<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.1//EN"
"http://www.w3.org/TR/xhtml11/DTD/xhtml11.dtd">
<html xmlns="http://www.w3.org/1999/xhtml">
<head><meta http-equiv="content-type" content="text/html; charset=utf-8" />
<title>[114266] trunk/dports/print/freetype</title>
</head>
<body>

<style type="text/css"><!--
#msg dl.meta { border: 1px #006 solid; background: #369; padding: 6px; color: #fff; }
#msg dl.meta dt { float: left; width: 6em; font-weight: bold; }
#msg dt:after { content:':';}
#msg dl, #msg dt, #msg ul, #msg li, #header, #footer, #logmsg { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt;  }
#msg dl a { font-weight: bold}
#msg dl a:link    { color:#fc3; }
#msg dl a:active  { color:#ff0; }
#msg dl a:visited { color:#cc6; }
h3 { font-family: verdana,arial,helvetica,sans-serif; font-size: 10pt; font-weight: bold; }
#msg pre { overflow: auto; background: #ffc; border: 1px #fa0 solid; padding: 6px; }
#logmsg { background: #ffc; border: 1px #fa0 solid; padding: 1em 1em 0 1em; }
#logmsg p, #logmsg pre, #logmsg blockquote { margin: 0 0 1em 0; }
#logmsg p, #logmsg li, #logmsg dt, #logmsg dd { line-height: 14pt; }
#logmsg h1, #logmsg h2, #logmsg h3, #logmsg h4, #logmsg h5, #logmsg h6 { margin: .5em 0; }
#logmsg h1:first-child, #logmsg h2:first-child, #logmsg h3:first-child, #logmsg h4:first-child, #logmsg h5:first-child, #logmsg h6:first-child { margin-top: 0; }
#logmsg ul, #logmsg ol { padding: 0; list-style-position: inside; margin: 0 0 0 1em; }
#logmsg ul { text-indent: -1em; padding-left: 1em; }#logmsg ol { text-indent: -1.5em; padding-left: 1.5em; }
#logmsg > ul, #logmsg > ol { margin: 0 0 1em 0; }
#logmsg pre { background: #eee; padding: 1em; }
#logmsg blockquote { border: 1px solid #fa0; border-left-width: 10px; padding: 1em 1em 0 1em; background: white;}
#logmsg dl { margin: 0; }
#logmsg dt { font-weight: bold; }
#logmsg dd { margin: 0; padding: 0 0 0.5em 0; }
#logmsg dd:before { content:'\00bb';}
#logmsg table { border-spacing: 0px; border-collapse: collapse; border-top: 4px solid #fa0; border-bottom: 1px solid #fa0; background: #fff; }
#logmsg table th { text-align: left; font-weight: normal; padding: 0.2em 0.5em; border-top: 1px dotted #fa0; }
#logmsg table td { text-align: right; border-top: 1px dotted #fa0; padding: 0.2em 0.5em; }
#logmsg table thead th { text-align: center; border-bottom: 1px solid #fa0; }
#logmsg table th.Corner { text-align: left; }
#logmsg hr { border: none 0; border-top: 2px dashed #fa0; height: 1px; }
#header, #footer { color: #fff; background: #636; border: 1px #300 solid; padding: 6px; }
#patch { width: 100%; }
#patch h4 {font-family: verdana,arial,helvetica,sans-serif;font-size:10pt;padding:8px;background:#369;color:#fff;margin:0;}
#patch .propset h4, #patch .binary h4 {margin:0;}
#patch pre {padding:0;line-height:1.2em;margin:0;}
#patch .diff {width:100%;background:#eee;padding: 0 0 10px 0;overflow:auto;}
#patch .propset .diff, #patch .binary .diff  {padding:10px 0;}
#patch span {display:block;padding:0 10px;}
#patch .modfile, #patch .addfile, #patch .delfile, #patch .propset, #patch .binary, #patch .copfile {border:1px solid #ccc;margin:10px 0;}
#patch ins {background:#dfd;text-decoration:none;display:block;padding:0 10px;}
#patch del {background:#fdd;text-decoration:none;display:block;padding:0 10px;}
#patch .lines, .info {color:#888;background:#fff;}
--></style>
<div id="msg">
<dl class="meta">
<dt>Revision</dt> <dd><a href="https://trac.macports.org/changeset/114266">114266</a></dd>
<dt>Author</dt> <dd>ryandesign@macports.org</dd>
<dt>Date</dt> <dd>2013-12-03 22:04:38 -0800 (Tue, 03 Dec 2013)</dd>
</dl>

<h3>Log Message</h3>
<pre>freetype: fix crash in TT_Load_Simple_Glyph (#41645)</pre>

<h3>Modified Paths</h3>
<ul>
<li><a href="#trunkdportsprintfreetypePortfile">trunk/dports/print/freetype/Portfile</a></li>
</ul>

<h3>Added Paths</h3>
<ul>
<li><a href="#trunkdportsprintfreetypefilespatchTT_Load_Simple_Glyphdiff">trunk/dports/print/freetype/files/patch-TT_Load_Simple_Glyph.diff</a></li>
</ul>

</div>
<div id="patch">
<h3>Diff</h3>
<a id="trunkdportsprintfreetypePortfile"></a>
<div class="modfile"><h4>Modified: trunk/dports/print/freetype/Portfile (114265 => 114266)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/dports/print/freetype/Portfile        2013-12-04 05:21:49 UTC (rev 114265)
+++ trunk/dports/print/freetype/Portfile        2013-12-04 06:04:38 UTC (rev 114266)
</span><span class="lines">@@ -6,6 +6,7 @@
</span><span class="cx"> 
</span><span class="cx"> name                    freetype
</span><span class="cx"> version                 2.5.1
</span><ins>+revision                1
</ins><span class="cx"> categories              print graphics
</span><span class="cx"> maintainers             ryandesign
</span><span class="cx"> license                 {FreeType GPL-2}
</span><span class="lines">@@ -43,6 +44,7 @@
</span><span class="cx"> 
</span><span class="cx"> patchfiles \
</span><span class="cx">     patch-src_base_ftrfork.c.diff \
</span><ins>+    patch-TT_Load_Simple_Glyph.diff \
</ins><span class="cx">     patch-modules.cfg.diff
</span><span class="cx"> 
</span><span class="cx"> depends_lib             port:bzip2 \
</span></span></pre></div>
<a id="trunkdportsprintfreetypefilespatchTT_Load_Simple_Glyphdiff"></a>
<div class="addfile"><h4>Added: trunk/dports/print/freetype/files/patch-TT_Load_Simple_Glyph.diff (0 => 114266)</h4>
<pre class="diff"><span>
<span class="info">--- trunk/dports/print/freetype/files/patch-TT_Load_Simple_Glyph.diff                                (rev 0)
+++ trunk/dports/print/freetype/files/patch-TT_Load_Simple_Glyph.diff        2013-12-04 06:04:38 UTC (rev 114266)
</span><span class="lines">@@ -0,0 +1,86 @@
</span><ins>+Fix crash in TT_Load_Simple_Glyph
+https://savannah.nongnu.org/bugs/?40797
+http://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=64872a50165d842d72c520f5f7e19124dbf7822d
+--- ChangeLog.orig        2013-11-24 17:27:44.000000000 -0600
++++ ChangeLog        2013-12-03 23:58:38.000000000 -0600
+@@ -1,3 +1,16 @@
++2013-12-02  Werner Lemberg  &lt;wl@gnu.org&gt;
++
++        [truetype] Fix change from 2013-11-20.
++
++        Problem reported by Akira Kakuto &lt;kakuto@fuk.kindai.ac.jp&gt;.
++
++        * src/truetype/ttgload.c (TT_Load_Simple_Glyph): Protect call to
++        `Update_Max' with both a TT_USE_BYTECODE_INTERPRETER guard and a
++        `IS_HINTED' clause.
++        Also remove redundant check using `maxSizeOfInstructions' – in
++        simple glyphs, the bytecode data comes before the outline data, and
++        a validity test for this is already present.
++
+ 2013-11-25  Werner Lemberg  &lt;wl@gnu.org&gt;

+         * Version 2.5.1 released.
+--- src/truetype/ttgload.c.orig        2013-11-20 14:03:17.000000000 -0600
++++ src/truetype/ttgload.c        2013-12-03 23:54:56.000000000 -0600
+@@ -348,8 +348,7 @@
+     FT_GlyphLoader  gloader    = load-&gt;gloader;
+     FT_Int          n_contours = load-&gt;n_contours;
+     FT_Outline*     outline;
+-    TT_Face         face       = (TT_Face)load-&gt;face;
+-    FT_UShort       n_ins, max_ins;
++    FT_UShort       n_ins;
+     FT_Int          n_points;
+     FT_ULong        tmp;

+@@ -418,30 +417,6 @@
+     FT_TRACE5(( &quot;  Instructions size: %u\n&quot;, n_ins ));

+     /* check it */
+-    max_ins = face-&gt;max_profile.maxSizeOfInstructions;
+-    if ( n_ins &gt; max_ins )
+-    {
+-      /* don't trust `maxSizeOfInstructions'; */
+-      /* only do a rough safety check         */
+-      if ( (FT_Int)n_ins &gt; load-&gt;byte_len )
+-      {
+-        FT_TRACE1(( &quot;TT_Load_Simple_Glyph:&quot;
+-                    &quot; too many instructions (%d) for glyph with length %d\n&quot;,
+-                    n_ins, load-&gt;byte_len ));
+-        return FT_THROW( Too_Many_Hints );
+-      }
+-
+-      tmp = load-&gt;exec-&gt;glyphSize;
+-      error = Update_Max( load-&gt;exec-&gt;memory,
+-                          &amp;tmp,
+-                          sizeof ( FT_Byte ),
+-                          (void*)&amp;load-&gt;exec-&gt;glyphIns,
+-                          n_ins );
+-      load-&gt;exec-&gt;glyphSize = (FT_UShort)tmp;
+-      if ( error )
+-        return error;
+-    }
+-
+     if ( ( limit - p ) &lt; n_ins )
+     {
+       FT_TRACE0(( &quot;TT_Load_Simple_Glyph: instruction count mismatch\n&quot; ));
+@@ -453,6 +428,20 @@

+     if ( IS_HINTED( load-&gt;load_flags ) )
+     {
++      /* we don't trust `maxSizeOfInstructions' in the `maxp' table */
++      /* and thus update the bytecode array size by ourselves       */
++
++      tmp   = load-&gt;exec-&gt;glyphSize;
++      error = Update_Max( load-&gt;exec-&gt;memory,
++                          &amp;tmp,
++                          sizeof ( FT_Byte ),
++                          (void*)&amp;load-&gt;exec-&gt;glyphIns,
++                          n_ins );
++
++      load-&gt;exec-&gt;glyphSize = (FT_UShort)tmp;
++      if ( error )
++        return error;
++
+       load-&gt;glyph-&gt;control_len  = n_ins;
+       load-&gt;glyph-&gt;control_data = load-&gt;exec-&gt;glyphIns;

</ins></span></pre>
</div>
</div>

</body>
</html>