code cleanup - fix memory leaks, buffer overflows, etc.

This commit is contained in:
dborth 2009-01-05 22:21:27 +00:00
parent 31c1d13fcf
commit 5ef12bcea9
6 changed files with 176 additions and 125 deletions

View File

@ -370,7 +370,7 @@ getentry (int entrycount, unsigned char dvdbuffer[])
if (entrycount >= MAXDVDFILES)
return 0;
if (diroffset >= 2048)
if (diroffset >= 2048 || diroffset < 0)
return 0;
/** Decode this entry **/
@ -384,7 +384,7 @@ getentry (int entrycount, unsigned char dvdbuffer[])
/* Check for wrap round - illegal in ISO spec,
* but certain crap writers do it! */
if ((diroffset + dvdbuffer[diroffset]) > 2048)
if ((diroffset + dvdbuffer[diroffset]) > 2048 || (diroffset + dvdbuffer[diroffset]) < 0)
return 0;
if (*filenamelength)
@ -392,7 +392,9 @@ getentry (int entrycount, unsigned char dvdbuffer[])
memset (&fname, 0, 512);
if (!IsJoliet) /*** Do ISO 9660 first ***/
strcpy (fname, filename);
{
strncpy (fname, filename, 512);
}
else
{ /*** The more tortuous unicode joliet entries ***/
for (j = 0; j < (*filenamelength >> 1); j++)
@ -437,17 +439,22 @@ getentry (int entrycount, unsigned char dvdbuffer[])
if (rr != NULL)
*rr = 0;
browserList = (BROWSERENTRY *)realloc(browserList, (entrycount+1) * sizeof(BROWSERENTRY));
if(!browserList) // failed to allocate required memory
BROWSERENTRY * newBrowserList = (BROWSERENTRY *)realloc(browserList, (entrycount+1) * sizeof(BROWSERENTRY));
if(!newBrowserList) // failed to allocate required memory
{
ResetBrowser();
WaitPrompt("Out of memory: too many files!");
return 0;
}
else
{
browserList = newBrowserList;
}
memset(&(browserList[entrycount]), 0, sizeof(BROWSERENTRY)); // clear the new entry
strcpy (browserList[entrycount].filename, fname);
strncpy (browserList[entrycount].filename, fname, MAXJOLIET);
StripExt(tmpname, fname); // hide file extension
strcpy (browserList[entrycount].displayname, tmpname);
strncpy (browserList[entrycount].displayname, tmpname, MAXDISPLAY);
memcpy (&offset32, &dvdbuffer[diroffset + EXTENT], 4);

View File

@ -48,12 +48,10 @@ extern u32 iNESGameCRC32;
#define RLSB 0x80000000
static int sboffset; /*** Used as a basic fileptr ***/
static int mcversion = 0x981211;
/****************************************************************************
* Memory based file functions
****************************************************************************/
static int sboffset; // Used as a basic fileptr
/*** Open a file ***/
static void memopen()
@ -62,23 +60,26 @@ static void memopen()
}
/*** Write to the file ***/
static void memfwrite( void *buffer, int len ) {
static void memfwrite(void *buffer, int len)
{
if ((sboffset + len) > SAVEBUFFERSIZE)
WaitPrompt("Buffer Exceeded");
if ( len > 0 ) {
if (len > 0)
{
memcpy(&savebuffer[sboffset], buffer, len);
sboffset += len;
}
}
/*** Read from a file ***/
static void memfread( void *buffer, int len ) {
static void memfread(void *buffer, int len)
{
if ( (sboffset + len) > SAVEBUFFERSIZE)
WaitPrompt("Buffer exceeded");
if ( len > 0 ) {
if (len > 0)
{
memcpy(buffer, &savebuffer[sboffset], len);
sboffset += len;
}
@ -279,6 +280,7 @@ static int GCFCEUSS_Save(int method)
}
// Add version ID
int mcversion = 0x981211;
memcpy(&header[8], &mcversion, 4);
// Do internal Saving

View File

@ -276,13 +276,13 @@ ParseDirectory()
WaitPrompt(msg);
// if we can't open the dir, open root dir
sprintf(fulldir,"%s",rootdir);
sprintf(browser.dir,"/");
dir = diropen(browser.dir);
dir = diropen(rootdir);
if (dir == NULL)
{
sprintf(msg, "Error opening %s", fulldir);
sprintf(msg, "Error opening %s", rootdir);
WaitPrompt(msg);
return 0;
}
@ -295,14 +295,19 @@ ParseDirectory()
{
if(strcmp(filename,".") != 0)
{
browserList = (BROWSERENTRY *)realloc(browserList, (entryNum+1) * sizeof(BROWSERENTRY));
BROWSERENTRY * newBrowserList = (BROWSERENTRY *)realloc(browserList, (entryNum+1) * sizeof(BROWSERENTRY));
if(!browserList) // failed to allocate required memory
if(!newBrowserList) // failed to allocate required memory
{
ResetBrowser();
WaitPrompt("Out of memory: too many files!");
entryNum = 0;
break;
}
else
{
browserList = newBrowserList;
}
memset(&(browserList[entryNum]), 0, sizeof(BROWSERENTRY)); // clear the new entry
strncpy(browserList[entryNum].filename, filename, MAXJOLIET);

View File

@ -465,14 +465,19 @@ int SzParse(char * filepath, int method)
if (SzF->IsDirectory)
continue;
browserList = (BROWSERENTRY *)realloc(browserList, (SzJ+1) * sizeof(BROWSERENTRY));
BROWSERENTRY * newBrowserList = (BROWSERENTRY *)realloc(browserList, (SzJ+1) * sizeof(BROWSERENTRY));
if(!browserList) // failed to allocate required memory
if(!newBrowserList) // failed to allocate required memory
{
ResetBrowser();
WaitPrompt("Out of memory: too many files!");
nbfiles = 0;
break;
}
else
{
browserList = newBrowserList;
}
memset(&(browserList[SzJ]), 0, sizeof(BROWSERENTRY)); // clear the new entry
// parse information about this file to the dvd file list structure

View File

@ -45,8 +45,9 @@ void UpdateCheck()
snprintf(url, 128, "http://fceugc.googlecode.com/svn/trunk/update.xml");
AllocSaveBuffer ();
retval = http_request(url, NULL, (u8 *)savebuffer, SAVEBUFFERSIZE);
u8 * tmpbuffer = (u8 *)malloc(32768);
memset(tmpbuffer, 0, 32768);
retval = http_request(url, NULL, tmpbuffer, 32768);
memset(url, 0, 128);
if (retval)
@ -54,13 +55,15 @@ void UpdateCheck()
mxml_node_t *xml;
mxml_node_t *item;
xml = mxmlLoadString(NULL, (char *)savebuffer, MXML_TEXT_CALLBACK);
xml = mxmlLoadString(NULL, (char *)tmpbuffer, MXML_TEXT_CALLBACK);
if(xml)
{
// check settings version
item = mxmlFindElement(xml, xml, "app", "version", NULL, MXML_DESCEND);
if(item) // a version entry exists
{
char * version = (char *)mxmlElementGetAttr(item, "version");
const char * version = (char *)mxmlElementGetAttr(item, "version");
int verMajor = version[0] - '0';
int verMinor = version[2] - '0';
@ -80,13 +83,19 @@ void UpdateCheck()
item = mxmlFindElement(xml, xml, "file", NULL, NULL, MXML_DESCEND);
if(item)
{
snprintf(updateURL, 128, "%s", mxmlElementGetAttr(item, "url"));
const char * tmp = mxmlElementGetAttr(item, "url");
if(tmp)
{
snprintf(updateURL, 128, "%s", tmp);
updateFound = true;
}
}
}
}
FreeSaveBuffer();
mxmlDelete(xml);
}
}
free(tmpbuffer);
}
}
@ -129,7 +138,7 @@ bool DownloadUpdate()
retval = http_request(updateURL, hfile, NULL, (1024*1024*5));
fclose (hfile);
}
ShowAction("Unzipping...");
ShowAction("Installing...");
bool unzipResult = unzipArchive(updateFile, (char *)"sd:/");
remove(updateFile); // delete update file

View File

@ -23,18 +23,16 @@
extern const unsigned short saveicon[1024];
static char prefscomment[2][32];
/****************************************************************************
* Prepare Preferences Data
*
* This sets up the save buffer for saving.
****************************************************************************/
static mxml_node_t *xml;
static mxml_node_t *data;
static mxml_node_t *section;
static mxml_node_t *item;
static mxml_node_t *elem;
static mxml_node_t *xml = NULL;
static mxml_node_t *data = NULL;
static mxml_node_t *section = NULL;
static mxml_node_t *item = NULL;
static mxml_node_t *elem = NULL;
static char temp[200];
@ -112,7 +110,6 @@ static int
preparePrefsData (int method)
{
int offset = 0;
memset (savebuffer, 0, SAVEBUFFERSIZE);
// add save icon and comments for Memory Card saves
if(method == METHOD_MC_SLOTA || method == METHOD_MC_SLOTB)
@ -123,6 +120,8 @@ preparePrefsData (int method)
memcpy (savebuffer, saveicon, offset);
// And the comments
char prefscomment[2][32];
memset(prefscomment, 0, 64);
sprintf (prefscomment[0], "%s Prefs", APPNAME);
sprintf (prefscomment[1], "Preferences");
memcpy (savebuffer + offset, prefscomment, 64);
@ -189,19 +188,31 @@ static void loadXMLSettingStr(char * var, const char * name, int maxsize)
{
item = mxmlFindElement(xml, xml, "setting", "name", name, MXML_DESCEND);
if(item)
snprintf(var, maxsize, "%s", mxmlElementGetAttr(item, "value"));
{
const char * tmp = mxmlElementGetAttr(item, "value");
if(tmp)
snprintf(var, maxsize, "%s", tmp);
}
}
static void loadXMLSettingInt(int * var, const char * name)
{
item = mxmlFindElement(xml, xml, "setting", "name", name, MXML_DESCEND);
if(item)
*var = atoi(mxmlElementGetAttr(item, "value"));
{
const char * tmp = mxmlElementGetAttr(item, "value");
if(tmp)
*var = atoi(tmp);
}
}
static void loadXMLSettingFloat(float * var, const char * name)
{
item = mxmlFindElement(xml, xml, "setting", "name", name, MXML_DESCEND);
if(item)
*var = atof(mxmlElementGetAttr(item, "value"));
{
const char * tmp = mxmlElementGetAttr(item, "value");
if(tmp)
*var = atof(tmp);
}
}
static void loadXMLController(unsigned int controller[], const char * name)
@ -217,7 +228,11 @@ static void loadXMLController(unsigned int controller[], const char * name)
{
elem = mxmlFindElement(item, xml, "button", "number", toStr(i), MXML_DESCEND);
if(elem)
controller[i] = atoi(mxmlElementGetAttr(elem, "assignment"));
{
const char * tmp = mxmlElementGetAttr(elem, "assignment");
if(tmp)
controller[i] = atoi(tmp);
}
}
}
}
@ -225,6 +240,7 @@ static void loadXMLController(unsigned int controller[], const char * name)
static bool
decodePrefsData (int method)
{
bool result = false;
int offset = 0;
// skip save icon and comments for Memory Card saves
@ -236,15 +252,16 @@ decodePrefsData (int method)
xml = mxmlLoadString(NULL, (char *)savebuffer+offset, MXML_TEXT_CALLBACK);
if(xml)
{
// check settings version
// we don't do anything with the version #, but we'll store it anyway
char * version;
item = mxmlFindElement(xml, xml, "file", "version", NULL, MXML_DESCEND);
if(item) // a version entry exists
version = (char *)mxmlElementGetAttr(item, "version");
else // version # not found, must be invalid
return false;
{
const char * version = (char *)mxmlElementGetAttr(item, "version");
if(version)
{
// this code assumes version in format X.X.X
// XX.X.X, X.XX.X, or X.X.XX will NOT work
int verMajor = version[0] - '0';
@ -258,13 +275,18 @@ decodePrefsData (int method)
if(!(verMajor >= 0 && verMajor <= 9 &&
verMinor >= 0 && verMinor <= 9 &&
verPoint >= 0 && verPoint <= 9))
return false;
if(verMajor == 2 && verPoint < 7) // less than version 2.0.7
return false; // reset settings
result = false;
else if(verMajor == 2 && verPoint < 7) // less than version 2.0.7
result = false; // reset settings
else if(verMajor > curMajor || verMinor > curMinor || verPoint > curPoint) // some future version
return false; // reset settings
result = false; // reset settings
else
result = true;
}
}
if(result)
{
// File Settings
loadXMLSettingInt(&GCSettings.AutoLoad, "AutoLoad");
@ -303,10 +325,11 @@ decodePrefsData (int method)
loadXMLController(wmpadmap, "wmpadmap");
loadXMLController(ccpadmap, "ccpadmap");
loadXMLController(ncpadmap, "ncpadmap");
}
mxmlDelete(xml);
}
return true;
return result;
}
/****************************************************************************