This is the mail archive of the libstdc++@gcc.gnu.org mailing list for the libstdc++ project.


Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]
Other format: [Raw text]

[PATCH] libstdc++/7961


Hi,

I believe John is right, even if it is difficult to create an
actually seg-faulting testcase. In the following

#include <string>
#include <cassert>

int main()
{
 std::string lhs("abc");

 lhs.push_back('\0');
 lhs += "def";

 assert( lhs != "abc" );
}

operator!= (memcmp, that is) access "abc" past its final '\0',
since lhs.size() == 7 and this value is currently used in
the memcmp() call from compare().

Indeed, John's fix makes compare(const _CharT* __s) consistent
with the current implementation of compare(size_type, size_type,
const _CharT*) in the use of traits_type::length(__s) and min().

Ok to apply?

Ciao, Paolo.

P.S. For Andreas: in v3 there are no risks of overflows in the
final computations of __r since max_size < npos/4.

///////

2002-11-01  John Carter  <john.carter@tait.co.nz>

       PR libstdc++/7961
       * include/bits/basic_string.tcc
       (compare(const _CharT* __s)): Don't access __s past its length.


diff -urN libstdc++-v3-orig/include/bits/basic_string.tcc libstdc++-v3/include/bits/basic_string.tcc
--- libstdc++-v3-orig/include/bits/basic_string.tcc	2002-10-27 08:35:06.000000000 +0100
+++ libstdc++-v3/include/bits/basic_string.tcc	2002-11-01 12:14:17.000000000 +0100
@@ -884,9 +884,11 @@
     compare(const _CharT* __s) const
     {
       size_type __size = this->size();
-      int __r = traits_type::compare(_M_data(), __s, __size);
+      size_type __osize = traits_type::length(__s);
+      size_type __len = min(__size, __osize);
+      int __r = traits_type::compare(_M_data(), __s, __len);
       if (!__r)
-	__r = __size - traits_type::length(__s);
+	__r = __size - __osize;
       return __r;
     }
 

Index Nav: [Date Index] [Subject Index] [Author Index] [Thread Index]
Message Nav: [Date Prev] [Date Next] [Thread Prev] [Thread Next]