vim/backport-patch-8.2.1677-memory-access-errors-when-calling-set.patch
shixuantong 1fb6d9da0b fix CVE-2022-3016
(cherry picked from commit a44600c79d87d6cccaf9ff4d262f63960c57c764)
2022-08-31 10:27:46 +08:00

151 lines
4.6 KiB
Diff

From 4d170af0a9379da64d67dc3fa7cc7297956c6f52 Mon Sep 17 00:00:00 2001
From: Bram Moolenaar <Bram@vim.org>
Date: Sun, 13 Sep 2020 22:21:22 +0200
Subject: [PATCH] patch 8.2.1677: memory access errors when calling
setloclist() in autocommand
Problem: Memory access errors when calling setloclist() in an autocommand.
Solution: Give an error if the list was changed unexpectedly. (closes #6946)
---
src/quickfix.c | 41 ++++++++++++++++++++++++++++++-----
src/testdir/test_quickfix.vim | 24 ++++++++++++++++++++
2 files changed, 60 insertions(+), 5 deletions(-)
diff --git a/src/quickfix.c b/src/quickfix.c
index 206e901..a88475b 100644
--- a/src/quickfix.c
+++ b/src/quickfix.c
@@ -211,7 +211,9 @@ static char_u *e_no_more_items = (char_u *)N_("E553: No more items");
static char_u *qf_last_bufname = NULL;
static bufref_T qf_last_bufref = {NULL, 0, 0};
-static char *e_loc_list_changed =
+static char *e_current_quickfix_list_was_changed =
+ N_("E925: Current quickfix list was changed");
+static char *e_current_location_list_was_changed =
N_("E926: Current location list was changed");
/*
@@ -3109,6 +3111,7 @@ qf_jump_edit_buffer(
int *opened_window)
{
qf_list_T *qfl = qf_get_curlist(qi);
+ int old_changedtick = qfl->qf_changedtick;
qfltype_T qfl_type = qfl->qfl_type;
int retval = OK;
int old_qf_curlist = qi->qf_curlist;
@@ -3147,17 +3150,20 @@ qf_jump_edit_buffer(
if (qfl_type == QFLT_QUICKFIX && !qflist_valid(NULL, save_qfid))
{
- emsg(_("E925: Current quickfix was changed"));
+ emsg(_(e_current_quickfix_list_was_changed));
return NOTDONE;
}
+ // Check if the list was changed. The pointers may happen to be identical,
+ // thus also check qf_changedtick.
if (old_qf_curlist != qi->qf_curlist
+ || old_changedtick != qfl->qf_changedtick
|| !is_qf_entry_present(qfl, qf_ptr))
{
if (qfl_type == QFLT_QUICKFIX)
- emsg(_("E925: Current quickfix was changed"));
+ emsg(_(e_current_quickfix_list_was_changed));
else
- emsg(_(e_loc_list_changed));
+ emsg(_(e_current_location_list_was_changed));
return NOTDONE;
}
@@ -3265,10 +3271,25 @@ qf_jump_open_window(
int newwin,
int *opened_window)
{
+ qf_list_T *qfl = qf_get_curlist(qi);
+ int old_changedtick = qfl->qf_changedtick;
+ int old_qf_curlist = qi->qf_curlist;
+ qfltype_T qfl_type = qfl->qfl_type;
+
// For ":helpgrep" find a help window or open one.
if (qf_ptr->qf_type == 1 && (!bt_help(curwin->w_buffer) || cmdmod.tab != 0))
if (jump_to_help_window(qi, newwin, opened_window) == FAIL)
return FAIL;
+ if (old_qf_curlist != qi->qf_curlist
+ || old_changedtick != qfl->qf_changedtick
+ || !is_qf_entry_present(qfl, qf_ptr))
+ {
+ if (qfl_type == QFLT_QUICKFIX)
+ emsg(_(e_current_quickfix_list_was_changed));
+ else
+ emsg(_(e_current_location_list_was_changed));
+ return FAIL;
+ }
// If currently in the quickfix window, find another window to show the
// file in.
@@ -3283,6 +3304,16 @@ qf_jump_open_window(
opened_window) == FAIL)
return FAIL;
}
+ if (old_qf_curlist != qi->qf_curlist
+ || old_changedtick != qfl->qf_changedtick
+ || !is_qf_entry_present(qfl, qf_ptr))
+ {
+ if (qfl_type == QFLT_QUICKFIX)
+ emsg(_(e_current_quickfix_list_was_changed));
+ else
+ emsg(_(e_current_location_list_was_changed));
+ return FAIL;
+ }
return OK;
}
@@ -5697,7 +5728,7 @@ vgr_qflist_valid(
if (wp != NULL)
{
// An autocmd has freed the location list.
- emsg(_(e_loc_list_changed));
+ emsg(_(e_current_location_list_was_changed));
return FALSE;
}
else
diff --git a/src/testdir/test_quickfix.vim b/src/testdir/test_quickfix.vim
index 72f3172..c6c0f28 100644
--- a/src/testdir/test_quickfix.vim
+++ b/src/testdir/test_quickfix.vim
@@ -1401,6 +1401,30 @@ func Test_quickfix_was_changed_by_autocmd()
call XquickfixChangedByAutocmd('l')
endfunc
+func Test_setloclist_in_autocommand()
+ call writefile(['test1', 'test2'], 'Xfile')
+ edit Xfile
+ let s:bufnr = bufnr()
+ call setloclist(1,
+ \ [{'bufnr' : s:bufnr, 'lnum' : 1, 'text' : 'test1'},
+ \ {'bufnr' : s:bufnr, 'lnum' : 2, 'text' : 'test2'}])
+
+ augroup Test_LocList
+ au!
+ autocmd BufEnter * call setloclist(1,
+ \ [{'bufnr' : s:bufnr, 'lnum' : 1, 'text' : 'test1'},
+ \ {'bufnr' : s:bufnr, 'lnum' : 2, 'text' : 'test2'}], 'r')
+ augroup END
+
+ lopen
+ call assert_fails('exe "normal j\<CR>"', 'E926:')
+
+ augroup Test_LocList
+ au!
+ augroup END
+ call delete('Xfile')
+endfunc
+
func Test_caddbuffer_to_empty()
helpgr quickfix
call setqflist([], 'r')
--
2.27.0