3ef2ca
To: vim_dev@googlegroups.com
3ef2ca
Subject: Patch 7.4.624
3ef2ca
Fcc: outbox
3ef2ca
From: Bram Moolenaar <Bram@moolenaar.net>
3ef2ca
Mime-Version: 1.0
3ef2ca
Content-Type: text/plain; charset=UTF-8
3ef2ca
Content-Transfer-Encoding: 8bit
3ef2ca
------------
3ef2ca
3ef2ca
Patch 7.4.624
3ef2ca
Problem:    May leak memory or crash when vim_realloc() returns NULL.
3ef2ca
Solution:   Handle a NULL value properly. (Mike Williams)
3ef2ca
Files:	    src/if_cscope.c, src/memline.c, src/misc1.c, src/netbeans.c
3ef2ca
3ef2ca
3ef2ca
*** ../vim-7.4.623/src/if_cscope.c	2014-12-13 03:20:10.539067382 +0100
3ef2ca
--- src/if_cscope.c	2015-02-10 18:33:14.764816257 +0100
3ef2ca
***************
3ef2ca
*** 1507,1515 ****
3ef2ca
--- 1507,1522 ----
3ef2ca
  	}
3ef2ca
  	else
3ef2ca
  	{
3ef2ca
+ 	    csinfo_T *t_csinfo = csinfo;
3ef2ca
+ 
3ef2ca
  	    /* Reallocate space for more connections. */
3ef2ca
  	    csinfo_size *= 2;
3ef2ca
  	    csinfo = vim_realloc(csinfo, sizeof(csinfo_T)*csinfo_size);
3ef2ca
+ 	    if (csinfo == NULL)
3ef2ca
+ 	    {
3ef2ca
+ 		vim_free(t_csinfo);
3ef2ca
+ 		csinfo_size = 0;
3ef2ca
+ 	    }
3ef2ca
  	}
3ef2ca
  	if (csinfo == NULL)
3ef2ca
  	    return -1;
3ef2ca
***************
3ef2ca
*** 2059,2064 ****
3ef2ca
--- 2066,2072 ----
3ef2ca
      int num_matches;
3ef2ca
  {
3ef2ca
      char	*buf = NULL;
3ef2ca
+     char	*t_buf;
3ef2ca
      int		bufsize = 0; /* Track available bufsize */
3ef2ca
      int		newsize = 0;
3ef2ca
      char	*ptag;
3ef2ca
***************
3ef2ca
*** 2120,2128 ****
3ef2ca
--- 2128,2140 ----
3ef2ca
  	newsize = (int)(strlen(csfmt_str) + 16 + strlen(lno));
3ef2ca
  	if (bufsize < newsize)
3ef2ca
  	{
3ef2ca
+ 	    t_buf = buf;
3ef2ca
  	    buf = (char *)vim_realloc(buf, newsize);
3ef2ca
  	    if (buf == NULL)
3ef2ca
+ 	    {
3ef2ca
  		bufsize = 0;
3ef2ca
+ 		vim_free(t_buf);
3ef2ca
+ 	    }
3ef2ca
  	    else
3ef2ca
  		bufsize = newsize;
3ef2ca
  	}
3ef2ca
***************
3ef2ca
*** 2143,2151 ****
3ef2ca
--- 2155,2167 ----
3ef2ca
  
3ef2ca
  	if (bufsize < newsize)
3ef2ca
  	{
3ef2ca
+ 	    t_buf = buf;
3ef2ca
  	    buf = (char *)vim_realloc(buf, newsize);
3ef2ca
  	    if (buf == NULL)
3ef2ca
+ 	    {
3ef2ca
  		bufsize = 0;
3ef2ca
+ 		vim_free(t_buf);
3ef2ca
+ 	    }
3ef2ca
  	    else
3ef2ca
  		bufsize = newsize;
3ef2ca
  	}
3ef2ca
*** ../vim-7.4.623/src/memline.c	2014-08-13 21:58:24.824885492 +0200
3ef2ca
--- src/memline.c	2015-02-10 18:26:23.158126542 +0100
3ef2ca
***************
3ef2ca
*** 5057,5062 ****
3ef2ca
--- 5057,5064 ----
3ef2ca
  	/* May resize here so we don't have to do it in both cases below */
3ef2ca
  	if (buf->b_ml.ml_usedchunks + 1 >= buf->b_ml.ml_numchunks)
3ef2ca
  	{
3ef2ca
+ 	    chunksize_T *t_chunksize = buf->b_ml.ml_chunksize;
3ef2ca
+ 
3ef2ca
  	    buf->b_ml.ml_numchunks = buf->b_ml.ml_numchunks * 3 / 2;
3ef2ca
  	    buf->b_ml.ml_chunksize = (chunksize_T *)
3ef2ca
  		vim_realloc(buf->b_ml.ml_chunksize,
3ef2ca
***************
3ef2ca
*** 5064,5069 ****
3ef2ca
--- 5066,5072 ----
3ef2ca
  	    if (buf->b_ml.ml_chunksize == NULL)
3ef2ca
  	    {
3ef2ca
  		/* Hmmmm, Give up on offset for this buffer */
3ef2ca
+ 		vim_free(t_chunksize);
3ef2ca
  		buf->b_ml.ml_usedchunks = -1;
3ef2ca
  		return;
3ef2ca
  	    }
3ef2ca
*** ../vim-7.4.623/src/misc1.c	2014-08-29 12:58:38.246430208 +0200
3ef2ca
--- src/misc1.c	2015-02-10 18:26:35.405968505 +0100
3ef2ca
***************
3ef2ca
*** 3431,3440 ****
3ef2ca
--- 3431,3444 ----
3ef2ca
  	    buf = alloc(buflen);
3ef2ca
  	else if (maxlen < 10)
3ef2ca
  	{
3ef2ca
+ 	    char_u  *t_buf = buf;
3ef2ca
+ 
3ef2ca
  	    /* Need some more space. This might happen when receiving a long
3ef2ca
  	     * escape sequence. */
3ef2ca
  	    buflen += 100;
3ef2ca
  	    buf = vim_realloc(buf, buflen);
3ef2ca
+ 	    if (buf == NULL)
3ef2ca
+ 		vim_free(t_buf);
3ef2ca
  	    maxlen = (buflen - 6 - len) / 3;
3ef2ca
  	}
3ef2ca
  	if (buf == NULL)
3ef2ca
*** ../vim-7.4.623/src/netbeans.c	2014-03-23 15:12:29.927264336 +0100
3ef2ca
--- src/netbeans.c	2015-02-10 18:27:18.693409965 +0100
3ef2ca
***************
3ef2ca
*** 1080,1089 ****
3ef2ca
--- 1080,1097 ----
3ef2ca
      {
3ef2ca
  	if (bufno >= buf_list_size) /* grow list */
3ef2ca
  	{
3ef2ca
+ 	    nbbuf_T *t_buf_list = buf_list;
3ef2ca
+ 
3ef2ca
  	    incr = bufno - buf_list_size + 90;
3ef2ca
  	    buf_list_size += incr;
3ef2ca
  	    buf_list = (nbbuf_T *)vim_realloc(
3ef2ca
  				   buf_list, buf_list_size * sizeof(nbbuf_T));
3ef2ca
+ 	    if (buf_list == NULL)
3ef2ca
+ 	    {
3ef2ca
+ 		vim_free(t_buf_list);
3ef2ca
+ 		buf_list_size = 0;
3ef2ca
+ 		return NULL;
3ef2ca
+ 	    }
3ef2ca
  	    vim_memset(buf_list + buf_list_size - incr, 0,
3ef2ca
  						      incr * sizeof(nbbuf_T));
3ef2ca
  	}
3ef2ca
***************
3ef2ca
*** 3678,3688 ****
3ef2ca
--- 3686,3703 ----
3ef2ca
  	    {
3ef2ca
  		int incr;
3ef2ca
  		int oldlen = globalsignmaplen;
3ef2ca
+ 		char **t_globalsignmap = globalsignmap;
3ef2ca
  
3ef2ca
  		globalsignmaplen *= 2;
3ef2ca
  		incr = globalsignmaplen - oldlen;
3ef2ca
  		globalsignmap = (char **)vim_realloc(globalsignmap,
3ef2ca
  					   globalsignmaplen * sizeof(char *));
3ef2ca
+ 		if (globalsignmap == NULL)
3ef2ca
+ 		{
3ef2ca
+ 		    vim_free(t_globalsignmap);
3ef2ca
+ 		    globalsignmaplen = 0;
3ef2ca
+ 		    return;
3ef2ca
+ 		}
3ef2ca
  		vim_memset(globalsignmap + oldlen, 0, incr * sizeof(char *));
3ef2ca
  	    }
3ef2ca
  	}
3ef2ca
***************
3ef2ca
*** 3708,3718 ****
3ef2ca
--- 3723,3740 ----
3ef2ca
  	{
3ef2ca
  	    int incr;
3ef2ca
  	    int oldlen = buf->signmaplen;
3ef2ca
+ 	    int *t_signmap = buf->signmap;
3ef2ca
  
3ef2ca
  	    buf->signmaplen *= 2;
3ef2ca
  	    incr = buf->signmaplen - oldlen;
3ef2ca
  	    buf->signmap = (int *)vim_realloc(buf->signmap,
3ef2ca
  					       buf->signmaplen * sizeof(int));
3ef2ca
+ 	    if (buf->signmap == NULL)
3ef2ca
+ 	    {
3ef2ca
+ 		vim_free(t_signmap);
3ef2ca
+ 		buf->signmaplen = 0;
3ef2ca
+ 		return;
3ef2ca
+ 	    }
3ef2ca
  	    vim_memset(buf->signmap + oldlen, 0, incr * sizeof(int));
3ef2ca
  	}
3ef2ca
      }
3ef2ca
*** ../vim-7.4.623/src/version.c	2015-02-10 18:18:13.004452406 +0100
3ef2ca
--- src/version.c	2015-02-10 18:21:29.697913596 +0100
3ef2ca
***************
3ef2ca
*** 743,744 ****
3ef2ca
--- 743,746 ----
3ef2ca
  {   /* Add new patch number below this line */
3ef2ca
+ /**/
3ef2ca
+     624,
3ef2ca
  /**/
3ef2ca
3ef2ca
-- 
3ef2ca
hundred-and-one symptoms of being an internet addict:
3ef2ca
211. Your husband leaves you...taking the computer with him and you
3ef2ca
     call him crying, and beg him to bring the computer back.
3ef2ca
3ef2ca
 /// Bram Moolenaar -- Bram@Moolenaar.net -- http://www.Moolenaar.net   \\\
3ef2ca
///        sponsor Vim, vote for features -- http://www.Vim.org/sponsor/ \\\
3ef2ca
\\\  an exciting new programming language -- http://www.Zimbu.org        ///
3ef2ca
 \\\            help me help AIDS victims -- http://ICCF-Holland.org    ///