# HG changeset patch # User Yuya Nishihara # Date 2015-10-11 09:41:41 # Node ID 473a63c45394e7c6d88bd4e40721a7256599ca32 # Parent fb388aa26453080a703a22df8b199689295114ba parsers: read sizes of metadata pair of obsolete marker at once This will make it easy to implement bound checking. Currently fm1readmarker() has no protection for corrupted obsstore and can cause infinite loop or out-of-bound reads. diff --git a/mercurial/parsers.c b/mercurial/parsers.c --- a/mercurial/parsers.c +++ b/mercurial/parsers.c @@ -2630,12 +2630,12 @@ static PyObject *fm1readmarker(const cha } for (i = 0; i < nmetadata; i++) { PyObject *tmp, *left = NULL, *right = NULL; - Py_ssize_t metasize = (unsigned char)(*data++); - left = PyString_FromStringAndSize(meta, metasize); - meta += metasize; - metasize = (unsigned char)(*data++); - right = PyString_FromStringAndSize(meta, metasize); - meta += metasize; + Py_ssize_t leftsize = (unsigned char)(*data++); + Py_ssize_t rightsize = (unsigned char)(*data++); + left = PyString_FromStringAndSize(meta, leftsize); + meta += leftsize; + right = PyString_FromStringAndSize(meta, rightsize); + meta += rightsize; tmp = PyTuple_New(2); if (!left || !right || !tmp) { Py_XDECREF(left);