提交 2b0f8ae0 编写于 作者: T Tom Lane

Fix pg_dump crashes caused by bogus use of va_start/va_end (only seen

on some platforms, which is not too surprising considering how platform
specific these macros must be).
上级 b25e60d8
......@@ -872,21 +872,21 @@ int archprintf(Archive* AH, const char *fmt, ...)
int bSize = strlen(fmt) + 256;
int cnt = -1;
va_start(ap, fmt);
/* This is paranoid: deal with the possibility that vsnprintf is willing to ignore trailing null */
/* or returns > 0 even if string does not fit. It may be the case that it returns cnt = bufsize */
while (cnt < 0 || cnt >= (bSize-1) ) {
if (p != NULL) free(p);
bSize *= 2;
if ((p = malloc(bSize)) == NULL)
while (cnt < 0 || cnt >= (bSize-1) )
{
va_end(ap);
exit_horribly(AH, "%s: could not allocate buffer for archprintf\n", progname);
}
cnt = vsnprintf(p, bSize, fmt, ap);
if (p != NULL) free(p);
bSize *= 2;
p = (char*)malloc(bSize);
if (p == NULL)
{
exit_horribly(AH, "%s: could not allocate buffer for archprintf\n", progname);
}
va_start(ap, fmt);
cnt = vsnprintf(p, bSize, fmt, ap);
va_end(ap);
}
va_end(ap);
WriteData(AH, p, cnt);
free(p);
return cnt;
......@@ -977,21 +977,21 @@ int ahprintf(ArchiveHandle* AH, const char *fmt, ...)
int bSize = strlen(fmt) + 256; /* Should be enough */
int cnt = -1;
va_start(ap, fmt);
/* This is paranoid: deal with the possibility that vsnprintf is willing to ignore trailing null */
/* or returns > 0 even if string does not fit. It may be the case that it returns cnt = bufsize */
while (cnt < 0 || cnt >= (bSize - 1) ) {
while (cnt < 0 || cnt >= (bSize - 1) )
{
if (p != NULL) free(p);
bSize *= 2;
p = (char*)malloc(bSize);
if (p == NULL)
{
va_end(ap);
die_horribly(AH, "%s: could not allocate buffer for ahprintf\n", progname);
}
va_start(ap, fmt);
cnt = vsnprintf(p, bSize, fmt, ap);
va_end(ap);
}
va_end(ap);
ahwrite(p, 1, cnt, AH);
free(p);
return cnt;
......
......@@ -899,24 +899,22 @@ static int tarPrintf(ArchiveHandle *AH, TAR_MEMBER *th, const char *fmt, ...)
int bSize = strlen(fmt) + 256; /* Should be enough */
int cnt = -1;
va_start(ap, fmt);
/* This is paranoid: deal with the possibility that vsnprintf is willing to ignore trailing null */
/* or returns > 0 even if string does not fit. It may be the case that it returns cnt = bufsize */
while (cnt < 0 || cnt >= (bSize - 1) ) {
while (cnt < 0 || cnt >= (bSize - 1) )
{
if (p != NULL) free(p);
bSize *= 2;
p = (char*)malloc(bSize);
if (p == NULL)
{
va_end(ap);
die_horribly(AH, "%s: could not allocate buffer for ahprintf\n", progname);
die_horribly(AH, "%s: could not allocate buffer for tarPrintf\n", progname);
}
va_start(ap, fmt);
cnt = vsnprintf(p, bSize, fmt, ap);
va_end(ap);
}
va_end(ap);
cnt = tarWrite(p, cnt, th);
free(p);
return cnt;
}
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册