Make sure the size of items on the model / data buffer is never negative.

Explicitly check that nmocap won't cause overflow when multiplied by 4, to give a nicer error message.

PiperOrigin-RevId: 465380712
Change-Id: I217e3759d55e9761b47db5efd892b8bc811ea8ae
This commit is contained in:
Nimrod Gileadi
2022-08-04 12:46:40 -07:00
committed by Copybara-Service
parent 4268d81b55
commit 760816ae18
+11
View File
@@ -15,6 +15,7 @@
#include "engine/engine_io.h"
#include <limits.h>
#include <stdint.h>
#include <stdio.h>
#include <stdlib.h>
@@ -361,6 +362,9 @@ static void mj_setPtrModel(mjModel* m) {
// *nbuffer += SKIP(*offset) + type_size*nr*nc;
// *offset += SKIP(*offset) + type_size*nr*nc;
static int safeAddToBufferSize(intptr_t* offset, int* nbuffer, size_t type_size, int nr, int nc) {
if (type_size < 0 || nr < 0 || nc < 0) {
return 0;
}
#if (__has_builtin(__builtin_add_overflow) && __has_builtin(__builtin_mul_overflow)) \
|| (defined(__GNUC__) && __GNUC__ >= 5)
// supported by GCC and Clang
@@ -469,6 +473,13 @@ mjModel* mj_makeModel(int nq, int nv, int nu, int na, int nbody, int njnt,
return 0;
}
// nmocap is going to get multiplied by 4, and shouldn't overflow
if (m->nmocap >= INT_MAX / 4) {
mju_warning("Invalid model: nmocap too large");
mj_deleteModel(m);
return 0;
}
// compute buffer size
m->nbuffer = 0;
#define X(type, name, nr, nc) \