From e83fbd18d3fa33af8a57198cddefe5fcef1b2f58 Mon Sep 17 00:00:00 2001 From: Petteri Aimonen Date: Sun, 20 Oct 2013 21:42:00 +0300 Subject: [PATCH] Check array max size when encoding. Update issue 90 Status: FixedInGit --- pb_encode.c | 3 +++ tests/encode_unittests/encode_unittests.c | 14 ++++++++++++++ 2 files changed, 17 insertions(+) diff --git a/pb_encode.c b/pb_encode.c index d6ba7e34..4aced3cb 100644 --- a/pb_encode.c +++ b/pb_encode.c @@ -94,6 +94,9 @@ static bool checkreturn encode_array(pb_ostream_t *stream, const pb_field_t *fie if (count == 0) return true; + + if (count > field->array_size) + PB_RETURN_ERROR(stream, "array max size exceeded"); /* We always pack arrays if the datatype allows it. */ if (PB_LTYPE(field->type) <= PB_LTYPE_LAST_PACKABLE) diff --git a/tests/encode_unittests/encode_unittests.c b/tests/encode_unittests/encode_unittests.c index 32a37bf1..14bc62ee 100644 --- a/tests/encode_unittests/encode_unittests.c +++ b/tests/encode_unittests/encode_unittests.c @@ -223,6 +223,20 @@ int main() TEST(!pb_encode(&s, FloatArray_fields, &msg)) } + { + uint8_t buffer[50]; + pb_ostream_t s; + FloatArray msg = {1, {99.0f}}; + + COMMENT("Test array size limit in pb_encode") + + s = pb_ostream_from_buffer(buffer, sizeof(buffer)); + TEST((msg.data_count = 10) && pb_encode(&s, FloatArray_fields, &msg)) + + s = pb_ostream_from_buffer(buffer, sizeof(buffer)); + TEST((msg.data_count = 11) && !pb_encode(&s, FloatArray_fields, &msg)) + } + { uint8_t buffer[10]; pb_ostream_t s; -- 2.16.6