Issue #16335: Fix integer overflow in unicode-escape decoder.
This commit is contained in:
parent
b357db885c
commit
1d3acd4b59
|
@ -8,6 +8,7 @@ Modified for Python 2.0 by Fredrik Lundh (fredrik@pythonware.com)
|
||||||
"""#"
|
"""#"
|
||||||
|
|
||||||
import unittest
|
import unittest
|
||||||
|
import _testcapi
|
||||||
|
|
||||||
from test import test_support
|
from test import test_support
|
||||||
|
|
||||||
|
@ -137,6 +138,21 @@ class UnicodeNamesTest(unittest.TestCase):
|
||||||
unicode, "\\NSPACE", 'unicode-escape', 'strict'
|
unicode, "\\NSPACE", 'unicode-escape', 'strict'
|
||||||
)
|
)
|
||||||
|
|
||||||
|
@unittest.skipUnless(_testcapi.INT_MAX < _testcapi.PY_SSIZE_T_MAX,
|
||||||
|
"needs UINT_MAX < SIZE_MAX")
|
||||||
|
def test_issue16335(self):
|
||||||
|
# very very long bogus character name
|
||||||
|
try:
|
||||||
|
x = b'\\N{SPACE' + b'x' * int(_testcapi.UINT_MAX + 1) + b'}'
|
||||||
|
except MemoryError:
|
||||||
|
raise unittest.SkipTest("not enough memory")
|
||||||
|
self.assertEqual(len(x), len(b'\\N{SPACE}') + (_testcapi.UINT_MAX + 1))
|
||||||
|
self.assertRaisesRegex(UnicodeError,
|
||||||
|
'unknown Unicode character name',
|
||||||
|
x.decode, 'unicode-escape'
|
||||||
|
)
|
||||||
|
|
||||||
|
|
||||||
def test_main():
|
def test_main():
|
||||||
test_support.run_unittest(UnicodeNamesTest)
|
test_support.run_unittest(UnicodeNamesTest)
|
||||||
|
|
||||||
|
|
|
@ -2899,7 +2899,8 @@ PyObject *PyUnicode_DecodeUnicodeEscape(const char *s,
|
||||||
/* found a name. look it up in the unicode database */
|
/* found a name. look it up in the unicode database */
|
||||||
message = "unknown Unicode character name";
|
message = "unknown Unicode character name";
|
||||||
s++;
|
s++;
|
||||||
if (ucnhash_CAPI->getcode(NULL, start, (int)(s-start-1), &chr))
|
if (s - start - 1 <= INT_MAX &&
|
||||||
|
ucnhash_CAPI->getcode(NULL, start, (int)(s-start-1), &chr))
|
||||||
goto store;
|
goto store;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
Loading…
Reference in New Issue