Preconditions of Update procedures were always true when Offset was 0.
The changes enable to protect from Update_Error when Offset is 0.

Tested on x86_64-pc-linux-gnu, committed on trunk

gcc/ada/

        * libgnat/i-cstrin.ads (Update): Update precondition.
diff --git a/gcc/ada/libgnat/i-cstrin.ads b/gcc/ada/libgnat/i-cstrin.ads
--- a/gcc/ada/libgnat/i-cstrin.ads
+++ b/gcc/ada/libgnat/i-cstrin.ads
@@ -120,7 +120,10 @@ is
    with
      Pre    =>
        Item /= Null_Ptr
-         and then (if Check then Offset <= Strlen (Item) - Chars'Length),
+         and then
+      (if Check then
+         Strlen (Item) <= size_t'Last - Offset
+           and then Strlen (Item) + Offset <= Chars'Length),
      Global => (In_Out => C_Memory);
 
    procedure Update
@@ -131,7 +134,10 @@ is
    with
      Pre    =>
        Item /= Null_Ptr
-         and then (if Check then Offset <= Strlen (Item) - Str'Length),
+         and then
+      (if Check then
+         Strlen (Item) <= size_t'Last - Offset
+           and then Strlen (Item) + Offset <= Str'Length),
      Global => (In_Out => C_Memory);
 
    Update_Error : exception;


Reply via email to