Fix out-of-bounds memory access in text rendering

This fixes SEGV in Hashiri Onna II when custom font is used. (#32)
This commit is contained in:
kichikuou
2024-12-11 16:30:42 +09:00
parent 07a049e05e
commit eab5eb075d
2 changed files with 11 additions and 5 deletions
+8 -3
View File
@@ -520,10 +520,15 @@ void AGS::flush_screen(bool update)
void AGS::draw_screen(int sx, int sy, int width, int height)
{
for(int y = sy; y < (sy + height) && y < 480; y++) {
SDL_Rect rect = {sx, sy, width, height};
SDL_Rect screen = {0, 0, screen_width, screen_height};
SDL_Rect clip;
SDL_IntersectRect(&rect, &screen, &clip);
for (int y = clip.y; y < clip.y + clip.h; y++) {
uint32* src = vram[0][y];
uint32* dest = surface_line(hBmpDest, y);
for(int x = sx; x < (sx + width) && x < 640; x++) {
for(int x = clip.x; x < clip.x + clip.w; x++) {
uint32 a=src[x];
if (game_id.sys_ver == 3 && src[x] & 0x80000000) {
// あゆみちゃん物語 フルカラー実写版
@@ -533,7 +538,7 @@ void AGS::draw_screen(int sx, int sy, int width, int height)
}
}
}
invalidate_screen(sx, sy, width, height);
invalidate_screen(clip.x, clip.y, clip.w, clip.h);
}
void AGS::invalidate_screen(int sx, int sy, int width, int height)
+3 -2
View File
@@ -4,6 +4,7 @@
[ AGS - text ]
*/
#include <algorithm>
#include <string.h>
#include "ags.h"
#include "nact.h"
@@ -440,7 +441,7 @@ void AGS::draw_char(int dest, int dest_x, int dest_y, uint16 code, TTF_Font* fon
SDL_Surface* fs = TTF_RenderGlyph_Solid(font, code, white);
// パターン出力
for(int y = 0; y < fs->h && dest_y + y < 480; y++) {
for (int y = std::max(0, -dest_y); y < fs->h && dest_y + y < 480; y++) {
uint8 *pattern = (uint8*)surface_line(fs, y); // FIXME: do not assume 8bpp
for(int x = 0; x < fs->w && dest_x + x < 640; x++) {
if(pattern[x] != 0) {
@@ -475,7 +476,7 @@ void AGS::draw_char_antialias(int dest, int dest_x, int dest_y, uint16 code, TTF
SDL_Surface* fs = TTF_RenderGlyph_Shaded(font, code, white, black);
// パターン出力
for(int y = 0; y < fs->h && dest_y + y < 480; y++) {
for (int y = std::max(0, -dest_y); y < fs->h && dest_y + y < 480; y++) {
uint8 *pattern = (uint8*)surface_line(fs, y);
uint32 *dp = &vram[dest][dest_y + y][dest_x];
for(int x = 0; x < fs->w && dest_x + x < 640; x++, dp++) {