… | |
… | |
3 | * |
3 | * |
4 | * Copyright (©) 2005,2006,2007,2008 Marc Alexander Lehmann / Robin Redeker / the Deliantra team |
4 | * Copyright (©) 2005,2006,2007,2008 Marc Alexander Lehmann / Robin Redeker / the Deliantra team |
5 | * Copyright (©) 2002,2007 Mark Wedel & Crossfire Development Team |
5 | * Copyright (©) 2002,2007 Mark Wedel & Crossfire Development Team |
6 | * Copyright (©) 1992,2007 Frank Tore Johansen |
6 | * Copyright (©) 1992,2007 Frank Tore Johansen |
7 | * |
7 | * |
8 | * Deliantra is free software: you can redistribute it and/or modify |
8 | * Deliantra is free software: you can redistribute it and/or modify it under |
9 | * it under the terms of the GNU General Public License as published by |
9 | * the terms of the Affero GNU General Public License as published by the |
10 | * the Free Software Foundation, either version 3 of the License, or |
10 | * Free Software Foundation, either version 3 of the License, or (at your |
11 | * (at your option) any later version. |
11 | * option) any later version. |
12 | * |
12 | * |
13 | * This program is distributed in the hope that it will be useful, |
13 | * This program is distributed in the hope that it will be useful, |
14 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
14 | * but WITHOUT ANY WARRANTY; without even the implied warranty of |
15 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
15 | * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the |
16 | * GNU General Public License for more details. |
16 | * GNU General Public License for more details. |
17 | * |
17 | * |
18 | * You should have received a copy of the GNU General Public License |
18 | * You should have received a copy of the Affero GNU General Public License |
19 | * along with this program. If not, see <http://www.gnu.org/licenses/>. |
19 | * and the GNU General Public License along with this program. If not, see |
|
|
20 | * <http://www.gnu.org/licenses/>. |
20 | * |
21 | * |
21 | * The authors can be reached via e-mail to <support@deliantra.net> |
22 | * The authors can be reached via e-mail to <support@deliantra.net> |
22 | */ |
23 | */ |
23 | |
24 | |
24 | /* |
25 | /* |
… | |
… | |
459 | msg_is_safe (const char *msg) |
460 | msg_is_safe (const char *msg) |
460 | { |
461 | { |
461 | bool safe = true; |
462 | bool safe = true; |
462 | |
463 | |
463 | /* Trying to cheat by getting data into the object */ |
464 | /* Trying to cheat by getting data into the object */ |
464 | if (!strncmp (msg, "endmsg", strlen ("endmsg")) || strstr (msg, "\nendmsg")) |
465 | if (!strncmp (msg, "endmsg", sizeof ("endmsg") - 1) |
|
|
466 | || strstr (msg, "\nendmsg")) |
465 | safe = false; |
467 | safe = false; |
466 | |
468 | |
467 | /* Trying to make the object talk, and potentially access arbitrary code */ |
469 | /* Trying to make the object talk, and potentially access arbitrary code */ |
468 | if (object::msg_has_dialogue (msg)) |
470 | if (object::msg_has_dialogue (msg)) |
469 | safe = false; |
471 | safe = false; |
… | |
… | |
610 | memcpy (dst, src, ++len); |
612 | memcpy (dst, src, ++len); |
611 | |
613 | |
612 | return len; |
614 | return len; |
613 | } |
615 | } |
614 | |
616 | |
615 | const char * |
617 | char * |
|
|
618 | vformat (const char *format, va_list ap) |
|
|
619 | { |
|
|
620 | static dynbuf_text buf; buf.clear (); |
|
|
621 | buf.vprintf (format, ap); |
|
|
622 | return buf; |
|
|
623 | } |
|
|
624 | |
|
|
625 | char * |
616 | format (const char *format, ...) |
626 | format (const char *format, ...) |
617 | { |
627 | { |
618 | static dynbuf_text buf; |
|
|
619 | |
|
|
620 | buf.clear (); |
|
|
621 | |
|
|
622 | va_list ap; |
628 | va_list ap; |
623 | va_start (ap, format); |
629 | va_start (ap, format); |
624 | buf.vprintf (format, ap); |
630 | char *buf = vformat (format, ap); |
625 | va_end (ap); |
631 | va_end (ap); |
626 | |
632 | |
627 | return buf; |
633 | return buf; |
628 | } |
634 | } |
629 | |
635 | |