diff options
| author | Raymond Hettinger <python@rcn.com> | 2003-01-02 22:08:39 +0000 |
|---|---|---|
| committer | Raymond Hettinger <python@rcn.com> | 2003-01-02 22:08:39 +0000 |
| commit | 65b5e1fdbebe4ca35b665bc22bc51e9a806b4669 (patch) | |
| tree | 5e10dcf5790a39319504016579ab4afcdc6ccbf5 /Objects | |
| parent | 176f3a65997b67ac4745c150e1503b920f46e9d9 (diff) | |
| download | cpython-git-65b5e1fdbebe4ca35b665bc22bc51e9a806b4669.tar.gz | |
Backport MAL's patch for bug #659709: bogus computation of float length
Diffstat (limited to 'Objects')
| -rw-r--r-- | Objects/stringobject.c | 22 | ||||
| -rw-r--r-- | Objects/unicodeobject.c | 31 |
2 files changed, 37 insertions, 16 deletions
diff --git a/Objects/stringobject.c b/Objects/stringobject.c index bd416bf1c7..3173f750c0 100644 --- a/Objects/stringobject.c +++ b/Objects/stringobject.c @@ -3059,21 +3059,31 @@ formatfloat(char *buf, size_t buflen, int flags, prec = 6; if (type == 'f' && fabs(x)/1e25 >= 1e25) type = 'g'; - PyOS_snprintf(fmt, sizeof(fmt), "%%%s.%d%c", - (flags&F_ALT) ? "#" : "", - prec, type); - /* worst case length calc to ensure no buffer overrun: + /* Worst case length calc to ensure no buffer overrun: + + 'g' formats: fmt = %#.<prec>g buf = '-' + [0-9]*prec + '.' + 'e+' + (longest exp for any double rep.) len = 1 + prec + 1 + 2 + 5 = 9 + prec + + 'f' formats: + buf = '-' + [0-9]*x + '.' + [0-9]*prec (with x < 50) + len = 1 + 50 + 1 + prec = 52 + prec + If prec=0 the effective precision is 1 (the leading digit is - always given), therefore increase by one to 10+prec. */ - if (buflen <= (size_t)10 + (size_t)prec) { + always given), therefore increase the length by one. + + */ + if ((type == 'g' && buflen <= (size_t)10 + (size_t)prec) || + (type == 'f' && buflen <= (size_t)53 + (size_t)prec)) { PyErr_SetString(PyExc_OverflowError, "formatted float is too long (precision too large?)"); return -1; } + PyOS_snprintf(fmt, sizeof(fmt), "%%%s.%d%c", + (flags&F_ALT) ? "#" : "", + prec, type); PyOS_snprintf(buf, buflen, fmt, x); return strlen(buf); } diff --git a/Objects/unicodeobject.c b/Objects/unicodeobject.c index eb6f0d6c0c..18ab145905 100644 --- a/Objects/unicodeobject.c +++ b/Objects/unicodeobject.c @@ -5250,20 +5250,31 @@ formatfloat(Py_UNICODE *buf, prec = 6; if (type == 'f' && (fabs(x) / 1e25) >= 1e25) type = 'g'; - PyOS_snprintf(fmt, sizeof(fmt), "%%%s.%d%c", - (flags & F_ALT) ? "#" : "", prec, type); - /* worst case length calc to ensure no buffer overrun: - fmt = %#.<prec>g - buf = '-' + [0-9]*prec + '.' + 'e+' + (longest exp - for any double rep.) - len = 1 + prec + 1 + 2 + 5 = 9 + prec + /* Worst case length calc to ensure no buffer overrun: + + 'g' formats: + fmt = %#.<prec>g + buf = '-' + [0-9]*prec + '.' + 'e+' + (longest exp + for any double rep.) + len = 1 + prec + 1 + 2 + 5 = 9 + prec + + 'f' formats: + buf = '-' + [0-9]*x + '.' + [0-9]*prec (with x < 50) + len = 1 + 50 + 1 + prec = 52 + prec + If prec=0 the effective precision is 1 (the leading digit is - always given), therefore increase by one to 10+prec. */ - if (buflen <= (size_t)10 + (size_t)prec) { + always given), therefore increase the length by one. + + */ + if ((type == 'g' && buflen <= (size_t)10 + (size_t)prec) || + (type == 'f' && buflen <= (size_t)53 + (size_t)prec)) { PyErr_SetString(PyExc_OverflowError, - "formatted float is too long (precision too long?)"); + "formatted float is too long (precision too large?)"); return -1; } + PyOS_snprintf(fmt, sizeof(fmt), "%%%s.%d%c", + (flags&F_ALT) ? "#" : "", + prec, type); return usprintf(buf, fmt, x); } |
