Skip to content

Commit 49acb29

Browse files
irorimibrunin
authored andcommitted
[Backport] Security bug 1135594
Manual cherry-pick of patch originally reviewed on https://chromium-review.googlesource.com/c/chromium/src/+/2465555: Roll WOFF2 1bccf208bc..a0d0ed7da2 This includes a fix for integer overflow, and relicensing to MIT. Bug: 1135594 Change-Id: Ia1ee98441f240a9e073cb05408801581144bbd0a Reviewed-by: Kenichi Ishibashi <[email protected]> Commit-Queue: Kunihiko Sakamoto <[email protected]> Cr-Commit-Position: refs/heads/master@{#817815} Reviewed-by: Allan Sandfeld Jensen <[email protected]> Reviewed-by: Michal Klocek <[email protected]>
1 parent 261f0bd commit 49acb29

File tree

5 files changed

+67
-212
lines changed

5 files changed

+67
-212
lines changed

chromium/third_party/woff2/LICENSE

Lines changed: 19 additions & 202 deletions
Original file line numberDiff line numberDiff line change
@@ -1,202 +1,19 @@
1-
2-
Apache License
3-
Version 2.0, January 2004
4-
http://www.apache.org/licenses/
5-
6-
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
7-
8-
1. Definitions.
9-
10-
"License" shall mean the terms and conditions for use, reproduction,
11-
and distribution as defined by Sections 1 through 9 of this document.
12-
13-
"Licensor" shall mean the copyright owner or entity authorized by
14-
the copyright owner that is granting the License.
15-
16-
"Legal Entity" shall mean the union of the acting entity and all
17-
other entities that control, are controlled by, or are under common
18-
control with that entity. For the purposes of this definition,
19-
"control" means (i) the power, direct or indirect, to cause the
20-
direction or management of such entity, whether by contract or
21-
otherwise, or (ii) ownership of fifty percent (50%) or more of the
22-
outstanding shares, or (iii) beneficial ownership of such entity.
23-
24-
"You" (or "Your") shall mean an individual or Legal Entity
25-
exercising permissions granted by this License.
26-
27-
"Source" form shall mean the preferred form for making modifications,
28-
including but not limited to software source code, documentation
29-
source, and configuration files.
30-
31-
"Object" form shall mean any form resulting from mechanical
32-
transformation or translation of a Source form, including but
33-
not limited to compiled object code, generated documentation,
34-
and conversions to other media types.
35-
36-
"Work" shall mean the work of authorship, whether in Source or
37-
Object form, made available under the License, as indicated by a
38-
copyright notice that is included in or attached to the work
39-
(an example is provided in the Appendix below).
40-
41-
"Derivative Works" shall mean any work, whether in Source or Object
42-
form, that is based on (or derived from) the Work and for which the
43-
editorial revisions, annotations, elaborations, or other modifications
44-
represent, as a whole, an original work of authorship. For the purposes
45-
of this License, Derivative Works shall not include works that remain
46-
separable from, or merely link (or bind by name) to the interfaces of,
47-
the Work and Derivative Works thereof.
48-
49-
"Contribution" shall mean any work of authorship, including
50-
the original version of the Work and any modifications or additions
51-
to that Work or Derivative Works thereof, that is intentionally
52-
submitted to Licensor for inclusion in the Work by the copyright owner
53-
or by an individual or Legal Entity authorized to submit on behalf of
54-
the copyright owner. For the purposes of this definition, "submitted"
55-
means any form of electronic, verbal, or written communication sent
56-
to the Licensor or its representatives, including but not limited to
57-
communication on electronic mailing lists, source code control systems,
58-
and issue tracking systems that are managed by, or on behalf of, the
59-
Licensor for the purpose of discussing and improving the Work, but
60-
excluding communication that is conspicuously marked or otherwise
61-
designated in writing by the copyright owner as "Not a Contribution."
62-
63-
"Contributor" shall mean Licensor and any individual or Legal Entity
64-
on behalf of whom a Contribution has been received by Licensor and
65-
subsequently incorporated within the Work.
66-
67-
2. Grant of Copyright License. Subject to the terms and conditions of
68-
this License, each Contributor hereby grants to You a perpetual,
69-
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
70-
copyright license to reproduce, prepare Derivative Works of,
71-
publicly display, publicly perform, sublicense, and distribute the
72-
Work and such Derivative Works in Source or Object form.
73-
74-
3. Grant of Patent License. Subject to the terms and conditions of
75-
this License, each Contributor hereby grants to You a perpetual,
76-
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
77-
(except as stated in this section) patent license to make, have made,
78-
use, offer to sell, sell, import, and otherwise transfer the Work,
79-
where such license applies only to those patent claims licensable
80-
by such Contributor that are necessarily infringed by their
81-
Contribution(s) alone or by combination of their Contribution(s)
82-
with the Work to which such Contribution(s) was submitted. If You
83-
institute patent litigation against any entity (including a
84-
cross-claim or counterclaim in a lawsuit) alleging that the Work
85-
or a Contribution incorporated within the Work constitutes direct
86-
or contributory patent infringement, then any patent licenses
87-
granted to You under this License for that Work shall terminate
88-
as of the date such litigation is filed.
89-
90-
4. Redistribution. You may reproduce and distribute copies of the
91-
Work or Derivative Works thereof in any medium, with or without
92-
modifications, and in Source or Object form, provided that You
93-
meet the following conditions:
94-
95-
(a) You must give any other recipients of the Work or
96-
Derivative Works a copy of this License; and
97-
98-
(b) You must cause any modified files to carry prominent notices
99-
stating that You changed the files; and
100-
101-
(c) You must retain, in the Source form of any Derivative Works
102-
that You distribute, all copyright, patent, trademark, and
103-
attribution notices from the Source form of the Work,
104-
excluding those notices that do not pertain to any part of
105-
the Derivative Works; and
106-
107-
(d) If the Work includes a "NOTICE" text file as part of its
108-
distribution, then any Derivative Works that You distribute must
109-
include a readable copy of the attribution notices contained
110-
within such NOTICE file, excluding those notices that do not
111-
pertain to any part of the Derivative Works, in at least one
112-
of the following places: within a NOTICE text file distributed
113-
as part of the Derivative Works; within the Source form or
114-
documentation, if provided along with the Derivative Works; or,
115-
within a display generated by the Derivative Works, if and
116-
wherever such third-party notices normally appear. The contents
117-
of the NOTICE file are for informational purposes only and
118-
do not modify the License. You may add Your own attribution
119-
notices within Derivative Works that You distribute, alongside
120-
or as an addendum to the NOTICE text from the Work, provided
121-
that such additional attribution notices cannot be construed
122-
as modifying the License.
123-
124-
You may add Your own copyright statement to Your modifications and
125-
may provide additional or different license terms and conditions
126-
for use, reproduction, or distribution of Your modifications, or
127-
for any such Derivative Works as a whole, provided Your use,
128-
reproduction, and distribution of the Work otherwise complies with
129-
the conditions stated in this License.
130-
131-
5. Submission of Contributions. Unless You explicitly state otherwise,
132-
any Contribution intentionally submitted for inclusion in the Work
133-
by You to the Licensor shall be under the terms and conditions of
134-
this License, without any additional terms or conditions.
135-
Notwithstanding the above, nothing herein shall supersede or modify
136-
the terms of any separate license agreement you may have executed
137-
with Licensor regarding such Contributions.
138-
139-
6. Trademarks. This License does not grant permission to use the trade
140-
names, trademarks, service marks, or product names of the Licensor,
141-
except as required for reasonable and customary use in describing the
142-
origin of the Work and reproducing the content of the NOTICE file.
143-
144-
7. Disclaimer of Warranty. Unless required by applicable law or
145-
agreed to in writing, Licensor provides the Work (and each
146-
Contributor provides its Contributions) on an "AS IS" BASIS,
147-
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
148-
implied, including, without limitation, any warranties or conditions
149-
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
150-
PARTICULAR PURPOSE. You are solely responsible for determining the
151-
appropriateness of using or redistributing the Work and assume any
152-
risks associated with Your exercise of permissions under this License.
153-
154-
8. Limitation of Liability. In no event and under no legal theory,
155-
whether in tort (including negligence), contract, or otherwise,
156-
unless required by applicable law (such as deliberate and grossly
157-
negligent acts) or agreed to in writing, shall any Contributor be
158-
liable to You for damages, including any direct, indirect, special,
159-
incidental, or consequential damages of any character arising as a
160-
result of this License or out of the use or inability to use the
161-
Work (including but not limited to damages for loss of goodwill,
162-
work stoppage, computer failure or malfunction, or any and all
163-
other commercial damages or losses), even if such Contributor
164-
has been advised of the possibility of such damages.
165-
166-
9. Accepting Warranty or Additional Liability. While redistributing
167-
the Work or Derivative Works thereof, You may choose to offer,
168-
and charge a fee for, acceptance of support, warranty, indemnity,
169-
or other liability obligations and/or rights consistent with this
170-
License. However, in accepting such obligations, You may act only
171-
on Your own behalf and on Your sole responsibility, not on behalf
172-
of any other Contributor, and only if You agree to indemnify,
173-
defend, and hold each Contributor harmless for any liability
174-
incurred by, or claims asserted against, such Contributor by reason
175-
of your accepting any such warranty or additional liability.
176-
177-
END OF TERMS AND CONDITIONS
178-
179-
APPENDIX: How to apply the Apache License to your work.
180-
181-
To apply the Apache License to your work, attach the following
182-
boilerplate notice, with the fields enclosed by brackets "[]"
183-
replaced with your own identifying information. (Don't include
184-
the brackets!) The text should be enclosed in the appropriate
185-
comment syntax for the file format. We also recommend that a
186-
file or class name and description of purpose be included on the
187-
same "printed page" as the copyright notice for easier
188-
identification within third-party archives.
189-
190-
Copyright [yyyy] [name of copyright owner]
191-
192-
Licensed under the Apache License, Version 2.0 (the "License");
193-
you may not use this file except in compliance with the License.
194-
You may obtain a copy of the License at
195-
196-
http://www.apache.org/licenses/LICENSE-2.0
197-
198-
Unless required by applicable law or agreed to in writing, software
199-
distributed under the License is distributed on an "AS IS" BASIS,
200-
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
201-
See the License for the specific language governing permissions and
202-
limitations under the License.
1+
Copyright (c) 2013-2017 by the WOFF2 Authors.
2+
3+
Permission is hereby granted, free of charge, to any person obtaining a copy
4+
of this software and associated documentation files (the "Software"), to deal
5+
in the Software without restriction, including without limitation the rights
6+
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
7+
copies of the Software, and to permit persons to whom the Software is
8+
furnished to do so, subject to the following conditions:
9+
10+
The above copyright notice and this permission notice shall be included in
11+
all copies or substantial portions of the Software.
12+
13+
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
14+
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
15+
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
16+
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
17+
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
18+
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN
19+
THE SOFTWARE.

chromium/third_party/woff2/Makefile

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
OS := $(shell uname)
22

3-
CPPFLAGS = -I./brotli/include/ -I./src
3+
CPPFLAGS = -I./brotli/include/ -I./src -I./include
44

55
AR ?= ar
66
CC ?= gcc
@@ -11,13 +11,15 @@ CANONICAL_PREFIXES ?= -no-canonical-prefixes
1111
NOISY_LOGGING ?= -DFONT_COMPRESSION_BIN
1212
COMMON_FLAGS = -fno-omit-frame-pointer $(CANONICAL_PREFIXES) $(NOISY_LOGGING) -D __STDC_FORMAT_MACROS
1313

14+
ARFLAGS = crf
15+
1416
ifeq ($(OS), Darwin)
1517
CPPFLAGS += -DOS_MACOSX
18+
ARFLAGS = cr
1619
else
1720
COMMON_FLAGS += -fno-tree-vrp
1821
endif
1922

20-
ARFLAGS = crf
2123
CFLAGS += $(COMMON_FLAGS)
2224
CXXFLAGS += $(COMMON_FLAGS) -std=c++11
2325

@@ -28,13 +30,13 @@ OUROBJ = font.o glyph.o normalize.o table_tags.o transform.o \
2830
variable_length.o
2931

3032
BROTLI = brotli
31-
BROTLIOBJ = $(BROTLI)/bin/obj
33+
BROTLIOBJ = $(BROTLI)/bin/obj/c
3234
ENCOBJ = $(BROTLIOBJ)/enc/*.o
3335
DECOBJ = $(BROTLIOBJ)/dec/*.o
3436
COMMONOBJ = $(BROTLIOBJ)/common/*.o
3537

3638
OBJS = $(patsubst %, $(SRCDIR)/%, $(OUROBJ))
37-
EXECUTABLES=woff2_compress woff2_decompress
39+
EXECUTABLES=woff2_compress woff2_decompress woff2_info
3840
EXE_OBJS=$(patsubst %, $(SRCDIR)/%.o, $(EXECUTABLES))
3941
ARCHIVES=convert_woff2ttf_fuzzer convert_woff2ttf_fuzzer_new_entry
4042
ARCHIVE_OBJS=$(patsubst %, $(SRCDIR)/%.o, $(ARCHIVES))
Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
Name: woff2
22
URL: https://github.com/google/woff2
3-
Version: 1bccf208bca986e53a647dfe4811322adb06ecf8
4-
License: Apache 2.0
3+
Version: a0d0ed7da27b708c0a4e96ad7a998bddc933c06e
4+
License: MIT
55
License File: LICENSE
66
Security Critical: yes
77

@@ -12,4 +12,3 @@ format (http://www.w3.org/TR/WOFF2/).
1212
Local Modifications:
1313

1414
- BUILD.gn: Added.
15-
- woff2.gyp: Added.

chromium/third_party/woff2/README.md

Lines changed: 23 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -25,6 +25,29 @@ cd woff2
2525
make clean all
2626
```
2727

28+
Alternatively, if Brotli is already installed on your system you can use CMake
29+
to build executables and libraries:
30+
31+
```
32+
git clone https://github.com/google/woff2.git
33+
cd woff2
34+
mkdir out
35+
cd out
36+
cmake ..
37+
make
38+
make install
39+
```
40+
41+
By default, shared libraries are built. To use static linkage, do:
42+
43+
```
44+
cd woff2
45+
mkdir out-static
46+
cmake -DBUILD_SHARED_LIBS=OFF ..
47+
make
48+
make install
49+
```
50+
2851
## Run
2952

3053
Ensure the binaries from the build process are in your $PATH, then:

chromium/third_party/woff2/src/woff2_dec.cc

Lines changed: 17 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -111,6 +111,16 @@ int WithSign(int flag, int baseval) {
111111
return (flag & 1) ? baseval : -baseval;
112112
}
113113

114+
bool _SafeIntAddition(int a, int b, int* result) {
115+
if (PREDICT_FALSE(
116+
((a > 0) && (b > std::numeric_limits<int>::max() - a)) ||
117+
((a < 0) && (b < std::numeric_limits<int>::min() - a)))) {
118+
return false;
119+
}
120+
*result = a + b;
121+
return true;
122+
}
123+
114124
bool TripletDecode(const uint8_t* flags_in, const uint8_t* in, size_t in_size,
115125
unsigned int n_points, Point* result, size_t* in_bytes_consumed) {
116126
int x = 0;
@@ -166,9 +176,13 @@ bool TripletDecode(const uint8_t* flags_in, const uint8_t* in, size_t in_size,
166176
(in[triplet_index + 2] << 8) + in[triplet_index + 3]);
167177
}
168178
triplet_index += n_data_bytes;
169-
// Possible overflow but coordinate values are not security sensitive
170-
x += dx;
171-
y += dy;
179+
180+
if (!_SafeIntAddition(x, dx, &x)) {
181+
return false;
182+
}
183+
if (!_SafeIntAddition(y, dy, &y)) {
184+
return false;
185+
}
172186
*result++ = {x, y, on_curve};
173187
}
174188
*in_bytes_consumed = triplet_index;

0 commit comments

Comments
 (0)