Fixed a bug in the parser.

When we parse the metadata we check that there is enough data in the parcel by checking
 the byte availables and the size in the header.
Since the size is in the header has been read, we should make sure than dataAvailable() >= size - 4

This bug was hidden by some test code which has been removed.
This commit is contained in:
niko
2009-07-20 13:10:01 -07:00
parent 0e9dd3b008
commit c39173be32
2 changed files with 4 additions and 8 deletions

View File

@@ -280,8 +280,9 @@ public class Metadata
final int pin = parcel.dataPosition(); // to roll back in case of errors.
final int size = parcel.readInt();
if (parcel.dataAvail() < size || size < kMetaHeaderSize) {
Log.e(TAG, "Bad size " + size);
// Magic 4 below is for the int32 'size' just read.
if (parcel.dataAvail() + 4 < size || size < kMetaHeaderSize) {
Log.e(TAG, "Bad size " + size + " avail " + parcel.dataAvail() + " position " + pin);
parcel.setDataPosition(pin);
return false;
}

View File

@@ -56,15 +56,10 @@ public class MediaPlayerMetadataParserTest extends AndroidTestCase {
assertEquals(0, mParcel.dataPosition());
}
// Check parsing of the parcel is successful. Before the
// invocation of the parser a token is inserted. When the parser
// returns, the parcel should be positioned at the token (check it
// does not read too much data).
// Check parsing of the parcel is successful.
private void assertParse() throws Exception {
mParcel.writeInt(kToken);
mParcel.setDataPosition(0);
assertTrue(mMetadata.parse(mParcel));
assertEquals(kToken, mParcel.readInt());
}
// Write the number of bytes from the start of the parcel to the