fix scanf %c conversion wrongly storing a terminating null byte
[musl] / src / stdio / vfscanf.c
1 #include <stdlib.h>
2 #include <stdarg.h>
3 #include <ctype.h>
4 #include <wchar.h>
5 #include <wctype.h>
6 #include <limits.h>
7 #include <string.h>
8 #include <errno.h>
9 #include <math.h>
10 #include <float.h>
11 #include <inttypes.h>
12
13 #include "stdio_impl.h"
14 #include "shgetc.h"
15 #include "intscan.h"
16 #include "floatscan.h"
17
18 #define SIZE_hh -2
19 #define SIZE_h  -1
20 #define SIZE_def 0
21 #define SIZE_l   1
22 #define SIZE_L   2
23 #define SIZE_ll  3
24
25 static void store_int(void *dest, int size, unsigned long long i)
26 {
27         if (!dest) return;
28         switch (size) {
29         case SIZE_hh:
30                 *(char *)dest = i;
31                 break;
32         case SIZE_h:
33                 *(short *)dest = i;
34                 break;
35         case SIZE_def:
36                 *(int *)dest = i;
37                 break;
38         case SIZE_l:
39                 *(long *)dest = i;
40                 break;
41         case SIZE_ll:
42                 *(long long *)dest = i;
43                 break;
44         }
45 }
46
47 static void *arg_n(va_list ap, unsigned int n)
48 {
49         void *p;
50         unsigned int i;
51         va_list ap2;
52         va_copy(ap2, ap);
53         for (i=n; i>1; i--) va_arg(ap2, void *);
54         p = va_arg(ap2, void *);
55         va_end(ap2);
56         return p;
57 }
58
59 int vfscanf(FILE *restrict f, const char *restrict fmt, va_list ap)
60 {
61         int width;
62         int size;
63         int alloc;
64         int base;
65         const unsigned char *p;
66         int c, t;
67         char *s;
68         wchar_t *wcs;
69         mbstate_t st;
70         void *dest=NULL;
71         int invert;
72         int matches=0;
73         unsigned long long x;
74         long double y;
75         off_t pos = 0;
76         unsigned char scanset[257];
77         size_t i, k;
78         wchar_t wc;
79
80         FLOCK(f);
81
82         for (p=(const unsigned char *)fmt; *p; p++) {
83
84                 if (isspace(*p)) {
85                         while (isspace(p[1])) p++;
86                         shlim(f, 0);
87                         while (isspace(shgetc(f)));
88                         shunget(f);
89                         pos += shcnt(f);
90                         continue;
91                 }
92                 if (*p != '%' || p[1] == '%') {
93                         p += *p=='%';
94                         shlim(f, 0);
95                         c = shgetc(f);
96                         if (c!=*p) {
97                                 shunget(f);
98                                 if (c<0) goto input_fail;
99                                 goto match_fail;
100                         }
101                         pos++;
102                         continue;
103                 }
104
105                 p++;
106                 if (*p=='*') {
107                         dest = 0; p++;
108                 } else if (isdigit(*p) && p[1]=='$') {
109                         dest = arg_n(ap, *p-'0'); p+=2;
110                 } else {
111                         dest = va_arg(ap, void *);
112                 }
113
114                 for (width=0; isdigit(*p); p++) {
115                         width = 10*width + *p - '0';
116                 }
117
118                 if (*p=='m') {
119                         alloc = !!dest;
120                         p++;
121                 } else {
122                         alloc = 0;
123                 }
124
125                 size = SIZE_def;
126                 switch (*p++) {
127                 case 'h':
128                         if (*p == 'h') p++, size = SIZE_hh;
129                         else size = SIZE_h;
130                         break;
131                 case 'l':
132                         if (*p == 'l') p++, size = SIZE_ll;
133                         else size = SIZE_l;
134                         break;
135                 case 'j':
136                         size = SIZE_ll;
137                         break;
138                 case 'z':
139                 case 't':
140                         size = SIZE_l;
141                         break;
142                 case 'L':
143                         size = SIZE_L;
144                         break;
145                 case 'd': case 'i': case 'o': case 'u': case 'x':
146                 case 'a': case 'e': case 'f': case 'g':
147                 case 'A': case 'E': case 'F': case 'G': case 'X':
148                 case 's': case 'c': case '[':
149                 case 'S': case 'C':
150                 case 'p': case 'n':
151                         p--;
152                         break;
153                 default:
154                         goto fmt_fail;
155                 }
156
157                 t = *p;
158
159                 /* C or S */
160                 if ((t&0x2f) == 3) {
161                         t |= 32;
162                         size = SIZE_l;
163                 }
164
165                 switch (t) {
166                 case 'c':
167                         if (width < 1) width = 1;
168                 case '[':
169                         break;
170                 case 'n':
171                         store_int(dest, size, pos);
172                         /* do not increment match count, etc! */
173                         continue;
174                 default:
175                         shlim(f, 0);
176                         while (isspace(shgetc(f)));
177                         shunget(f);
178                         pos += shcnt(f);
179                 }
180
181                 shlim(f, width);
182                 if (shgetc(f) < 0) goto input_fail;
183                 shunget(f);
184
185                 switch (t) {
186                 case 's':
187                 case 'c':
188                 case '[':
189                         if (t == 'c' || t == 's') {
190                                 memset(scanset, -1, sizeof scanset);
191                                 scanset[0] = 0;
192                                 if (t == 's') {
193                                         scanset[1+'\t'] = 0;
194                                         scanset[1+'\n'] = 0;
195                                         scanset[1+'\v'] = 0;
196                                         scanset[1+'\f'] = 0;
197                                         scanset[1+'\r'] = 0;
198                                         scanset[1+' '] = 0;
199                                 }
200                         } else {
201                                 if (*++p == '^') p++, invert = 1;
202                                 else invert = 0;
203                                 memset(scanset, invert, sizeof scanset);
204                                 scanset[0] = 0;
205                                 if (*p == '-') p++, scanset[1+'-'] = 1-invert;
206                                 else if (*p == ']') p++, scanset[1+']'] = 1-invert;
207                                 for (; *p != ']'; p++) {
208                                         if (!*p) goto fmt_fail;
209                                         if (*p=='-' && p[1] && p[1] != ']')
210                                                 for (c=p++[-1]; c<*p; c++)
211                                                         scanset[1+c] = 1-invert;
212                                         scanset[1+*p] = 1-invert;
213                                 }
214                         }
215                         wcs = 0;
216                         s = 0;
217                         i = 0;
218                         k = t=='c' ? width+1U : 31;
219                         if (size == SIZE_l) {
220                                 if (alloc) {
221                                         wcs = malloc(k*sizeof(wchar_t));
222                                         if (!wcs) goto alloc_fail;
223                                 } else {
224                                         wcs = dest;
225                                 }
226                                 st = (mbstate_t){0};
227                                 while (scanset[(c=shgetc(f))+1]) {
228                                         switch (mbrtowc(&wc, &(char){c}, 1, &st)) {
229                                         case -1:
230                                                 goto input_fail;
231                                         case -2:
232                                                 continue;
233                                         }
234                                         if (wcs) wcs[i++] = wc;
235                                         if (alloc && i==k) {
236                                                 k+=k+1;
237                                                 wchar_t *tmp = realloc(wcs, k*sizeof(wchar_t));
238                                                 if (!tmp) goto alloc_fail;
239                                                 wcs = tmp;
240                                         }
241                                 }
242                                 if (!mbsinit(&st)) goto input_fail;
243                         } else if (alloc) {
244                                 s = malloc(k);
245                                 if (!s) goto alloc_fail;
246                                 while (scanset[(c=shgetc(f))+1]) {
247                                         s[i++] = c;
248                                         if (i==k) {
249                                                 k+=k+1;
250                                                 char *tmp = realloc(s, k);
251                                                 if (!tmp) goto alloc_fail;
252                                                 s = tmp;
253                                         }
254                                 }
255                         } else if ((s = dest)) {
256                                 while (scanset[(c=shgetc(f))+1])
257                                         s[i++] = c;
258                         } else {
259                                 while (scanset[(c=shgetc(f))+1]);
260                         }
261                         shunget(f);
262                         if (!shcnt(f)) goto match_fail;
263                         if (t == 'c' && shcnt(f) != width) goto match_fail;
264                         if (alloc) {
265                                 if (size == SIZE_l) *(wchar_t **)dest = wcs;
266                                 else *(char **)dest = s;
267                         }
268                         if (t != 'c') {
269                                 if (wcs) wcs[i] = 0;
270                                 if (s) s[i] = 0;
271                         }
272                         break;
273                 case 'p':
274                 case 'X':
275                 case 'x':
276                         base = 16;
277                         goto int_common;
278                 case 'o':
279                         base = 8;
280                         goto int_common;
281                 case 'd':
282                 case 'u':
283                         base = 10;
284                         goto int_common;
285                 case 'i':
286                         base = 0;
287                 int_common:
288                         x = __intscan(f, base, 0, ULLONG_MAX);
289                         if (!shcnt(f)) goto match_fail;
290                         if (t=='p' && dest) *(void **)dest = (void *)(uintptr_t)x;
291                         else store_int(dest, size, x);
292                         break;
293                 case 'a': case 'A':
294                 case 'e': case 'E':
295                 case 'f': case 'F':
296                 case 'g': case 'G':
297                         y = __floatscan(f, size, 0);
298                         if (!shcnt(f)) goto match_fail;
299                         if (dest) switch (size) {
300                         case SIZE_def:
301                                 *(float *)dest = y;
302                                 break;
303                         case SIZE_l:
304                                 *(double *)dest = y;
305                                 break;
306                         case SIZE_L:
307                                 *(long double *)dest = y;
308                                 break;
309                         }
310                         break;
311                 }
312
313                 pos += shcnt(f);
314                 if (dest) matches++;
315         }
316         if (0) {
317 fmt_fail:
318 alloc_fail:
319 input_fail:
320                 if (!matches) matches--;
321 match_fail:
322                 if (alloc) {
323                         free(s);
324                         free(wcs);
325                 }
326         }
327         FUNLOCK(f);
328         return matches;
329 }