JasonWoof Got questions, comments, patches, etc.? Contact Jason Woofenden
Avoid buffer overrun in kpress() and remove limit on shortcut strings.
[st.git] / st.c
diff --git a/st.c b/st.c
index 77ea0c8..16bf68b 100644 (file)
--- a/st.c
+++ b/st.c
@@ -264,7 +264,7 @@ typedef struct {
 typedef struct {
        KeySym k;
        uint mask;
-       char s[ESC_BUF_SIZ];
+       char *s;
        /* three valued logic variables: 0 indifferent, 1 on, -1 off */
        signed char appkey;    /* application keypad */
        signed char appcursor; /* application cursor */
@@ -3563,8 +3563,8 @@ void
 kpress(XEvent *ev) {
        XKeyEvent *e = &ev->xkey;
        KeySym ksym;
-       char xstr[31], buf[32], *customkey, *cp = buf;
-       int len, ret;
+       char buf[32], *customkey;
+       int len;
        long c;
        Status status;
        Shortcut *bp;
@@ -3572,7 +3572,7 @@ kpress(XEvent *ev) {
        if(IS_SET(MODE_KBDLOCK))
                return;
 
-       len = XmbLookupString(xw.xic, e, xstr, sizeof(xstr), &ksym, &status);
+       len = XmbLookupString(xw.xic, e, buf, sizeof buf, &ksym, &status);
        e->state &= ~Mod2Mask;
        /* 1. shortcuts */
        for(bp = shortcuts; bp < shortcuts + LEN(shortcuts); bp++) {
@@ -3585,29 +3585,27 @@ kpress(XEvent *ev) {
        /* 2. custom keys from config.h */
        if((customkey = kmap(ksym, e->state))) {
                len = strlen(customkey);
-               memcpy(buf, customkey, len);
-       /* 3. hardcoded (overrides X lookup) */
-       } else {
-               if(len == 0)
-                       return;
+               ttywrite(customkey, len);
+               if(IS_SET(MODE_ECHO))
+                       techo(customkey, len);
+               return;
+       }
 
-               if(len == 1 && e->state & Mod1Mask) {
-                       if(IS_SET(MODE_8BIT)) {
-                               if(*xstr < 0177) {
-                                       c = *xstr | 0x80;
-                                       ret = utf8encode(&c, cp);
-                                       cp += ret;
-                                       len = 0;
-                               }
-                       } else {
-                               *cp++ = '\033';
+       /* 3. composed string from input method */
+       if(len == 0)
+               return;
+       if(len == 1 && e->state & Mod1Mask) {
+               if(IS_SET(MODE_8BIT)) {
+                       if(*buf < 0177) {
+                               c = *buf | 0x80;
+                               len = utf8encode(&c, buf);
                        }
+               } else {
+                       buf[1] = buf[0];
+                       buf[0] = '\033';
+                       len = 2;
                }
-
-               memcpy(cp, xstr, len);
-               len = cp - buf + len;
        }
-
        ttywrite(buf, len);
        if(IS_SET(MODE_ECHO))
                techo(buf, len);