X-Git-Url: http://git.indexdata.com/?a=blobdiff_plain;f=odr%2Fber_any.c;h=73f8dfb06cceba6a784c474804115327a2953bfc;hb=2e0cefa8b248dafdbc6518d12d0ba646d2f19565;hp=6094f9a7f524a7ca04dd9300e2d4d3942210c65c;hpb=3f7b54230a51be797c9439b091aa59133da16732;p=yaz-moved-to-github.git diff --git a/odr/ber_any.c b/odr/ber_any.c index 6094f9a..73f8dfb 100644 --- a/odr/ber_any.c +++ b/odr/ber_any.c @@ -2,12 +2,13 @@ * Copyright (c) 1995-2003, Index Data * See the file LICENSE for details. * - * $Id: ber_any.c,v 1.25 2003-05-20 17:22:54 adam Exp $ + * $Id: ber_any.c,v 1.27 2003-10-21 09:30:32 adam Exp $ */ #if HAVE_CONFIG_H #include #endif +#include #include "odr-priv.h" int ber_any(ODR o, Odr_any **p) @@ -35,41 +36,105 @@ int ber_any(ODR o, Odr_any **p) } } +#define BER_ANY_DEBUG 0 + /* * Return length of BER-package or 0. */ -int completeBER(const unsigned char *buf, int len) +int completeBER_n(const unsigned char *buf, int len, int level) { int res, ll, zclass, tag, cons; const unsigned char *b = buf; + int bad = 0; - if (!len) + if (len > 5000000 || level > 1000) + { + bad = 1; +#if BER_ANY_DEBUG + yaz_log(LOG_LOG, "completeBER lev=%d len=%d", level, len); +#endif + if (level > 1000) + return -2; + } + if (len < 2) return 0; if (!buf[0] && !buf[1]) - return 0; + return -2; if ((res = ber_dectag(b, &zclass, &tag, &cons, len)) <= 0) return 0; +#if 0 +/* removed, since ber_dectag never reads that far .. */ if (res > len) return 0; +#endif b += res; len -= res; - if ((res = ber_declen(b, &ll, len)) <= 0) - return 0; + assert (len >= 0); + res = ber_declen(b, &ll, len); + if (res == -2) + { +#if BER_ANY_DEBUG + if (bad) + yaz_log(LOG_LOG, "<<<<<<<<< return1 lev=%d res=%d", level, res); +#endif + return -1; /* error */ + } + if (res == -1) + { +#if BER_ANY_DEBUG + if (bad) + yaz_log(LOG_LOG, "<<<<<<<<< return3 lev=%d res=-1", level); +#endif + return 0; /* incomplete length */ + } + if (ll > 5000000) + { +#if BER_ANY_DEBUG + if (bad) + yaz_log(LOG_LOG, "<<<<<<<<< return2 lev=%d len=%d res=%d ll=%d", + level, len, res, ll); +#endif + return -1; /* error */ + } +#if 0 +/* no longer necessary, since ber_declen never reads that far (returns -1) */ if (res > len) + { + if (bad) + yaz_log(LOG_LOG, "<<<<<<<<< return4 lev=%d res=%d len=%d", + level, res, len); return 0; + } +#endif b += res; len -= res; if (ll >= 0) + { /* definite length */ +#if BER_ANY_DEBUG + if (bad && len < ll) + yaz_log(LOG_LOG, "<<<<<<<<< return5 lev=%d len=%d ll=%d", + level, len, ll); +#endif return (len >= ll ? ll + (b-buf) : 0); + } + /* indefinite length */ if (!cons) - return 0; + { /* if primitive, it's an error */ +#if BER_ANY_DEBUG + yaz_log(LOG_LOG, "<<<<<<<<< return6 lev=%d ll=%d len=%d res=%d", + level, ll, len, res); +#endif + return -1; /* error */ + } /* constructed - cycle through children */ while (len >= 2) { - if (*b == 0 && *(b + 1) == 0) + if (b[0] == 0 && b[1] == 0) break; - if (!(res = completeBER(b, len))) + if (!(res = completeBER_n(b, len, level+1))) return 0; + if (res == -1) + return -1; b += res; len -= res; } @@ -77,3 +142,11 @@ int completeBER(const unsigned char *buf, int len) return 0; return (b - buf) + 2; } + +int completeBER(const unsigned char *buf, int len) +{ + int res = completeBER_n(buf, len, 0); + if (res < 0) + return len; + return res; +}