Commit Graph
13 Commits
Author SHA1 Message Date
Mika Kuoppala 9294239197 util: match fopen_datafile function prototype
The prototype for fopen_datafile() is different if
it is used for util/dlb. Add the missing integer parameter.
2024-10-28 21:40:50 +02:00
Mika Kuoppala 25061dbce4 Remove magic members from instance globals.
We ought to trust compiler and we have other
tools to check oob access.
2024-10-23 23:41:24 +03:00
Mika Kuoppala 238d501cce win/curses: Check input range in menu selection fallthrough
curletter is screened to be in valid range in all
other switch/case branches except in the default case,
which is fallthrough.

Add check for valid range in here also, otherwise
array might be addressed with invalid offset.

This should fix the following, found
with UBSAN and #debugfuzzer:

../win/curses/cursdial.c:1558:49: runtime error: index -154 out of bounds for type 'char [256]'
0x5f3857eff140 in menu_get_selections ../win/curses/cursdial.c:1558
0x5f3857ef78c8 in curses_display_nhmenu ../win/curses/cursdial.c:801
0x5f3857edd390 in curses_select_menu ../win/curses/cursmain.c:768
2024-06-22 23:31:22 -07:00
Mika Kuoppala 20f8af224b hints/linux.370: Add support for ubsan (undefined behaviour sanitizer) for gcc
This will add an option to compile and link nethack executable
with ubsan and catch undefined behaviour errors on runtime.
2024-06-09 09:34:57 -04:00
Mika Kuoppala 91781ef0a6 dothrow: Check for LOW_PM before accessing mon array
on toss_up() when checking for touch_petrifies, add
a check for corpsenm >= LOW_PM as EGG can be without
corpse reference.

This prevents:
dothrow.c:1266:29: runtime error: index -1 out of bounds for type 'permonst [384]'
2024-01-10 17:26:38 +02:00
Mika Kuoppala 0ca1a1ca8e src/trap: Fix isclearpath out of bound access on levl array
Do isok check apriori to accessing the levl array to filter
out dx/dy that have grown too large.

This fixes:
trap.c:3455:19: runtime error: index 80 out of bounds for type 'rm [80][21]'
2024-01-09 01:18:17 +02:00
Mika Kuoppala 4669676fc0 src/weapon: Avoid touch_petrifies with invalid corpsenm
Filter out unset (-1) corpsenm before calling touch_petrifies.
While here, cleanup the oselect by doing excluding loop
and use can_touch_safely for filtering (suggested by entrez).
2024-01-06 12:06:56 -08:00
Mika Kuoppala 83fba62152 src/uhitm: Avoid touch_petrifies with invalid corpsenm
Before checking with touch_petrifies, check that corpsenm
is valid (>= LOW_PM)
2024-01-06 12:06:55 -08:00
Mika Kuoppala c4d3ca00ce src/muse: Avoid touch_petrifies check if bad corpsenm
EGGs can have non permanent monster based corpsenm assigned
(-1). Before doing the touch_petrifies check, make sure
that we have valid corpsenm.
2024-01-06 12:06:55 -08:00
Mika Kuoppala 4f15e134fc src/mon: Avoid addressing with invalid corpsenm in mstoning
corpsenm can be -1 (for EGGs and TINs) so touch_petrifies
using this as index would point to bad entry.

Fix this by making mstoning as helper function and bailing
out early if corpsenm <= LOW_PM (while keeping MEDUSA as is)
2024-01-06 12:06:54 -08:00
Mika Kuoppala 6a085955ea src/eat: Check for valid corpsenm before checking is_rider
corpsenm can be -1 so limit checking is_rider with only
>= LOW_PM corpse numbers.
2024-01-06 12:06:54 -08:00
Mika Kuoppala 5cfa4cd9f6 src/dog: Fix TIN or EGG based corpsenm
TIN or EGG can have the corpsenm not assigned into a
proper monster and instead have an value of -1.

Take this into account in assigning the monster (fptr)
pointer to only point into >= LOW_PM monste entries.
2024-01-06 12:06:54 -08:00
Mika Kuoppala e6c4838161 sp_lvl: fix memory leak on lspo_region
If tutorial is entered, we get following leak on exit:

=================================================================
==81358==ERROR: LeakSanitizer: detected memory leaks

Direct leak of 96 byte(s) in 3 object(s) allocated from:
    #0 0x7f6996edefdf in __interceptor_malloc ../../../../src/libsanitizer/asan/asan_malloc_linux.cpp:69
        #1 0x5601c255bcbb in alloc /home/miku/src/NetHack/src/alloc.c:71

Indirect leak of 5064 byte(s) in 3 object(s) allocated from:
    #0 0x7f6996edefdf in __interceptor_malloc ../../../../src/libsanitizer/asan/asan_malloc_linux.cpp:69
        #1 0x5601c255be1e in alloc /home/miku/src/NetHack/src/alloc.c:71
	    #2 0x5601c255be1e in dupstr /home/miku/src/NetHack/src/alloc.c:236

SUMMARY: AddressSanitizer: 5160 byte(s) leaked in 6 allocation(s).

Fix this by freeing the cloned selection before returning.
2023-12-17 11:47:26 +02:00