From b907e278751b740da7b9dc00c0cbdb93e7498919 Mon Sep 17 00:00:00 2001 From: Simon Tatham Date: Sun, 22 Jan 2023 09:30:57 +0000 Subject: Add validate_params bounds checks in a few more games. Ben tells me that his recent work in this area was entirely driven by fuzzing: he added bounds checks in validate_params when the fuzzer had managed to prove that the lack of them allowed something buggy to happen. It seemed worth doing an eyeball-review pass to complement that strategy, so in this commit I've gone through and added a few more checks that restrict the area of the grid to be less than INT_MAX. Notable in this commit: cube.c had to do something complicated because in the triangular-grid modes the area isn't calculated as easily as w*h, and Range's existing check that w+h-1 < SCHAR_MAX is sufficient to rule out w*h being overlarge _but_ should be done before w*h is ever computed. --- cube.c | 24 ++++++++++++++++++++++++ 1 file changed, 24 insertions(+) (limited to 'cube.c') diff --git a/cube.c b/cube.c index 32b7343..21df46d 100644 --- a/cube.c +++ b/cube.c @@ -542,12 +542,36 @@ static const char *validate_params(const game_params *params, bool full) if (params->solid < 0 || params->solid >= lenof(solids)) return "Unrecognised solid type"; + if (params->d1 < 0 || params->d2 < 0) + return "Grid dimensions may not be negative"; + if (solids[params->solid]->order == 4) { if (params->d1 <= 1 || params->d2 <= 1) return "Both grid dimensions must be greater than one"; + if (params->d2 > INT_MAX / params->d1) + return "Grid area must not be unreasonably large"; } else { if (params->d1 <= 0 && params->d2 <= 0) return "At least one grid dimension must be greater than zero"; + + /* + * Check whether d1^2 + d2^2 + 4 d1 d2 > INT_MAX, without overflow: + * + * First check d1^2 doesn't overflow by itself. + * + * Then check d2^2 doesn't exceed the remaining space between + * d1^2 and INT_MAX. + * + * If that's all OK then we know both d1 and d2 are + * individually less than the square root of INT_MAX, so we + * can safely multiply them and compare against the + * _remaining_ space. + */ + if ((params->d1 > INT_MAX / params->d1) || + (params->d2 > (INT_MAX - params->d1*params->d1) / params->d2) || + (params->d1*params->d2 > (INT_MAX - params->d1*params->d1 - + params->d2*params->d2) / params->d2)) + return "Grid area must not be unreasonably large"; } for (i = 0; i < 4; i++) -- cgit v1.1