SIGN IN SIGN UP

macOS: Fix crash on out-of-bounds text input ranges (#191780)

`TextInputModel` assumes its selection and composing range fall within
its text, but nothing in the text input plugin enforced that. When they
don't, we index past the end of `text_` which triggers an abort due to
out of range access.

Previously, `setMarkedText:selectedRange:replacementRange:` passed
`selectedRange` unvalidated. IMEs report `NSNotFound` to indicate no
selection within the mark text. That maps to `NSIntegerMax` rather than
an offset, and we incorrectly stored that as the selection. Clearing the
marked text collapses the composing range, so the next update replaces
the selection instead and calls `replace` with a position
`NSIntegerMax`. Clear and re-mark is what an input method emits when the
input source is switched mid-composition.

`SetText` was also unsafe: it assigned `text_` before validating the
ranges, so a rejected update left us with the new text but the old (now
out-of-bounds) ranges still pointing into it.

This fixes that by clamping both ranges before any operation that
indexes the text, applying either all of `SetText`'s fields or none, and
clamping `selectedRange` and `replacementRange` in the plugin.
`setMarkedText:` also null-checks the UTF-16 buffer, which
`cStringUsingEncoding:` can return as nullptr.

Fixes: https://github.com/flutter/flutter/issues/190704

<!--
Thanks for filing a pull request!
Reviewers are typically assigned within a week of filing a request.
To learn more about code review, see our documentation on Tree Hygiene:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md
-->


## Pre-launch Checklist

- [X] I read the [Contributor Guide] and followed the process outlined
there for submitting PRs.
- [X] I read the [AI contribution guidelines] and understand my
responsibilities, or I am not using AI tools.
- [X] I read the [Tree Hygiene] wiki page, which explains my
responsibilities.
- [X] I read and followed the [Flutter Style Guide], including [Features
we expect every widget to implement].
- [X] I signed the [CLA].
- [X] I listed at least one issue that this PR fixes in the description
above.
- [X] I updated/added relevant documentation (doc comments with `///`).
- [X] I added new tests to check the change I am making, or this PR is
[test-exempt].
- [X] I followed the [breaking change policy] and added [Data Driven
Fixes] where supported.
- [X] All existing and new tests are passing.

If you need help, consider asking for advice on the #hackers-new channel
on [Discord].

If this change needs to override an active code freeze, provide a
comment explaining why. The code freeze workflow can be overridden by
code reviewers. See pinned issues for any active code freezes with
guidance.

**Note**: The Flutter team is currently trialing the use of [Gemini Code
Assist for
GitHub](https://developers.google.com/gemini-code-assist/docs/review-github-code).
Comments from the `gemini-code-assist` bot should not be taken as
authoritative feedback from the Flutter team. If you find its comments
useful you can update your code accordingly, but if you are unsure or
disagree with the feedback, please feel free to wait for a Flutter team
member's review for guidance on which automated comments should be
addressed.

<!-- Links -->
[Contributor Guide]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#overview
[AI contribution guidelines]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#ai-contribution-guidelines
[Tree Hygiene]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md
[test-exempt]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#tests
[Flutter Style Guide]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md
[Features we expect every widget to implement]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Style-guide-for-Flutter-repo.md#features-we-expect-every-widget-to-implement
[CLA]: https://cla.developers.google.com/
[flutter/tests]: https://github.com/flutter/tests
[breaking change policy]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Tree-hygiene.md#handling-breaking-changes
[Discord]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Chat.md
[Data Driven Fixes]:
https://github.com/flutter/flutter/blob/main/docs/contributing/Data-driven-Fixes.md
C
Chris Bracken committed
e100f30e696bf44a5cdd538cd4c2fce62795252f
Parent: 0a42304
Committed by GitHub <noreply@github.com> on 8/27/2026, 12:38:35 AM