Merge "Handle integer overflow in BaseInputConnection" into udc-dev

This commit is contained in:
Treehugger Robot
2023-05-09 16:14:40 +00:00
committed by Android (Google) Code Review
2 changed files with 52 additions and 13 deletions

View File

@@ -622,15 +622,11 @@ public class BaseInputConnection implements InputConnection {
if (b < 0) { if (b < 0) {
b = 0; b = 0;
} }
int end = (int) Math.min((long) b + length, content.length());
if (b + length > content.length()) {
length = content.length() - b;
}
if ((flags&GET_TEXT_WITH_STYLES) != 0) { if ((flags&GET_TEXT_WITH_STYLES) != 0) {
return content.subSequence(b, b + length); return content.subSequence(b, end);
} }
return TextUtils.substring(content, b, b + length); return TextUtils.substring(content, b, end);
} }
/** /**
@@ -666,13 +662,9 @@ public class BaseInputConnection implements InputConnection {
selEnd = tmp; selEnd = tmp;
} }
int contentLength = content.length();
int startPos = selStart - beforeLength;
int endPos = selEnd + afterLength;
// Guards the start and end pos within range [0, contentLength]. // Guards the start and end pos within range [0, contentLength].
startPos = Math.max(0, startPos); int startPos = Math.max(0, selStart - beforeLength);
endPos = Math.min(contentLength, endPos); int endPos = (int) Math.min((long) selEnd + afterLength, content.length());
CharSequence surroundingText; CharSequence surroundingText;
if ((flags & GET_TEXT_WITH_STYLES) != 0) { if ((flags & GET_TEXT_WITH_STYLES) != 0) {

View File

@@ -549,6 +549,14 @@ public class BaseInputConnectionTest {
.isEqualTo(new SurroundingText("456", 0, 3, -1))) .isEqualTo(new SurroundingText("456", 0, 3, -1)))
.isTrue(); .isTrue();
verifyContentEquals(mBaseInputConnection.getTextBeforeCursor(Integer.MAX_VALUE, 0), "123");
verifyContentEquals(mBaseInputConnection.getTextAfterCursor(Integer.MAX_VALUE, 0), "789");
assertThat(
mBaseInputConnection
.getSurroundingText(Integer.MAX_VALUE, Integer.MAX_VALUE, 0)
.isEqualTo(new SurroundingText("123456789", 3, 6, -1)))
.isTrue();
int cursorCapsMode = int cursorCapsMode =
TextUtils.getCapsMode( TextUtils.getCapsMode(
"123456789", "123456789",
@@ -617,6 +625,45 @@ public class BaseInputConnectionTest {
verifyTextSnapshotContentEquals(mBaseInputConnection.takeSnapshot(), expectedTextSnapshot); verifyTextSnapshotContentEquals(mBaseInputConnection.takeSnapshot(), expectedTextSnapshot);
} }
@Test
public void testGetText_emptyText() {
// ""
prepareContent("", 0, 0, -1, -1);
verifyContentEquals(mBaseInputConnection.getTextBeforeCursor(1, 0), "");
verifyContentEquals(mBaseInputConnection.getTextAfterCursor(1, 0), "");
assertThat(mBaseInputConnection.getSelectedText(0)).isNull();
// This falls back to default implementation in {@code InputConnection}, which always return
// -1 for offset.
assertThat(
mBaseInputConnection
.getSurroundingText(1, 1, 0)
.isEqualTo(new SurroundingText("", 0, 0, -1)))
.isTrue();
verifyContentEquals(mBaseInputConnection.getTextBeforeCursor(0, 0), "");
verifyContentEquals(mBaseInputConnection.getTextAfterCursor(0, 0), "");
assertThat(mBaseInputConnection.getSelectedText(0)).isNull();
// This falls back to default implementation in {@code InputConnection}, which always return
// -1 for offset.
assertThat(
mBaseInputConnection
.getSurroundingText(0, 0, 0)
.isEqualTo(new SurroundingText("", 0, 0, -1)))
.isTrue();
verifyContentEquals(mBaseInputConnection.getTextBeforeCursor(Integer.MAX_VALUE, 0), "");
verifyContentEquals(mBaseInputConnection.getTextAfterCursor(Integer.MAX_VALUE, 0), "");
assertThat(mBaseInputConnection.getSelectedText(0)).isNull();
assertThat(
mBaseInputConnection
.getSurroundingText(Integer.MAX_VALUE, Integer.MAX_VALUE, 0)
.isEqualTo(new SurroundingText("", 0, 0, -1)))
.isTrue();
}
@Test @Test
public void testReplaceText_toEditorWithoutSelectionAndComposing() { public void testReplaceText_toEditorWithoutSelectionAndComposing() {
// before replace: "|" // before replace: "|"