Amiga: clamp amii_numcolors and guard tile CMAP loop
Reject tile/tomb IFF files whose nPlanes field exceeds DEPTH: the CMAP loop writes 1<<np entries into amii_initmap[] / amiv_init_map[], both sized AMII_MAXCOLORS = 1<<DEPTH = 64, so a malformed file with nPlanes >= 7 would corrupt adjacent BSS. After OpenScreen succeeds, clamp amii_numcolors to the actually populated portion of the init-map arrays (AMII_PALETTE_SIZE for text mode, AMIV_PALETTE_SIZE for tile mode). On a 64-color screen this stops LoadRGB4 from loading the zero-initialized tail entries as black. Replace the matching magic 32 in the tilefile selection with AMIV_PALETTE_SIZE. While there, add the (char) cast on amii_glyph_buffer's truncating assignment to make the contract explicit.
This commit is contained in:
+7
-1
@@ -130,6 +130,12 @@ ReadImageFile(const char *filename, struct BitMap **bmp)
|
||||
bmhd = (BitMapHeader *) prop->sp_Data;
|
||||
np = bmhd->nPlanes;
|
||||
|
||||
if (np > DEPTH) {
|
||||
errfmt = "%s: too many bitplanes (code %ld)";
|
||||
errcode = np;
|
||||
goto cleanup;
|
||||
}
|
||||
|
||||
/* Load CMAP into palette arrays if present */
|
||||
prop = FindProp(iff, ID_BMAP, ID_CMAP);
|
||||
if (prop) {
|
||||
@@ -819,7 +825,7 @@ amii_lprint_glyph(winid window, int color_index, int glyph)
|
||||
/*
|
||||
* Add it to the end of the buffer
|
||||
*/
|
||||
amii_glyph_buffer[glyph_buffer_index++] = glyph;
|
||||
amii_glyph_buffer[glyph_buffer_index++] = (char) glyph;
|
||||
amii_g_nodes[glyph_node_index - 1].len++;
|
||||
} else {
|
||||
/* See if we're out of glyph nodes */
|
||||
|
||||
Reference in New Issue
Block a user