, &mp_type_int)) {
+ mp_obj_int_buffer_overflow_check(val_in, size, signed_type);
mp_obj_int_to_bytes_impl(val_in, struct_type == '>', size, p);
return;
} else
#endif
{
val = mp_obj_get_int(val_in);
+ mp_obj_int_buffer_overflow_check(val_in, size, signed_type);
// zero/sign extend if needed
if (BYTES_PER_WORD < 8 && size > sizeof(val)) {
int c = (is_signed(val_type) && (mp_int_t)val < 0) ? 0xff : 0x00;
@@ -322,6 +325,7 @@ void mp_binary_set_val(char struct_type, char val_type, mp_obj_t val_in, byte **
}
}
}
+ }
}
mp_binary_set_int(MIN((size_t)size, sizeof(val)), struct_type == '>', p, val);
@@ -343,16 +347,22 @@ void mp_binary_set_val_array(char typecode, void *p, mp_uint_t index, mp_obj_t v
((mp_obj_t*)p)[index] = val_in;
break;
#endif
- default:
+ default: {
+ size_t size = mp_binary_get_size('@', typecode, NULL);
+ bool signed_type = is_signed(typecode);
+
#if MICROPY_LONGINT_IMPL != MICROPY_LONGINT_IMPL_NONE
if (MP_OBJ_IS_TYPE(val_in, &mp_type_int)) {
- size_t size = mp_binary_get_size('@', typecode, NULL);
+ mp_obj_int_buffer_overflow_check(val_in, size, signed_type);
mp_obj_int_to_bytes_impl(val_in, MP_ENDIANNESS_BIG,
size, (uint8_t*)p + index * size);
return;
}
#endif
- mp_binary_set_val_array_from_int(typecode, p, index, mp_obj_get_int(val_in));
+ mp_int_t val = mp_obj_get_int(val_in);
+ mp_obj_int_buffer_overflow_check(val_in, size, signed_type);
+ mp_binary_set_val_array_from_int(typecode, p, index, val);
+ }
}
}