Guard line buffer copy bounds

This commit is contained in:
Idate96
2026-04-27 14:43:21 +02:00
parent dc29e102cc
commit 5a74cb126f
2 changed files with 3 additions and 0 deletions

View File

@@ -292,6 +292,7 @@ copy_line_to(LineBuf *self, PyObject *args) {
unsigned int y; unsigned int y;
Line src, *dest; Line src, *dest;
if (!PyArg_ParseTuple(args, "IO!", &y, &Line_Type, &dest)) return NULL; if (!PyArg_ParseTuple(args, "IO!", &y, &Line_Type, &dest)) return NULL;
if (y >= self->ynum) { PyErr_SetString(PyExc_ValueError, "Out of bounds"); return NULL; }
src.xnum = self->xnum; dest->xnum = self->xnum; src.xnum = self->xnum; dest->xnum = self->xnum;
dest->ynum = y; dest->ynum = y;
dest->attrs = self->line_attrs[y]; dest->attrs = self->line_attrs[y];

View File

@@ -279,6 +279,8 @@ class TestDataTypes(BaseTest):
l2 = lb.create_line_copy(2) l2 = lb.create_line_copy(2)
lb.copy_line_to(1, l2) lb.copy_line_to(1, l2)
self.ae(l2, lb2.line(2)) self.ae(l2, lb2.line(2))
with self.assertRaises(ValueError):
lb.copy_line_to(lb.ynum, l2)
lb.clear_line(0) lb.clear_line(0)
self.ae(lb.line(0), LineBuf(1, lb.xnum).create_line_copy(0)) self.ae(lb.line(0), LineBuf(1, lb.xnum).create_line_copy(0))
lb = filled_line_buf(5, 5, filled_cursor()) lb = filled_line_buf(5, 5, filled_cursor())