1
0
mirror of https://github.com/rkd77/elinks.git synced 2024-06-26 01:15:37 +00:00
elinks/src
Kalle Olavi Niemitalo d33c807dd9 http_negotiate: Fix int* vs. size_t* type mismatch
http_negotiate_parse_data passed &token->length as the int *outlen
parameter of base64_decode_bin, which stores an int at that location.
However, gss_buffer_desc::length is size_t in all implementations that
I checked: MIT Kerberos Version 5 Release 1.10, libgssglue 0.4, and
GNU GSS 1.0.2.  This mismatch could cause the build to fail:

.../src/protocol/http/http_negotiate.c: In function ‘http_negotiate_parse_data’:
.../src/protocol/http/http_negotiate.c:173:2: error: passing argument 3 of ‘base64_decode_bin’ from incompatible pointer type [-Werror]
In file included from .../src/protocol/http/http_negotiate.c:30:0:
.../src/util/base64.h:8:16: note: expected ‘int *’ but argument is of type ‘size_t *’

On 64-bit big-endian hosts, it might also cause the GSSAPI
implementation to read too much data from memory and disclose it to
some network server, or crash ELinks.
2012-10-28 14:50:58 +02:00
..
bfu bug 764: Initialize the right member of union option_value 2009-08-18 05:02:16 +03:00
bookmarks bug 764: Initialize the right member of union option_value 2009-08-18 05:02:16 +03:00
cache Patch 3: Further fixes including strcasestr and convert_to_lowercase 2008-11-01 22:32:43 +02:00
config bug 764: Convert sentinel to struct option 2009-08-22 00:23:16 +03:00
cookies bug 764: Initialize the right member of union option_value 2009-08-18 05:02:16 +03:00
dialogs menu_keys(): Do not compare different enums 2012-10-26 18:34:52 +03:00
document Remove variables that were set but not used 2012-10-26 19:15:49 +03:00
dom Remove variables that were set but not used 2012-10-26 19:15:49 +03:00
ecmascript Deleted ecmascript code using SEE. 2011-05-15 14:26:33 +03:00
encoding bug 1083: Distinguish EOF from errors in read_encoded 2009-08-19 01:31:40 +03:00
formhist bug 764: Initialize the right member of union option_value 2009-08-18 05:02:16 +03:00
globhist bug 764: Initialize the right member of union option_value 2009-08-18 05:02:16 +03:00
intl I18N bug 1112: Use strange_chars[] for UTF-8 output too 2011-05-01 22:14:55 +03:00
main bug 764: Initialize the right member of union option_value 2009-08-18 05:02:16 +03:00
mime mailcap bug 1113: Don't leak values of duplicate fields 2011-05-01 22:14:55 +03:00
network bug 764: Initialize the right member of union option_value 2009-08-18 05:02:16 +03:00
osdep Compile xprop_to_string only #ifdef HAVE_X11 2011-05-15 14:04:03 +03:00
protocol http_negotiate: Fix int* vs. size_t* type mismatch 2012-10-28 14:50:58 +02:00
scripting bug 764, LUA: option_types[OPT_INT].set needs long * 2009-08-20 22:50:37 +03:00
session download: Add DOWNLOAD_EXTERNAL flag 2009-07-24 18:09:59 +03:00
terminal Recode X11 window title when saving and restoring 2011-05-15 14:02:55 +03:00
util Define die() with __attribute__((noreturn)) 2009-05-27 01:11:03 +03:00
viewer Remove variables that were set but not used 2012-10-26 19:15:49 +03:00
.gitignore Ignore tags file 2007-08-08 14:25:38 +02:00
elinks.h TRE: Check for 32-bit wchar_t at configure time 2009-05-21 17:22:12 +03:00
Makefile BUILD_ID: Fix dirt check when srcdir != builddir. 2008-03-01 14:30:57 +02:00
README Remove now useless $Id: lines. 2005-10-21 09:14:07 +02:00
setup.h Make copyright info independent from translations. 2007-10-03 11:53:09 +02:00
vernum.c Remove now useless $Id: lines. 2005-10-21 09:14:07 +02:00
vernum.h Remove now useless $Id: lines. 2005-10-21 09:14:07 +02:00

				  The Big View

The whole dependency tree is supposed (in ideal world) to look somewhat like
the following. Please note that this deals only with the core parts of ELinks,
not extensions like bookmarks, cookies, globhist, mime etc. Those act like
modules and are generally self-contained - the main visible difference is that
they don't have their UI stuff in dialogs/foo.c but in foo/dialogs.c.

Note also that it isn't all that clean-cut as it looks. Some parts of e.g.
lowlevel/ or osdep/ are omnipresent as well and it's meant to be so (at least
for now). Also some other exceptions are possible; the exception to this is
util/, where no exceptions are permitted - it must have no dependencies to the
rest of the code whatsoever, not even compile-time ones. The other way around,
the gettext part of intl/ is generally omnipresent but the charset part is
pretty isolated - it could be probably drawn as connected to document and
terminal (actually, it is used when encoding forms in viewer too, but that
stuff should be probably moved to document).

viewer/ contains code concerning that big rectangle between bars at the top
and bars at the bottom, documents usually being shown inside. Logically, it
is in fact kind of a BFU widget, but in practice it has little in common with
the bfu/ widgets, it is special in many ways and deeply woven to the fabric
of session/ (e.g. session history is basically a chain of viewer widget
descriptors).

dialogs/ is special too. It in fact means to say "global and unique BFU
instances belonging to the ELinks core"/ but that's a rather long and boring
name, besides the nightmares associated with maintaining files and directories
containing spaces in GIT. The "global and unique BFU instances" part can be
represented by exmode, menus and leds (were they there). The "ELinks core"
part can be represented by options, document and downloads. The reason those
aren't in their respective directories (while bookmarks or formhist have their
dialogs.c) is that it's important to keep the dependencies sorted out
reasonably. Had there been e.g. terminal/dialogs.c, it would mean libterminal
has to depend on libbfu.a and so. (There are two 'managerial' exceptions
to this; don't dig into them, please. ;-)

scripting/ (== browser scripting) is also expected to hook all around, perhaps
it should be better in the omnipresent box.

The edges are directed and represent the "using" relation. Therefore,
"bfu -> terminal" means "bfu/ is using terminal/ services (but not
the other way around)".

.---------.
| util/   | <-- This is omnipresent :)
| config/ |
| intl/   |
`---------'

                   .-------.         .---------.
                   |  bfu  |<------- | dialogs |
                   `-------' \       `---------'
                       v      `---.       |
                 .----------.      \ .--------.
                 | terminal | <----- | viewer | <-----------------.
               / `----------'     .> `--------'                   |
           .--'        v         /        v                       v
.-------. /      .----------.   |    .----------.       .----/ecmascript/----.
| osdep |<------ | lowlevel |   |    | document | ----> | document scripting |
`-------' \      `----------'   |    `----------'       `--------------------'
           `---.       ^         \        ^
                \ .---------.     `> .---------.        .----/scripting/----.
                  | network | <----- | session | -----> | browser scripting |
                  `---------'      / `---------'        `-------------------'
                       ^       .--'
                 .----------. <
                 | protocol |
                 `----------'