[Bug #19754] Make IO::Buffer#get_string check offset range (#8016)

This commit is contained in:
Nobuyoshi Nakada 2023-09-13 06:45:26 +09:00 committed by GitHub
parent 11c32e33eb
commit 19346c2336
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
Notes: git 2023-09-12 21:45:46 +00:00
Merged-By: ioquatix <samuel@codeotaku.com>
2 changed files with 11 additions and 0 deletions

View File

@ -1156,6 +1156,9 @@ VALUE rb_io_buffer_free_locked(VALUE self)
static inline void
io_buffer_validate_range(struct rb_io_buffer *buffer, size_t offset, size_t length)
{
if (offset > buffer->size) {
rb_raise(rb_eArgError, "Specified offset exceeds buffer size!");
}
if (offset + length > buffer->size) {
rb_raise(rb_eArgError, "Specified offset+length exceeds buffer size!");
}

View File

@ -251,6 +251,14 @@ class TestIOBuffer < Test::Unit::TestCase
chunk = buffer.get_string(0, message.bytesize, Encoding::BINARY)
assert_equal Encoding::BINARY, chunk.encoding
assert_raise_with_message(ArgumentError, /exceeds buffer size/) do
buffer.get_string(0, 129)
end
assert_raise_with_message(ArgumentError, /exceeds buffer size/) do
buffer.get_string(129)
end
end
# We check that values are correctly round tripped.