// Copyright 2018 David Robillard // SPDX-License-Identifier: ISC #undef NDEBUG #include "serd/serd.h" #include #include static const size_t min_stack_size = 4U * sizeof(size_t) + 240U; static const size_t max_stack_size = 1024U; static SerdStatus test_size(SerdWorld* const world, const char* const str, const SerdSyntax syntax, const size_t stack_size) { SerdLimits limits = serd_world_limits(world); limits.reader_stack_size = stack_size; serd_world_set_limits(world, limits); SerdSink* sink = serd_sink_new(NULL, NULL, NULL); SerdReader* const reader = serd_reader_new(world, syntax, 0U, sink); if (!reader) { return SERD_BAD_STACK; } serd_reader_start_string(reader, str, NULL); const SerdStatus st = serd_reader_read_document(reader); serd_reader_free(reader); serd_sink_free(sink); return st; } static void test_all_sizes(SerdWorld* const world, const char* const str, const SerdSyntax syntax) { // Ensure reading with the maximum stack size succeeds SerdStatus st = test_size(world, str, syntax, max_stack_size); assert(!st); // Test with an increasingly smaller stack for (size_t size = max_stack_size; size > min_stack_size; --size) { if ((st = test_size(world, str, syntax, size))) { assert(st == SERD_BAD_STACK); } } assert(st == SERD_BAD_STACK); } static void test_ntriples_overflow(void) { static const char* const test_strings[] = { " .", NULL, }; SerdWorld* const world = serd_world_new(); for (const char* const* t = test_strings; *t; ++t) { test_all_sizes(world, *t, SERD_NTRIPLES); } serd_world_free(world); } static void test_turtle_overflow(void) { static const char* const test_strings[] = { " :%99 .", " .", " " " .", " eg:foo .", " 1234 .", " (1 2 3 4) .", " (((((((42))))))) .", " \"literal\" .", " _:blank .", " true .", " \"\"@en .", "(((((((((42))))))))) .", "@prefix eg: .", "@base .", "@prefix eg: . \neg:s eg:p eg:o .\n", "@prefix ug.dot: . \nug.dot:s ug.dot:p ug.dot:o .\n", // NOLINTNEXTLINE(bugprone-suspicious-missing-comma) "@prefix øøøøøøøøø: . \n" " øøøøøøøøø:p " "øøøøøøøøø:o .\n", // NOLINTNEXTLINE(bugprone-suspicious-missing-comma) " " " " " .", // NOLINTNEXTLINE(bugprone-suspicious-missing-comma) " " "\"typed\"^^ .", // NOLINTNEXTLINE(bugprone-suspicious-missing-comma) "@prefix eg: .\n" " " "\"typed\"^^eg:Datatype .", // NOLINTNEXTLINE(bugprone-suspicious-missing-comma) "@prefix eg: .\n" " eg:foo .", // NOLINTNEXTLINE(bugprone-suspicious-missing-comma) "@prefix prefix: .\n" "prefix:subject prefix:predicate prefix:object .\n", // NOLINTNEXTLINE(bugprone-suspicious-missing-comma) "@prefix prefix: .\n" "prefix:subjectthatwillcomearoundtobeingfinishedanycharacternow " "prefix:predicate prefix:object .\n", // NOLINTNEXTLINE(bugprone-suspicious-missing-comma) "@prefix eg: .\n" "eg:s eg:p [ eg:p [ eg:p [ eg:p [ eg:p eg:o ] ] ] ] .\n", // NOLINTNEXTLINE(bugprone-suspicious-missing-comma) "@prefix eg: .\n" "eg:s eg:p ( 1 2 3 ( 4 5 6 ( 7 8 9 ) ) ) .\n", // NOLINTNEXTLINE(bugprone-suspicious-missing-comma) "@prefix eg: .\n" " eg:%99 .", // NOLINTNEXTLINE(bugprone-suspicious-missing-comma) "@prefix øøøøøøøøø: .\n" " øøøøøøøøø:p " "øøøøøøøøø:o .\n", // NOLINTNEXTLINE(bugprone-suspicious-missing-comma) "@base .\n" " .", NULL, }; SerdWorld* const world = serd_world_new(); for (const char* const* t = test_strings; *t; ++t) { test_all_sizes(world, *t, SERD_TURTLE); } serd_world_free(world); } int main(void) { test_ntriples_overflow(); test_turtle_overflow(); return 0; }