Karsten Hopp 4d5cfa
To: vim_dev@googlegroups.com
Karsten Hopp 4d5cfa
Subject: Patch 7.3.975
Karsten Hopp 4d5cfa
Fcc: outbox
Karsten Hopp 4d5cfa
From: Bram Moolenaar <Bram@moolenaar.net>
Karsten Hopp 4d5cfa
Mime-Version: 1.0
Karsten Hopp 4d5cfa
Content-Type: text/plain; charset=UTF-8
Karsten Hopp 4d5cfa
Content-Transfer-Encoding: 8bit
Karsten Hopp 4d5cfa
------------
Karsten Hopp 4d5cfa
Karsten Hopp 4d5cfa
Patch 7.3.975
Karsten Hopp 4d5cfa
Problem:    Crash in regexp parsing.
Karsten Hopp 4d5cfa
Solution:   Correctly compute the end of allocated memory.
Karsten Hopp 4d5cfa
Files:	    src/regexp_nfa.c
Karsten Hopp 4d5cfa
Karsten Hopp 4d5cfa
Karsten Hopp 4d5cfa
*** ../vim-7.3.974/src/regexp_nfa.c	2013-05-19 22:31:13.000000000 +0200
Karsten Hopp 4d5cfa
--- src/regexp_nfa.c	2013-05-20 13:43:37.000000000 +0200
Karsten Hopp 4d5cfa
***************
Karsten Hopp 4d5cfa
*** 231,244 ****
Karsten Hopp 4d5cfa
      /* A reasonable estimation for size */
Karsten Hopp 4d5cfa
      nstate_max = (STRLEN(expr) + 1) * NFA_POSTFIX_MULTIPLIER;
Karsten Hopp 4d5cfa
  
Karsten Hopp 4d5cfa
!     /* Size for postfix representation of expr */
Karsten Hopp 4d5cfa
      postfix_size = sizeof(*post_start) * nstate_max;
Karsten Hopp 4d5cfa
      post_start = (int *)lalloc(postfix_size, TRUE);
Karsten Hopp 4d5cfa
      if (post_start == NULL)
Karsten Hopp 4d5cfa
  	return FAIL;
Karsten Hopp 4d5cfa
      vim_memset(post_start, 0, postfix_size);
Karsten Hopp 4d5cfa
      post_ptr = post_start;
Karsten Hopp 4d5cfa
!     post_end = post_start + postfix_size;
Karsten Hopp 4d5cfa
      nfa_has_zend = FALSE;
Karsten Hopp 4d5cfa
  
Karsten Hopp 4d5cfa
      regcomp_start(expr, re_flags);
Karsten Hopp 4d5cfa
--- 231,249 ----
Karsten Hopp 4d5cfa
      /* A reasonable estimation for size */
Karsten Hopp 4d5cfa
      nstate_max = (STRLEN(expr) + 1) * NFA_POSTFIX_MULTIPLIER;
Karsten Hopp 4d5cfa
  
Karsten Hopp 4d5cfa
!     /* Some items blow up in size, such as [A-z].  Add more space for that.
Karsten Hopp 4d5cfa
!      * TODO: some patterns may still fail. */
Karsten Hopp 4d5cfa
! //    nstate_max += 1000;
Karsten Hopp 4d5cfa
! 
Karsten Hopp 4d5cfa
!     /* Size for postfix representation of expr. */
Karsten Hopp 4d5cfa
      postfix_size = sizeof(*post_start) * nstate_max;
Karsten Hopp 4d5cfa
+ 
Karsten Hopp 4d5cfa
      post_start = (int *)lalloc(postfix_size, TRUE);
Karsten Hopp 4d5cfa
      if (post_start == NULL)
Karsten Hopp 4d5cfa
  	return FAIL;
Karsten Hopp 4d5cfa
      vim_memset(post_start, 0, postfix_size);
Karsten Hopp 4d5cfa
      post_ptr = post_start;
Karsten Hopp 4d5cfa
!     post_end = post_start + nstate_max;
Karsten Hopp 4d5cfa
      nfa_has_zend = FALSE;
Karsten Hopp 4d5cfa
  
Karsten Hopp 4d5cfa
      regcomp_start(expr, re_flags);
Karsten Hopp 4d5cfa
*** ../vim-7.3.974/src/version.c	2013-05-20 12:52:23.000000000 +0200
Karsten Hopp 4d5cfa
--- src/version.c	2013-05-20 13:42:10.000000000 +0200
Karsten Hopp 4d5cfa
***************
Karsten Hopp 4d5cfa
*** 730,731 ****
Karsten Hopp 4d5cfa
--- 730,733 ----
Karsten Hopp 4d5cfa
  {   /* Add new patch number below this line */
Karsten Hopp 4d5cfa
+ /**/
Karsten Hopp 4d5cfa
+     975,
Karsten Hopp 4d5cfa
  /**/
Karsten Hopp 4d5cfa
Karsten Hopp 4d5cfa
-- 
Karsten Hopp 4d5cfa
My Go, this amn keyboar oesn't have a .
Karsten Hopp 4d5cfa
Karsten Hopp 4d5cfa
 /// Bram Moolenaar -- Bram@Moolenaar.net -- http://www.Moolenaar.net   \\\
Karsten Hopp 4d5cfa
///        sponsor Vim, vote for features -- http://www.Vim.org/sponsor/ \\\
Karsten Hopp 4d5cfa
\\\  an exciting new programming language -- http://www.Zimbu.org        ///
Karsten Hopp 4d5cfa
 \\\            help me help AIDS victims -- http://ICCF-Holland.org    ///