girepository: Ensure indexed access on members is not overflowing

Even though we expose member access as size_t, a GI info blob can
typically just access to an a number of values that is never bigger
than uint16_t, as that's how the typelib is defined (cfr. typelib
internal header blob sizes and n_* elements).

So let's avoid this to happen by adding a check.
This commit is contained in:
Marco Trevisan (Treviño)
2024-01-16 01:40:09 +01:00
parent acabaa1568
commit 19476db825
6 changed files with 22 additions and 0 deletions

View File

@@ -275,6 +275,7 @@ gi_object_info_get_interface (GIObjectInfo *info,
g_return_val_if_fail (info != NULL, NULL);
g_return_val_if_fail (GI_IS_OBJECT_INFO (info), NULL);
g_return_val_if_fail (n <= G_MAXUINT16, NULL);
blob = (ObjectBlob *)&rinfo->typelib->data[rinfo->offset];
@@ -325,6 +326,7 @@ gi_object_info_get_field (GIObjectInfo *info,
g_return_val_if_fail (info != NULL, NULL);
g_return_val_if_fail (GI_IS_OBJECT_INFO (info), NULL);
g_return_val_if_fail (n <= G_MAXUINT16, NULL);
offset = gi_object_info_get_field_offset(info, n);
@@ -375,6 +377,7 @@ gi_object_info_get_property (GIObjectInfo *info,
g_return_val_if_fail (info != NULL, NULL);
g_return_val_if_fail (GI_IS_OBJECT_INFO (info), NULL);
g_return_val_if_fail (n <= G_MAXUINT16, NULL);
header = (Header *)rinfo->typelib->data;
blob = (ObjectBlob *)&rinfo->typelib->data[rinfo->offset];
@@ -434,6 +437,7 @@ gi_object_info_get_method (GIObjectInfo *info,
g_return_val_if_fail (info != NULL, NULL);
g_return_val_if_fail (GI_IS_OBJECT_INFO (info), NULL);
g_return_val_if_fail (n <= G_MAXUINT16, NULL);
header = (Header *)rinfo->typelib->data;
blob = (ObjectBlob *)&rinfo->typelib->data[rinfo->offset];
@@ -595,6 +599,7 @@ gi_object_info_get_signal (GIObjectInfo *info,
g_return_val_if_fail (info != NULL, NULL);
g_return_val_if_fail (GI_IS_OBJECT_INFO (info), NULL);
g_return_val_if_fail (n <= G_MAXUINT16, NULL);
header = (Header *)rinfo->typelib->data;
blob = (ObjectBlob *)&rinfo->typelib->data[rinfo->offset];
@@ -693,6 +698,7 @@ gi_object_info_get_vfunc (GIObjectInfo *info,
g_return_val_if_fail (info != NULL, NULL);
g_return_val_if_fail (GI_IS_OBJECT_INFO (info), NULL);
g_return_val_if_fail (n <= G_MAXUINT16, NULL);
header = (Header *)rinfo->typelib->data;
blob = (ObjectBlob *)&rinfo->typelib->data[rinfo->offset];
@@ -868,6 +874,7 @@ gi_object_info_get_constant (GIObjectInfo *info,
g_return_val_if_fail (info != NULL, NULL);
g_return_val_if_fail (GI_IS_OBJECT_INFO (info), NULL);
g_return_val_if_fail (n <= G_MAXUINT16, NULL);
header = (Header *)rinfo->typelib->data;
blob = (ObjectBlob *)&rinfo->typelib->data[rinfo->offset];