Skip to content
Projeler
Gruplar
Parçacıklar
Yardım
Yükleniyor...
Oturum aç / Kaydol
Gezinmeyi değiştir
C
cpython
Proje
Proje
Ayrıntılar
Etkinlik
Cycle Analytics
Depo (repository)
Depo (repository)
Dosyalar
Kayıtlar (commit)
Dallar (branch)
Etiketler
Katkıda bulunanlar
Grafik
Karşılaştır
Grafikler
Konular (issue)
0
Konular (issue)
0
Liste
Pano
Etiketler
Kilometre Taşları
Birleştirme (merge) Talepleri
0
Birleştirme (merge) Talepleri
0
CI / CD
CI / CD
İş akışları (pipeline)
İşler
Zamanlamalar
Grafikler
Paketler
Paketler
Wiki
Wiki
Parçacıklar
Parçacıklar
Üyeler
Üyeler
Collapse sidebar
Close sidebar
Etkinlik
Grafik
Grafikler
Yeni bir konu (issue) oluştur
İşler
Kayıtlar (commit)
Konu (issue) Panoları
Kenar çubuğunu aç
Batuhan Osman TASKAYA
cpython
Commits
5bdff606
Kaydet (Commit)
5bdff606
authored
Mar 11, 2008
tarafından
Guido van Rossum
Dosyalara gözat
Seçenekler
Dosyalara Gözat
İndir
Eposta Yamaları
Sade Fark
Fix the overflows in expandtabs(). "This time for sure!"
(Exploit at request.)
üst
e8b4b605
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
65 additions
and
50 deletions
+65
-50
stringobject.c
Objects/stringobject.c
+32
-25
unicodeobject.c
Objects/unicodeobject.c
+33
-25
No files found.
Objects/stringobject.c
Dosyayı görüntüle @
5bdff606
...
...
@@ -3363,9 +3363,9 @@ If tabsize is not given, a tab size of 8 characters is assumed.");
static
PyObject
*
string_expandtabs
(
PyStringObject
*
self
,
PyObject
*
args
)
{
const
char
*
e
,
*
p
;
const
char
*
e
,
*
p
,
*
qe
;
char
*
q
;
Py_ssize_t
i
,
j
,
old_j
;
Py_ssize_t
i
,
j
,
incr
;
PyObject
*
u
;
int
tabsize
=
8
;
...
...
@@ -3373,63 +3373,70 @@ string_expandtabs(PyStringObject *self, PyObject *args)
return
NULL
;
/* First pass: determine size of output string */
i
=
j
=
old_j
=
0
;
e
=
PyString_AS_STRING
(
self
)
+
PyString_GET_SIZE
(
self
);
i
=
0
;
/* chars up to and including most recent \n or \r */
j
=
0
;
/* chars since most recent \n or \r (use in tab calculations) */
e
=
PyString_AS_STRING
(
self
)
+
PyString_GET_SIZE
(
self
);
/* end of input */
for
(
p
=
PyString_AS_STRING
(
self
);
p
<
e
;
p
++
)
if
(
*
p
==
'\t'
)
{
if
(
tabsize
>
0
)
{
j
+=
tabsize
-
(
j
%
tabsize
);
if
(
old_j
>
j
)
{
PyErr_SetString
(
PyExc_OverflowError
,
"new string is too long"
);
return
NULL
;
}
old_j
=
j
;
incr
=
tabsize
-
(
j
%
tabsize
);
if
(
j
>
PY_SSIZE_T_MAX
-
incr
)
goto
overflow1
;
j
+=
incr
;
}
}
else
{
if
(
j
>
PY_SSIZE_T_MAX
-
1
)
goto
overflow1
;
j
++
;
if
(
*
p
==
'\n'
||
*
p
==
'\r'
)
{
if
(
i
>
PY_SSIZE_T_MAX
-
j
)
goto
overflow1
;
i
+=
j
;
old_j
=
j
=
0
;
if
(
i
<
0
)
{
PyErr_SetString
(
PyExc_OverflowError
,
"new string is too long"
);
return
NULL
;
}
j
=
0
;
}
}
if
((
i
+
j
)
<
0
)
{
PyErr_SetString
(
PyExc_OverflowError
,
"new string is too long"
);
return
NULL
;
}
if
(
i
>
PY_SSIZE_T_MAX
-
j
)
goto
overflow1
;
/* Second pass: create output string and fill it */
u
=
PyString_FromStringAndSize
(
NULL
,
i
+
j
);
if
(
!
u
)
return
NULL
;
j
=
0
;
q
=
PyString_AS_STRING
(
u
);
j
=
0
;
/* same as in first pass */
q
=
PyString_AS_STRING
(
u
);
/* next output char */
qe
=
PyString_AS_STRING
(
u
)
+
PyString_GET_SIZE
(
u
);
/* end of output */
for
(
p
=
PyString_AS_STRING
(
self
);
p
<
e
;
p
++
)
if
(
*
p
==
'\t'
)
{
if
(
tabsize
>
0
)
{
i
=
tabsize
-
(
j
%
tabsize
);
j
+=
i
;
while
(
i
--
)
while
(
i
--
)
{
if
(
q
>=
qe
)
goto
overflow2
;
*
q
++
=
' '
;
}
}
}
else
{
j
++
;
if
(
q
>=
qe
)
goto
overflow2
;
*
q
++
=
*
p
;
j
++
;
if
(
*
p
==
'\n'
||
*
p
==
'\r'
)
j
=
0
;
}
return
u
;
overflow2:
Py_DECREF
(
u
);
overflow1:
PyErr_SetString
(
PyExc_OverflowError
,
"new string is too long"
);
return
NULL
;
}
Py_LOCAL_INLINE
(
PyObject
*
)
...
...
Objects/unicodeobject.c
Dosyayı görüntüle @
5bdff606
...
...
@@ -6495,7 +6495,8 @@ unicode_expandtabs(PyUnicodeObject *self, PyObject *args)
Py_UNICODE
*
e
;
Py_UNICODE
*
p
;
Py_UNICODE
*
q
;
Py_ssize_t
i
,
j
,
old_j
;
Py_UNICODE
*
qe
;
Py_ssize_t
i
,
j
,
incr
;
PyUnicodeObject
*
u
;
int
tabsize
=
8
;
...
...
@@ -6503,63 +6504,70 @@ unicode_expandtabs(PyUnicodeObject *self, PyObject *args)
return
NULL
;
/* First pass: determine size of output string */
i
=
j
=
old_j
=
0
;
e
=
self
->
str
+
self
->
length
;
i
=
0
;
/* chars up to and including most recent \n or \r */
j
=
0
;
/* chars since most recent \n or \r (use in tab calculations) */
e
=
self
->
str
+
self
->
length
;
/* end of input */
for
(
p
=
self
->
str
;
p
<
e
;
p
++
)
if
(
*
p
==
'\t'
)
{
if
(
tabsize
>
0
)
{
j
+=
tabsize
-
(
j
%
tabsize
);
if
(
old_j
>
j
)
{
PyErr_SetString
(
PyExc_OverflowError
,
"new string is too long"
);
return
NULL
;
}
old_j
=
j
;
}
incr
=
tabsize
-
(
j
%
tabsize
);
/* cannot overflow */
if
(
j
>
PY_SSIZE_T_MAX
-
incr
)
goto
overflow1
;
j
+=
incr
;
}
}
else
{
if
(
j
>
PY_SSIZE_T_MAX
-
1
)
goto
overflow1
;
j
++
;
if
(
*
p
==
'\n'
||
*
p
==
'\r'
)
{
if
(
i
>
PY_SSIZE_T_MAX
-
j
)
goto
overflow1
;
i
+=
j
;
old_j
=
j
=
0
;
if
(
i
<
0
)
{
PyErr_SetString
(
PyExc_OverflowError
,
"new string is too long"
);
return
NULL
;
}
j
=
0
;
}
}
if
((
i
+
j
)
<
0
)
{
PyErr_SetString
(
PyExc_OverflowError
,
"new string is too long"
);
return
NULL
;
}
if
(
i
>
PY_SSIZE_T_MAX
-
j
)
goto
overflow1
;
/* Second pass: create output string and fill it */
u
=
_PyUnicode_New
(
i
+
j
);
if
(
!
u
)
return
NULL
;
j
=
0
;
q
=
u
->
str
;
j
=
0
;
/* same as in first pass */
q
=
u
->
str
;
/* next output char */
qe
=
u
->
str
+
u
->
length
;
/* end of output */
for
(
p
=
self
->
str
;
p
<
e
;
p
++
)
if
(
*
p
==
'\t'
)
{
if
(
tabsize
>
0
)
{
i
=
tabsize
-
(
j
%
tabsize
);
j
+=
i
;
while
(
i
--
)
while
(
i
--
)
{
if
(
q
>=
qe
)
goto
overflow2
;
*
q
++
=
' '
;
}
}
}
else
{
j
++
;
if
(
q
>=
qe
)
goto
overflow2
;
*
q
++
=
*
p
;
j
++
;
if
(
*
p
==
'\n'
||
*
p
==
'\r'
)
j
=
0
;
}
return
(
PyObject
*
)
u
;
overflow2:
Py_DECREF
(
u
);
overflow1:
PyErr_SetString
(
PyExc_OverflowError
,
"new string is too long"
);
return
NULL
;
}
PyDoc_STRVAR
(
find__doc__
,
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment