macOS: Fix crash on out-of-bounds text input ranges (#191780)
`TextInputModel` assumes its selection and composing range fall within its text, but nothing in the text input plugin enforced that. When they don't, we index past the end of `text_` which triggers an abort due to out of range access. Previously, `setMarkedText:selectedRange:replacementRange:` passed `selectedRange` unvalidated. IMEs report `NSNotFound` to indicate no selection within the mark text. That maps to `NSIntegerMax` rather than an offset, and we incorrectly stored that as the selection. Clearing the marked text collapses the composing range, so the next update replaces the selection instead and calls `replace` with a position `NSIntegerMax`. Clear and re-mark is what an input method emits when the input source is switched mid-composition. `SetText` was also unsafe: it assigned `text_` before validating the ranges, so a rejected update left us with the new text but the old (now out-of-bounds) ranges still pointing into it. This fixes that by clamping both ranges before any operation that indexes the text, applying either all of `SetText`'s fields or none, and clamping `selectedRange` and `replacementRange` in the plugin. `setMarkedText:` also null-checks the UTF-16 buffer, which `cStringUsingEncoding:` can return as nullptr. Fixes: https://github.com/flutter/flutter/issues/190704 <!-- Thanks for filing a pull request! Reviewers are typically assigned within a week of filing a request. To learn more about code review, see our documentation on Tree Hygiene: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md --> ## Pre-launch Checklist - [X] I read the [Contributor Guide] and followed the process outlined there for submitting PRs. - [X] I read the [AI contribution guidelines] and understand my responsibilities, or I am not using AI tools. - [X] I read the [Tree Hygiene] wiki page, which explains my responsibilities. - [X] I read and followed the [Flutter Style Guide], including [Features we expect every widget to implement]. - [X] I signed the [CLA]. - [X] I listed at least one issue that this PR fixes in the description above. - [X] I updated/added relevant documentation (doc comments with `///`). - [X] I added new tests to check the change I am making, or this PR is [test-exempt]. - [X] I followed the [breaking change policy] and added [Data Driven Fixes] where supported. - [X] All existing and new tests are passing. If you need help, consider asking for advice on the #hackers-new channel on [Discord]. If this change needs to override an active code freeze, provide a comment explaining why. The code freeze workflow can be overridden by code reviewers. See pinned issues for any active code freezes with guidance. **Note**: The Flutter team is currently trialing the use of [Gemini Code Assist for GitHub](https://developers.google.com/gemini-code-assist/docs/review-github-code). Comments from the `gemini-code-assist` bot should not be taken as authoritative feedback from the Flutter team. If you find its comments useful you can update your code accordingly, but if you are unsure or disagree with the feedback, please feel free to wait for a Flutter team member's review for guidance on which automated comments should be addressed. <!-- Links --> [Contributor Guide]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#overview [AI contribution guidelines]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#ai-contribution-guidelines [Tree Hygiene]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md [test-exempt]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#tests [Flutter Style Guide]: https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md [Features we expect every widget to implement]: https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md#features-we-expect-every-widget-to-implement [CLA]: https://cla.developers.google.com/ [flutter/tests]: https://github.com/flutter/tests [breaking change policy]: https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#handling-breaking-changes [Discord]: https://github.com/flutter/flutter/blob/main/docs/contributing/Chat.md [Data Driven Fixes]: https://github.com/flutter/flutter/blob/main/docs/contributing/Data-driven-Fixes.md
C
Chris Bracken committed
e100f30e696bf44a5cdd538cd4c2fce62795252f
Parent: 0a42304
Committed by GitHub <noreply@github.com>
on 8/27/2026, 12:38:35 AM