[glibc] posix: Remove unnecessary overflow check in wordexp (BZ 34090)
Adhemerval Zanella via Glibc-cvs <[email protected]>
| Newsgroups | gmane.comp.lib.glibc.cvs |
|---|---|
| Message-ID | <[email protected]> |
https://sourceware.org/git/gitweb.cgi?p=glibc.git;h=53ec26f1736aee747b353aaea0667b1ebdd5cae7 commit 53ec26f1736aee747b353aaea0667b1ebdd5cae7 Author: Adhemerval Zanella <[email protected]> Date: Thu Aug 13 08:53:06 2026 -0300 posix: Remove unnecessary overflow check in wordexp (BZ 34090) The WRDE_APPEND path duplicates the caller's we_wordv array, which already holds we_offs + we_wordc + 1 pointers. Follow-up to commit e2cefe16c37. Checked on x86_64-linux-gnu and i686-linux-gnu. Diff: --- posix/wordexp.c | 15 ++++++--------- 1 file changed, 6 insertions(+), 9 deletions(-) diff --git a/posix/wordexp.c b/posix/wordexp.c index 8fdc8b8caf..9a49e102ee 100644 --- a/posix/wordexp.c +++ b/posix/wordexp.c @@ -35,7 +35,6 @@ #include <scratch_buffer.h> #include <_itoa.h> #include <assert.h> -#include <intprops.h> /* * This is a recursive-descent-style word expansion routine. @@ -2269,16 +2268,14 @@ wordexp (const char *words, wordexp_t *pwordexp, int flags) { /* WRDE_APPEND with an existing word list: duplicate the array so that realloc during parsing does not invalidate the caller's pointer. The - strings themselves are shared. */ - size_t num_p; - char **dup; - if (INT_ADD_WRAPV (pwordexp->we_offs, pwordexp->we_wordc, &num_p) - || INT_ADD_WRAPV (num_p, 1, &num_p)) - return WRDE_NOSPACE; - dup = __libc_reallocarray (NULL, num_p, sizeof *dup); + strings themselves are shared an the array already holds + 'we_offs + we_wordc + 1 pointers' (so the size computation cannot + overflow). */ + size_t num_p = pwordexp->we_offs + pwordexp->we_wordc + 1; + char **dup = malloc (num_p * sizeof (char *)); if (dup == NULL) return WRDE_NOSPACE; - memcpy (dup, pwordexp->we_wordv, num_p * sizeof *dup); + memcpy (dup, pwordexp->we_wordv, num_p * sizeof (char *)); saved_wordv = pwordexp->we_wordv; pwordexp->we_wordv = dup; }