From: Eric Anholt Date: Wed, 25 Feb 2009 19:57:44 +0000 (-0800) Subject: Cap array elements at 0 when passed an invalid pointer for an array object. X-Git-Url: https://git.libre-soc.org/?a=commitdiff_plain;h=058e96916b1ee661dfc16052b79b3aa9fcb47690;p=mesa.git Cap array elements at 0 when passed an invalid pointer for an array object. Otherwise, a pointer greater than the size would underflow and give a large maximum element. Reviewed-by: Brian Paul (previous version) --- diff --git a/src/mesa/main/state.c b/src/mesa/main/state.c index 7b41b8f4da4..3b2c6ec6189 100644 --- a/src/mesa/main/state.c +++ b/src/mesa/main/state.c @@ -75,6 +75,16 @@ compute_max_element(struct gl_client_array *array) { assert(array->Enabled); if (array->BufferObj->Name) { + GLsizeiptrARB offset = (GLsizeiptrARB) array->Ptr; + GLsizeiptrARB obj_size = (GLsizeiptrARB) array->BufferObj->Size; + + if (offset < obj_size) { + array->_MaxElement = (obj_size - offset + + array->StrideB - + array->_ElementSize) / array->StrideB; + } else { + array->_MaxElement = 0; + } /* Compute the max element we can access in the VBO without going * out of bounds. */