Throw error if sizes of referenced arrays are near INT_MAX.
PiperOrigin-RevId: 484218386 Change-Id: I07dff633b4911bf296ad8993550509ed7b3dfe53
This commit is contained in:
committed by
Copybara-Service
parent
f695f55253
commit
507b573763
@@ -35,6 +35,8 @@
|
||||
#pragma warning (disable: 4305) // disable MSVC warning: truncation from 'double' to 'float'
|
||||
#endif
|
||||
|
||||
static const int MAX_ARRAY_SIZE = INT_MAX / 4;
|
||||
|
||||
//------------------------------ mjLROpt -----------------------------------------------------------
|
||||
|
||||
// set default options for length range computation
|
||||
@@ -454,7 +456,7 @@ mjModel* mj_makeModel(int nq, int nv, int nu, int na, int nbody, int njnt,
|
||||
}
|
||||
|
||||
// nmocap is going to get multiplied by 4, and shouldn't overflow
|
||||
if (m->nmocap >= INT_MAX / 4) {
|
||||
if (m->nmocap >= MAX_ARRAY_SIZE) {
|
||||
mju_free(m);
|
||||
mju_warning("Invalid model: nmocap too large");
|
||||
return 0;
|
||||
@@ -1405,6 +1407,9 @@ const char* mj_validateReferences(const mjModel* m) {
|
||||
if (num < 0) { \
|
||||
return "Invalid model: " #numarray " is negative."; \
|
||||
} \
|
||||
if (num > MAX_ARRAY_SIZE) { \
|
||||
return "Invalid model: " #numarray " is too large."; \
|
||||
} \
|
||||
int adrsmax = m->adrarray[i] + num; \
|
||||
if (adrsmax > m->ntarget || adrsmin < -1) { \
|
||||
return "Invalid model: " #adrarray " out of bounds."; \
|
||||
|
||||
Reference in New Issue
Block a user