瀏覽代碼

allow non-integer arguments to integer formats (%d, %x, etc.),
but check range

Roberto Ierusalimschy 13 年之前
父節點
當前提交
f1d2ac3a98
共有 1 個文件被更改,包括 10 次插入9 次删除
  1. 10 9
      lstrlib.c

+ 10 - 9
lstrlib.c

@@ -1,5 +1,5 @@
 /*
-** $Id: lstrlib.c,v 1.171 2011/08/09 20:58:29 roberto Exp roberto $
+** $Id: lstrlib.c,v 1.172 2011/10/25 12:01:20 roberto Exp roberto $
 ** Standard library for string operations and pattern-matching
 ** See Copyright Notice in lua.h
 */
@@ -756,6 +756,9 @@ static int str_gsub (lua_State *L) {
 #endif
 #endif				/* } */
 
+#define MAX_UINTFRM	((lua_Number)(~(unsigned LUA_INTFRM_T)0))
+#define MAX_INTFRM	((lua_Number)((~(unsigned LUA_INTFRM_T)0)/2))
+#define MIN_INTFRM	(-(lua_Number)((~(unsigned LUA_INTFRM_T)0)/2) - 1)
 
 /*
 ** LUA_FLTFRMLEN is the length modifier for float conversions in
@@ -867,20 +870,18 @@ static int str_format (lua_State *L) {
         }
         case 'd':  case 'i': {
           lua_Number n = luaL_checknumber(L, arg);
-          LUA_INTFRM_T r = (LUA_INTFRM_T)n;
-          luaL_argcheck(L, (lua_Number)r == n, arg,
-                        "not an integer in proper range");
+          luaL_argcheck(L, (MIN_INTFRM - 1) < n && n < (MAX_INTFRM + 1), arg,
+                        "not a number in proper range");
           addlenmod(form, LUA_INTFRMLEN);
-          nb = sprintf(buff, form, r);
+          nb = sprintf(buff, form, (LUA_INTFRM_T)n);
           break;
         }
         case 'o':  case 'u':  case 'x':  case 'X': {
           lua_Number n = luaL_checknumber(L, arg);
-          unsigned LUA_INTFRM_T r = (unsigned LUA_INTFRM_T)n;
-          luaL_argcheck(L, (lua_Number)r == n, arg,
-                        "not a non-negative integer in proper range");
+          luaL_argcheck(L, 0 <= n && n < (MAX_UINTFRM + 1), arg,
+                        "not a non-negative number in proper range");
           addlenmod(form, LUA_INTFRMLEN);
-          nb = sprintf(buff, form, r);
+          nb = sprintf(buff, form, (unsigned LUA_INTFRM_T)n);
           break;
         }
         case 'e':  case 'E': case 'f':