Commit 9206eba291017e9917d5e17e94ea6d4fcbca9f0f

suzuki toshiya 2009-08-01T00:32:17

truetype: Truncate the deltas of composite glyph at 16-bit values.

diff --git a/ChangeLog b/ChangeLog
index 3de1bba..b91d029 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,5 +1,18 @@
 2009-07-31  suzuki toshiya <mpsuzuki@hiroshima-u.ac.jp>
 
+	truetype: Truncate the deltas of composite glyph at 16-bit values.
+
+	* src/truetype/ttgload.c (load_truetype_glyph):
+	Insert cast from FT_Long (deltas[i].{x,y}) to
+	FT_Int16 in the summation of deltas[] for composite
+	glyphs.  Because deltas[i] is typed as FT_Pos,
+	its component x, y are typed as FT_Long, but
+	their sources are always FT_Int16 when they are
+	loaded by ft_var_readpackeddeltas().  However,
+	the limitation about the summed deltas is unclear.
+
+2009-07-31  suzuki toshiya <mpsuzuki@hiroshima-u.ac.jp>
+
 	truetype: Truncate the instructions upto 16-bit per a glyph.
 
 	* src/truetype/ttgload.c (TT_Hint_Glyph): Truncate
diff --git a/src/truetype/ttgload.c b/src/truetype/ttgload.c
index 5d48e8f..b0f6810 100644
--- a/src/truetype/ttgload.c
+++ b/src/truetype/ttgload.c
@@ -1400,8 +1400,11 @@
         {
           if ( subglyph->flags & ARGS_ARE_XY_VALUES )
           {
-            subglyph->arg1 += deltas[i].x;
-            subglyph->arg2 += deltas[i].y;
+            /* XXX: overflow check for subglyph->{arg1,arg2}.   */
+            /* deltas[i].{x,y} must be within signed 16-bit,    */
+            /* but the restriction of summed delta is not clear */
+            subglyph->arg1 += (FT_Int16)deltas[i].x;
+            subglyph->arg2 += (FT_Int16)deltas[i].y;
           }
         }