| 677 | |
| 678 | template<typename Stream, typename V> |
| 679 | void Unser(Stream& s, V& v) |
| 680 | { |
| 681 | Formatter formatter; |
| 682 | v.clear(); |
| 683 | size_t size = ReadCompactSize(s); |
| 684 | size_t allocated = 0; |
| 685 | while (allocated < size) { |
| 686 | // For DoS prevention, do not blindly allocate as much as the stream claims to contain. |
| 687 | // Instead, allocate in 5MiB batches, so that an attacker actually needs to provide |
| 688 | // X MiB of data to make us allocate X+5 Mib. |
| 689 | static_assert(sizeof(typename V::value_type) <= MAX_VECTOR_ALLOCATE, "Vector element size too large"); |
| 690 | allocated = std::min(size, allocated + MAX_VECTOR_ALLOCATE / sizeof(typename V::value_type)); |
| 691 | v.reserve(allocated); |
| 692 | while (v.size() < allocated) { |
| 693 | v.emplace_back(); |
| 694 | formatter.Unser(s, v.back()); |
| 695 | } |
| 696 | } |
| 697 | }; |
| 698 | }; |
| 699 | |
| 700 | /** |
nothing calls this directly
no test coverage detected