[meego-commits] 6100: Changes to Trunk:Testing/python
Huaxu Wan
huaxu.wan at intel.com
Fri Jul 30 02:08:09 UTC 2010
Hi,
I have made the following changes to python in project Trunk:Testing. Please review and accept ASAP.
Thank You,
Huaxu Wan
[This message was auto-generated]
---
Request #6100:
submit: home:huaxu:branches:Trunk:Testing/python(r2)(cleanup) -> Trunk:Testing/python
Message:
Fix bug BMC#2616 in Trunk
State: new 2010-07-29T14:01:06 huaxu
Comment: None
changes files:
--------------
--- python.changes
+++ python.changes
@@ -0,0 +1,3 @@
+* Fri Jul 30 2010 Huaxu Wan <huaxu.wan at linux.intel.com> - 2.6.4
+- Fix bug BMC#2616 in Trunk
+
new:
----
python-2.6-audioop-int-overflows.patch
spec files:
-----------
--- python.spec
+++ python.spec
@@ -63,6 +63,10 @@
#Most functions of audioop takes as input a byte string (audio data) and a size argument (number of bytes of a sample). Functions don't check that the byte string length is a multiple of the size. It leads to read and write from/to uninitialised memory and might crash.
Patch56: audioop_check_length.patch
+# Fix audioop: incorrect integer overflow checks http://bugs.python.org/issue8674
+# Patch is generated from http://svn.python.org/view?rev=81045&view=rev and
+# http://svn.python.org/view?rev=81079&view=rev
+Patch57: python-2.6-audioop-int-overflows.patch
Obsoletes: Distutils
Provides: Distutils
@@ -120,7 +124,7 @@
provides the libraries needed for this.
%package devel
-Summary: The libraries and header files needed for Python development
+Summary: The libraries and header files needed for Python development.
Group: Development/Libraries
Requires: %{python} = %{version}-%{release}
Obsoletes: python2-devel
@@ -138,7 +142,7 @@
documentation.
%package tools
-Summary: A collection of development tools included with Python
+Summary: A collection of development tools included with Python.
Group: Development/Tools
Requires: %{name} = %{version}-%{release}
Obsoletes: python2-tools
@@ -185,7 +189,7 @@
%patch54 -p1 -b .setup-db48
%patch55 -p1
%patch56 -p1 -b .audioop
-
+%patch57 -p1 -b .audioop-int-overflows
# This shouldn't be necesarry, but is right now (2.2a3)
find -name "*~" |xargs rm -f
other changes:
--------------
++++++ python-2.6-audioop-int-overflows.patch (new)
--- python-2.6-audioop-int-overflows.patch
+++ python-2.6-audioop-int-overflows.patch
+diff --git a/Modules/audioop.c b/Modules/audioop.c
+index 767cae6..199069c 100644
+--- a/Modules/audioop.c
++++ b/Modules/audioop.c
+@@ -829,7 +829,7 @@ static PyObject *
+ audioop_tostereo(PyObject *self, PyObject *args)
+ {
+ signed char *cp, *ncp;
+- int len, new_len, size, val1, val2, val = 0;
++ int len, size, val1, val2, val = 0;
+ double fac1, fac2, fval, maxval;
+ PyObject *rv;
+ int i;
+@@ -846,14 +846,13 @@ audioop_tostereo(PyObject *self, PyObject *args)
+ return 0;
+ }
+
+- new_len = len*2;
+- if (new_len < 0) {
++ if (len > INT_MAX/2) {
+ PyErr_SetString(PyExc_MemoryError,
+ "not enough memory for output buffer");
+ return 0;
+ }
+
+- rv = PyString_FromStringAndSize(NULL, new_len);
++ rv = PyString_FromStringAndSize(NULL, len*2);
+ if ( rv == 0 )
+ return 0;
+ ncp = (signed char *)PyString_AsString(rv);
+@@ -1016,7 +1015,7 @@ audioop_lin2lin(PyObject *self, PyObject *args)
+ {
+ signed char *cp;
+ unsigned char *ncp;
+- int len, new_len, size, size2, val = 0;
++ int len, size, size2, val = 0;
+ PyObject *rv;
+ int i, j;
+
+@@ -1030,13 +1029,12 @@ audioop_lin2lin(PyObject *self, PyObject *args)
+ return 0;
+ }
+
+- new_len = (len/size)*size2;
+- if (new_len < 0) {
++ if (len/size > INT_MAX/size2) {
+ PyErr_SetString(PyExc_MemoryError,
+ "not enough memory for output buffer");
+ return 0;
+ }
+- rv = PyString_FromStringAndSize(NULL, new_len);
++ rv = PyString_FromStringAndSize(NULL, (len/size)*size2);
+ if ( rv == 0 )
+ return 0;
+ ncp = (unsigned char *)PyString_AsString(rv);
+@@ -1072,7 +1070,6 @@ audioop_ratecv(PyObject *self, PyObject *args)
+ int chan, d, *prev_i, *cur_i, cur_o;
+ PyObject *state, *samps, *str, *rv = NULL;
+ int bytes_per_frame;
+- size_t alloc_size;
+
+ weightA = 1;
+ weightB = 0;
+@@ -1115,14 +1112,13 @@ audioop_ratecv(PyObject *self, PyObject *args)
+ inrate /= d;
+ outrate /= d;
+
+- alloc_size = sizeof(int) * (unsigned)nchannels;
+- if (alloc_size < nchannels) {
++ if (nchannels > PY_SIZE_MAX/sizeof(int)) {
+ PyErr_SetString(PyExc_MemoryError,
+ "not enough memory for output buffer");
+ return 0;
+ }
+- prev_i = (int *) malloc(alloc_size);
+- cur_i = (int *) malloc(alloc_size);
++ prev_i = (int *) malloc(nchannels * sizeof(int));
++ cur_i = (int *) malloc(nchannels * sizeof(int));
+ if (prev_i == NULL || cur_i == NULL) {
+ (void) PyErr_NoMemory();
+ goto exit;
+@@ -1159,25 +1155,16 @@ audioop_ratecv(PyObject *self, PyObject *args)
+ ceiling(len*outrate/inrate) output frames, and each frame
+ requires bytes_per_frame bytes. Computing this
+ without spurious overflow is the challenge; we can
+- settle for a reasonable upper bound, though. */
+- int ceiling; /* the number of output frames */
+- int nbytes; /* the number of output bytes needed */
+- int q = len / inrate;
+- /* Now len = q * inrate + r exactly (with r = len % inrate),
+- and this is less than q * inrate + inrate = (q+1)*inrate.
+- So a reasonable upper bound on len*outrate/inrate is
+- ((q+1)*inrate)*outrate/inrate =
+- (q+1)*outrate.
+- */
+- ceiling = (q+1) * outrate;
+- nbytes = ceiling * bytes_per_frame;
+- /* See whether anything overflowed; if not, get the space. */
+- if (q+1 < 0 ||
+- ceiling / outrate != q+1 ||
+- nbytes / bytes_per_frame != ceiling)
++ settle for a reasonable upper bound, though, in this
++ case ceiling(len/inrate) * outrate. */
++
++ /* compute ceiling(len/inrate) without overflow */
++ int q = len > 0 ? 1 + (len - 1) / inrate : 0;
++ if (outrate > INT_MAX / q / bytes_per_frame)
+ str = NULL;
+ else
+- str = PyString_FromStringAndSize(NULL, nbytes);
++ str = PyString_FromStringAndSize(NULL,
++ q * outrate * bytes_per_frame);
+
+ if (str == NULL) {
+ PyErr_SetString(PyExc_MemoryError,
+@@ -1296,7 +1283,7 @@ audioop_ulaw2lin(PyObject *self, PyObject *args)
+ unsigned char *cp;
+ unsigned char cval;
+ signed char *ncp;
+- int len, new_len, size, val;
++ int len, size, val;
+ PyObject *rv;
+ int i;
+
+@@ -1309,18 +1296,17 @@ audioop_ulaw2lin(PyObject *self, PyObject *args)
+ return 0;
+ }
+
+- new_len = len*size;
+- if (new_len < 0) {
++ if (len > INT_MAX/size) {
+ PyErr_SetString(PyExc_MemoryError,
+ "not enough memory for output buffer");
+ return 0;
+ }
+- rv = PyString_FromStringAndSize(NULL, new_len);
++ rv = PyString_FromStringAndSize(NULL, len*size);
+ if ( rv == 0 )
+ return 0;
+ ncp = (signed char *)PyString_AsString(rv);
+
+- for ( i=0; i < new_len; i += size ) {
++ for ( i=0; i < len*size; i += size ) {
+ cval = *cp++;
+ val = st_ulaw2linear16(cval);
+
+@@ -1370,7 +1356,7 @@ audioop_alaw2lin(PyObject *self, PyObject *args)
+ unsigned char *cp;
+ unsigned char cval;
+ signed char *ncp;
+- int len, new_len, size, val;
++ int len, size, val;
+ PyObject *rv;
+ int i;
+
+@@ -1383,18 +1369,17 @@ audioop_alaw2lin(PyObject *self, PyObject *args)
+ return 0;
+ }
+
+- new_len = len*size;
+- if (new_len < 0) {
++ if (len > INT_MAX/size) {
+ PyErr_SetString(PyExc_MemoryError,
+ "not enough memory for output buffer");
+ return 0;
+ }
+- rv = PyString_FromStringAndSize(NULL, new_len);
++ rv = PyString_FromStringAndSize(NULL, len*size);
+ if ( rv == 0 )
+ return 0;
+ ncp = (signed char *)PyString_AsString(rv);
+
+- for ( i=0; i < new_len; i += size ) {
++ for ( i=0; i < len*size; i += size ) {
+ cval = *cp++;
+ val = st_alaw2linear16(cval);
+
+@@ -1519,7 +1504,7 @@ audioop_adpcm2lin(PyObject *self, PyObject *args)
+ {
+ signed char *cp;
+ signed char *ncp;
+- int len, new_len, size, valpred, step, delta, index, sign, vpdiff;
++ int len, size, valpred, step, delta, index, sign, vpdiff;
+ PyObject *rv, *str, *state;
+ int i, inputbuffer = 0, bufferstep;
+
+@@ -1541,13 +1526,12 @@ audioop_adpcm2lin(PyObject *self, PyObject *args)
+ } else if ( !PyArg_ParseTuple(state, "ii", &valpred, &index) )
+ return 0;
+
+- new_len = len*size*2;
+- if (new_len < 0) {
++ if (len > (INT_MAX/size)/2) {
+ PyErr_SetString(PyExc_MemoryError,
+ "not enough memory for output buffer");
+ return 0;
+ }
+- str = PyString_FromStringAndSize(NULL, new_len);
(13 more lines skipped)
More information about the MeeGo-commits
mailing list