From 13eefac0acde84883ca85554bcd9812603ebc06a Mon Sep 17 00:00:00 2001 From: Nunuhara Cabbage Date: Wed, 4 Dec 2019 20:16:44 -0800 Subject: [PATCH] Fix multiple memory issues with the help of asan Fix buffer overflows and memory leaks. --- cg.c | 3 +++ page.c | 2 +- sact_graphics.c | 1 + savedata.c | 4 +++- sdl_video.c | 3 +++ system4.c | 8 ++++---- 6 files changed, 15 insertions(+), 6 deletions(-) diff --git a/cg.c b/cg.c index a2dbd97..988f657 100644 --- a/cg.c +++ b/cg.c @@ -55,8 +55,10 @@ bool cg_get_metrics(int no, struct cg_metrics *dst) break; default: WARNING("Unknown CG type (CG %d)", no); + ald_free_data(dfile); return false; } + ald_free_data(dfile); return true; } @@ -68,6 +70,7 @@ void _cg_free(struct cg *cg) if (cg->pixel_alloc) free(cg->s->pixels); SDL_FreeSurface(cg->s); + SDL_DestroyTexture(cg->t); } } diff --git a/page.c b/page.c index 8d4710d..92a6aea 100644 --- a/page.c +++ b/page.c @@ -56,7 +56,7 @@ struct page *_alloc_page(int nr_vars) void free_page(struct page *page) { int cache_no = page->nr_vars - 1; - if (cache_no >= NR_CACHES || page_cache[cache_no].cached >= CACHE_SIZE) { + if (cache_no < 0 || cache_no >= NR_CACHES || page_cache[cache_no].cached >= CACHE_SIZE) { free(page); return; } diff --git a/sact_graphics.c b/sact_graphics.c index f660b4d..4cae4e0 100644 --- a/sact_graphics.c +++ b/sact_graphics.c @@ -254,6 +254,7 @@ int sact_SP_SetCG(int sp_no, int cg_no) WARNING("Failed to create sprite"); return 0; } + cg_reinit(sp->cg); if (!cg_load(sp->cg, cg_no - 1)) return 0; sp->rect.w = sp->cg->s->w; diff --git a/savedata.c b/savedata.c index 67013ed..a51cdc4 100644 --- a/savedata.c +++ b/savedata.c @@ -267,6 +267,7 @@ static union vm_value json_to_vm_value(enum ain_data_type type, enum ain_data_ty } rank = get_json_array_rank(json, &dims); heap[slot].page = alloc_array(rank, dims, array_type(type), struct_type, false); + free(dims); load_page(heap[slot].page, json); return vm_int(slot); case AIN_REF_TYPE: @@ -295,7 +296,8 @@ static cJSON *read_save_file(const char *filename) len = ftell(f); fseek(f, 0, SEEK_SET); - buf = xmalloc(len); + buf = xmalloc(len+1); + buf[len] = '\0'; if (fread(buf, len, 1, f) != 1) { WARNING("Failed to read save file: %s", filename); free(buf); diff --git a/sdl_video.c b/sdl_video.c index dd0faf7..b9ed66f 100644 --- a/sdl_video.c +++ b/sdl_video.c @@ -39,6 +39,7 @@ int sdl_initialize(void) sdl.renderer = SDL_CreateRenderer(sdl.window, -1, 0); sdl_set_window_size(config.view_width, config.view_height); + atexit(sdl_remove); return 0; } @@ -48,7 +49,9 @@ void sdl_remove(void) return; SDL_DestroyRenderer(sdl.renderer); + SDL_FreeFormat(sdl.format); SDL_Quit(); + sdl.window = NULL; } void sdl_fullscreen(bool on) diff --git a/system4.c b/system4.c index 21e6d0c..bb8b718 100644 --- a/system4.c +++ b/system4.c @@ -128,6 +128,7 @@ static void init_gamedata_dir(const char *path) if (ald_count[ALDFILE_WAVE] > 0) ald_init(ALDFILE_WAVE, ald_filenames[ALDFILE_WAVE], ald_count[ALDFILE_WAVE]); + closedir(dir); } static char *get_xsystem4_home(void) @@ -150,7 +151,7 @@ static char *get_xsystem4_home(void) // $HOME/.xsystem4 env_home = getenv("HOME"); if (env_home && *env_home) { - char *home = xmalloc(strlen(env_home) + strlen("/.xsystem4")); + char *home = xmalloc(strlen(env_home) + strlen("/.xsystem4") + 1); strcpy(home, env_home); strcat(home, "/.xsystem4"); return home; @@ -165,11 +166,10 @@ static char *get_save_path(const char *dir_name) if (!dir_name) dir_name = "SaveData"; - const char *home = get_xsystem4_home(); char *utf8_game_name = sjis2utf(config.game_name, strlen(config.game_name)); char *utf8_dir_name = sjis2utf(dir_name, strlen(dir_name)); - char *save_dir = xmalloc(strlen(home) + 1 + strlen(utf8_game_name) + 1 + strlen(utf8_dir_name) + 1); - strcpy(save_dir, home); + char *save_dir = xmalloc(strlen(config.home_dir) + 1 + strlen(utf8_game_name) + 1 + strlen(utf8_dir_name) + 1); + strcpy(save_dir, config.home_dir); strcat(save_dir, "/"); strcat(save_dir, utf8_game_name); strcat(save_dir, "/");