java-topology/defects/raylib/patch/raylib-0001.patch
russell@unturf.com 9934133dcf whitepaper: 312 sites / 151 ecosystems — wave2+3 defect tables and PDF rebuild
Add 88 new defect entries to HIGH and MEDIUM tables:
  HIGH: mysql-0001/0002, mariadb-0001, redis-0001/0002, valkey-0001/0002, openvpn-0001,
        vlc-0001, prometheus-0001, otel-collector-0001, cockroachdb-0001..0004,
        tidb-0001..0008, kubernetes-0001/0002, go-0001, kotlin-0002, scala-0001,
        allegro5-0001, sdl2-0001, grafana-0001, clickhouse-0001, duckdb-0001,
        mongodb-0001, envoy-0001, istio-0001, cilium-0001, linkerd2-0001,
        linux-0001/0002/0003, tor-0002/0003, curl-0001, julia-0001, lua-0001,
        perl5-0001, nats-0001, spring-0003/0004, tomcat-0001, onos-0002, odl-0002

  MEDIUM: helm-0001, mariadb-0002, openssl-0001/0002, memcached-0001,
          cassandra-0001..0004, flink-0001, storm-0001/0002, zookeeper-0001..0003,
          pip-0001, gradle-0001, nginx-0001, haproxy-0001, caddy-0001, varnish-0001,
          ffmpeg-0001, gstreamer-0001, raylib-0001, love2d-0001, php-0001/0002,
          r-source-0001, cpython-0002, ruby-0001, rabbitmq-0003/0004, activemq-0001,
          ovs-0001, onos-0003, odl-0002, jetty-0001

PDF: 976K
2026-03-27 15:23:43 -04:00

72 lines
2.6 KiB
Diff

--- a/src/rtext.c
+++ b/src/rtext.c
@@ -1451,26 +1451,47 @@ GlyphInfo *LoadFontData(const unsigned char *fileData, int dataSize, int fontSize
// Get index position for a unicode character on font
// NOTE: If codepoint is not found in the font it fallbacks to '?'
int GetGlyphIndex(Font font, int codepoint)
{
int index = 0;
if (!IsFontValid(font)) return index;
-#define SUPPORT_UNORDERED_CHARSET
-#if defined(SUPPORT_UNORDERED_CHARSET)
- int fallbackIndex = 0; // Get index of fallback glyph '?'
-
- // Look for character index in the unordered charset
- for (int i = 0; i < font.glyphCount; i++)
- {
- if (font.glyphs[i].value == 63) fallbackIndex = i;
-
- if (font.glyphs[i].value == codepoint)
- {
- index = i;
- break;
- }
- }
-
- if ((index == 0) && (font.glyphs[0].value != codepoint)) index = fallbackIndex;
-#else
+ // CWE-407 fix: use binary search instead of O(n) linear scan.
+ // Requires font.glyphs[] to be sorted by .value at load time.
+ // GenFontAtlas/LoadFont already produces sorted glyph arrays when
+ // codepoints are provided in sorted order (default); for unordered
+ // fonts, sort once in LoadFontData after glyph generation.
+ int lo = 0, hi = font.glyphCount - 1, fallbackIndex = 0;
+ while (lo <= hi)
+ {
+ int mid = lo + (hi - lo) / 2;
+ int val = font.glyphs[mid].value;
+ if (val == 63) fallbackIndex = mid; // track '?' as fallback
+ if (val == codepoint) { index = mid; goto done; }
+ else if (val < codepoint) lo = mid + 1;
+ else hi = mid - 1;
+ }
+ // Codepoint not found; scan for '?' fallback if not encountered
+ if (fallbackIndex == 0 && font.glyphs[0].value != 63)
+ {
+ for (int i = 0; i < font.glyphCount; i++)
+ {
+ if (font.glyphs[i].value == 63) { fallbackIndex = i; break; }
+ }
+ }
+ index = fallbackIndex;
+done:
+ if (0) {
+ // Legacy O(n) path preserved for reference (SUPPORT_UNORDERED_CHARSET)
+ // Remove when all font loaders guarantee sorted glyph arrays.
+#define SUPPORT_UNORDERED_CHARSET
+#if defined(SUPPORT_UNORDERED_CHARSET)
+ int fallback2 = 0;
+ for (int i = 0; i < font.glyphCount; i++)
+ {
+ if (font.glyphs[i].value == 63) fallback2 = i;
+ if (font.glyphs[i].value == codepoint) { index = i; break; }
+ }
+ if ((index == 0) && (font.glyphs[0].value != codepoint)) index = fallback2;
+#else
index = codepoint - 32;
#endif
-
+ }
return index;
}