* alloc.c (allocate_vectorlike): Check for ptrdiff_t overflow.

2011-06-08 Paul Eggert <>
* alloc.c (Fmake_bool_vector): Don't assume vector size fits in int.
(allocate_vectorlike): Check for ptrdiff_t overflow.
* alloc.c: Catch some string size overflows that we were missing.
......@@ -2802,10 +2802,11 @@ allocate_vectorlike (EMACS_INT len)
struct Lisp_Vector *p;
size_t nbytes;
ptrdiff_t nbytes_max = min (PTRDIFF_MAX, SIZE_MAX);
int header_size = offsetof (struct Lisp_Vector, contents);
int word_size = sizeof p->contents[0];
if ((SIZE_MAX - header_size) / word_size < len)
if ((nbytes_max - header_size) / word_size < len)
memory_full (SIZE_MAX);
