Restrict parse value to strtoll with restrictions on input.

This commit is contained in:
rakshasa
2026-09-30 12:01:13 +02:00
committed by Jari Sundell
parent 44d51171e1
commit c5d54fbb97
16 changed files with 440 additions and 60 deletions
+30 -4
View File
@@ -1,5 +1,7 @@
#include "config.h"
#include <cctype>
#include <charconv>
#include <cstring>
#include <cstdio>
#include <limits>
@@ -113,13 +115,37 @@ parse_value_nothrow(const char* src, int64_t* value, int base, int unit) {
if (unit <= 0)
throw torrent::input_error("Command::string_to_value_unit(...) received unit <= 0.");
char* last;
if (base != 0 && base != 8 && base != 10 && base != 16)
throw torrent::input_error("Command::string_to_value_unit(...) received invalid base.");
while (parse_is_space(*src))
src++;
if (src[0] == '+')
return src;
if (src[0] == '-') {
if (base == 8 || base == 16)
return src;
if (src[1] == '0')
return src;
}
char* last{};
errno = 0;
*value = strtoll(src, &last, base);
if (errno == ERANGE)
return src;
if (last == src) {
if (strcasecmp(src, "no") == 0) { *value = 0; return src + strlen("no"); }
if (strcasecmp(src, "yes") == 0) { *value = 1; return src + strlen("yes"); }
if (strcasecmp(src, "true") == 0) { *value = 1; return src + strlen("true"); }
*value = 0;
if (strcasecmp(src, "no") == 0) { *value = 0; return src + strlen("no"); }
if (strcasecmp(src, "yes") == 0) { *value = 1; return src + strlen("yes"); }
if (strcasecmp(src, "true") == 0) { *value = 1; return src + strlen("true"); }
if (strcasecmp(src, "false") == 0) { *value = 0; return src + strlen("false"); }
return src;
-34
View File
@@ -1,37 +1,3 @@
// rTorrent - BitTorrent client
// Copyright (C) 2005-2011, Jari Sundell
//
// This program is free software; you can redistribute it and/or modify
// it under the terms of the GNU General Public License as published by
// the Free Software Foundation; either version 2 of the License, or
// (at your option) any later version.
//
// This program is distributed in the hope that it will be useful,
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
// GNU General Public License for more details.
//
// You should have received a copy of the GNU General Public License
// along with this program; if not, write to the Free Software
// Foundation, Inc., 59 Temple Place, Suite 330, Boston, MA 02111-1307 USA
//
// In addition, as a special exception, the copyright holders give
// permission to link the code of portions of this program with the
// OpenSSL library under certain conditions as described in each
// individual source file, and distribute linked combinations
// including the two.
//
// You must obey the GNU General Public License in all respects for
// all of the code used other than OpenSSL. If you modify file(s)
// with this exception, you may extend this exception to your version
// of the file(s), but you are not obligated to do so. If you do not
// wish to do so, delete this exception statement from your version.
// If you delete this exception statement from all source files in the
// program, then also delete it here.
//
// Contact: Jari Sundell <sundell.software@gmail.com>
#ifndef RTORRENT_RPC_PARSE_H
#define RTORRENT_RPC_PARSE_H