mirror of
https://github.com/carbon-language/carbon-lang.git
synced 2026-10-05 11:21:05 +01:00
Fix an out-of-bounds read in TokenizedBuffer::IsRawIdentifier. (#7434)
`IsRawIdentifier` checked `token_text.starts_with("r#")` and then read
`token_text[2]`, but `starts_with` only guarantees a length of two. An
`r` identifier immediately followed by `#` at the end of the source --
so the token text is exactly `r#` -- made the `token_text[2]` read run
off the end. Guard on the length first.
Found by fuzzing. The read is reached only via `GetTokenText`, so the
parser fuzzer, which does not request token text, never hit it.
Assisted-by: Claude Code
This commit is contained in:
@@ -192,7 +192,7 @@ auto TokenizedBuffer::IsRawIdentifier(TokenIndex token) const -> bool {
|
||||
// starting with `#`. It suffices to check that character is the first
|
||||
// character of the identifier.
|
||||
auto token_text = source_->text().substr(token_info.byte_offset());
|
||||
return token_text.starts_with("r#") &&
|
||||
return token_text.size() > 2 && token_text.starts_with("r#") &&
|
||||
token_text[2] ==
|
||||
value_stores_->identifiers().Get(token_info.ident_id()).front();
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user