X-Git-Url: http://git.indexdata.com/?p=yaz-moved-to-github.git;a=blobdiff_plain;f=odr%2Fber_any.c;h=73f8dfb06cceba6a784c474804115327a2953bfc;hp=3c00d4750840dec5540a08bc890fba0c49afb3e6;hb=c71d717ada2a9ef730d527f161eb5ba9aa641a9f;hpb=044d170f0a963555486df54653cd2fdc5815928b diff --git a/odr/ber_any.c b/odr/ber_any.c index 3c00d47..73f8dfb 100644 --- a/odr/ber_any.c +++ b/odr/ber_any.c @@ -1,117 +1,140 @@ /* - * Copyright (c) 1995, Index Data + * Copyright (c) 1995-2003, Index Data * See the file LICENSE for details. - * Sebastian Hammer, Adam Dickmeiss - * - * $Log: ber_any.c,v $ - * Revision 1.14 1998-02-11 11:53:34 adam - * Changed code so that it compiles as C++. - * - * Revision 1.13 1997/05/14 06:53:56 adam - * C++ support. - * - * Revision 1.12 1995/09/29 17:12:15 quinn - * Smallish - * - * Revision 1.11 1995/09/27 15:02:54 quinn - * Modified function heads & prototypes. - * - * Revision 1.10 1995/05/16 08:50:42 quinn - * License, documentation, and memory fixes - * - * Revision 1.9 1995/04/18 08:15:12 quinn - * Added dynamic memory allocation on encoding (whew). Code is now somewhat - * neater. We'll make the same change for decoding one day. - * - * Revision 1.8 1995/04/17 09:37:42 quinn - * *** empty log message *** - * - * Revision 1.7 1995/03/17 10:17:39 quinn - * Added memory management. - * - * Revision 1.6 1995/03/08 12:12:02 quinn - * Added better error checking. - * - * Revision 1.5 1995/02/14 20:39:54 quinn - * Fixed bugs in completeBER and (serious one in) ber_oid. - * - * Revision 1.4 1995/02/14 11:54:33 quinn - * Adjustments. - * - * Revision 1.3 1995/02/10 18:57:24 quinn - * More in the way of error-checking. - * - * Revision 1.2 1995/02/10 15:55:28 quinn - * Bug fixes, mostly. - * - * Revision 1.1 1995/02/09 15:51:45 quinn - * Works better now. * + * $Id: ber_any.c,v 1.27 2003-10-21 09:30:32 adam Exp $ */ +#if HAVE_CONFIG_H +#include +#endif -#include +#include +#include "odr-priv.h" int ber_any(ODR o, Odr_any **p) { int res; - + switch (o->direction) { - case ODR_DECODE: - if ((res = completeBER(o->bp, o->left)) <= 0) /* FIX THIS */ - { - o->error = OPROTO; - return 0; - } - (*p)->buf = (unsigned char *)odr_malloc(o, res); - memcpy((*p)->buf, o->bp, res); - (*p)->len = (*p)->size = res; - o->bp += res; - o->left -= res; - return 1; - case ODR_ENCODE: - if (odr_write(o, (*p)->buf, (*p)->len) < 0) - return 0; - return 1; - default: o->error = OOTHER; return 0; + case ODR_DECODE: + if ((res = completeBER(o->bp, odr_max(o))) <= 0) /* FIX THIS */ + { + odr_seterror(o, OPROTO, 2); + return 0; + } + (*p)->buf = (unsigned char *)odr_malloc(o, res); + memcpy((*p)->buf, o->bp, res); + (*p)->len = (*p)->size = res; + o->bp += res; + return 1; + case ODR_ENCODE: + if (odr_write(o, (*p)->buf, (*p)->len) < 0) + return 0; + return 1; + default: odr_seterror(o, OOTHER, 3); return 0; } } +#define BER_ANY_DEBUG 0 + /* * Return length of BER-package or 0. */ -int completeBER(unsigned char *buf, int len) +int completeBER_n(const unsigned char *buf, int len, int level) { int res, ll, zclass, tag, cons; - unsigned char *b = buf; + const unsigned char *b = buf; + int bad = 0; - if (!len) + if (len > 5000000 || level > 1000) + { + bad = 1; +#if BER_ANY_DEBUG + yaz_log(LOG_LOG, "completeBER lev=%d len=%d", level, len); +#endif + if (level > 1000) + return -2; + } + if (len < 2) return 0; if (!buf[0] && !buf[1]) + return -2; + if ((res = ber_dectag(b, &zclass, &tag, &cons, len)) <= 0) return 0; - if ((res = ber_dectag(b, &zclass, &tag, &cons)) <= 0) - return 0; +#if 0 +/* removed, since ber_dectag never reads that far .. */ if (res > len) return 0; +#endif b += res; len -= res; - if ((res = ber_declen(b, &ll)) <= 0) - return 0; + assert (len >= 0); + res = ber_declen(b, &ll, len); + if (res == -2) + { +#if BER_ANY_DEBUG + if (bad) + yaz_log(LOG_LOG, "<<<<<<<<< return1 lev=%d res=%d", level, res); +#endif + return -1; /* error */ + } + if (res == -1) + { +#if BER_ANY_DEBUG + if (bad) + yaz_log(LOG_LOG, "<<<<<<<<< return3 lev=%d res=-1", level); +#endif + return 0; /* incomplete length */ + } + if (ll > 5000000) + { +#if BER_ANY_DEBUG + if (bad) + yaz_log(LOG_LOG, "<<<<<<<<< return2 lev=%d len=%d res=%d ll=%d", + level, len, res, ll); +#endif + return -1; /* error */ + } +#if 0 +/* no longer necessary, since ber_declen never reads that far (returns -1) */ if (res > len) + { + if (bad) + yaz_log(LOG_LOG, "<<<<<<<<< return4 lev=%d res=%d len=%d", + level, res, len); return 0; + } +#endif b += res; len -= res; if (ll >= 0) + { /* definite length */ +#if BER_ANY_DEBUG + if (bad && len < ll) + yaz_log(LOG_LOG, "<<<<<<<<< return5 lev=%d len=%d ll=%d", + level, len, ll); +#endif return (len >= ll ? ll + (b-buf) : 0); + } + /* indefinite length */ if (!cons) - return 0; + { /* if primitive, it's an error */ +#if BER_ANY_DEBUG + yaz_log(LOG_LOG, "<<<<<<<<< return6 lev=%d ll=%d len=%d res=%d", + level, ll, len, res); +#endif + return -1; /* error */ + } /* constructed - cycle through children */ while (len >= 2) { - if (*b == 0 && *(b + 1) == 0) + if (b[0] == 0 && b[1] == 0) break; - if (!(res = completeBER(b, len))) + if (!(res = completeBER_n(b, len, level+1))) return 0; + if (res == -1) + return -1; b += res; len -= res; } @@ -119,3 +142,11 @@ int completeBER(unsigned char *buf, int len) return 0; return (b - buf) + 2; } + +int completeBER(const unsigned char *buf, int len) +{ + int res = completeBER_n(buf, len, 0); + if (res < 0) + return len; + return res; +}