Make sure the size of items on the model / data buffer is never negative.
Explicitly check that nmocap won't cause overflow when multiplied by 4, to give a nicer error message. PiperOrigin-RevId: 465380712 Change-Id: I217e3759d55e9761b47db5efd892b8bc811ea8ae
This commit is contained in:
committed by
Copybara-Service
parent
4268d81b55
commit
760816ae18
@@ -15,6 +15,7 @@
|
||||
|
||||
#include "engine/engine_io.h"
|
||||
|
||||
#include <limits.h>
|
||||
#include <stdint.h>
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
@@ -361,6 +362,9 @@ static void mj_setPtrModel(mjModel* m) {
|
||||
// *nbuffer += SKIP(*offset) + type_size*nr*nc;
|
||||
// *offset += SKIP(*offset) + type_size*nr*nc;
|
||||
static int safeAddToBufferSize(intptr_t* offset, int* nbuffer, size_t type_size, int nr, int nc) {
|
||||
if (type_size < 0 || nr < 0 || nc < 0) {
|
||||
return 0;
|
||||
}
|
||||
#if (__has_builtin(__builtin_add_overflow) && __has_builtin(__builtin_mul_overflow)) \
|
||||
|| (defined(__GNUC__) && __GNUC__ >= 5)
|
||||
// supported by GCC and Clang
|
||||
@@ -469,6 +473,13 @@ mjModel* mj_makeModel(int nq, int nv, int nu, int na, int nbody, int njnt,
|
||||
return 0;
|
||||
}
|
||||
|
||||
// nmocap is going to get multiplied by 4, and shouldn't overflow
|
||||
if (m->nmocap >= INT_MAX / 4) {
|
||||
mju_warning("Invalid model: nmocap too large");
|
||||
mj_deleteModel(m);
|
||||
return 0;
|
||||
}
|
||||
|
||||
// compute buffer size
|
||||
m->nbuffer = 0;
|
||||
#define X(type, name, nr, nc) \
|
||||
|
||||
Reference in New Issue
Block a user