Skip to content

Commit 380e440

Browse files
author
Mike Pall
committed
Fix overflow of snapshot map offset.
Thanks to Yichun Zhang.
1 parent 3404183 commit 380e440

File tree

3 files changed

+12
-12
lines changed

3 files changed

+12
-12
lines changed

src/lj_jit.h

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -163,7 +163,7 @@ typedef struct MCLink {
163163

164164
/* Stack snapshot header. */
165165
typedef struct SnapShot {
166-
uint16_t mapofs; /* Offset into snapshot map. */
166+
uint32_t mapofs; /* Offset into snapshot map. */
167167
IRRef1 ref; /* First IR ref for this snapshot. */
168168
uint8_t nslots; /* Number of valid slots. */
169169
uint8_t topslot; /* Maximum frame extent. */
@@ -217,14 +217,12 @@ typedef enum {
217217
/* Trace object. */
218218
typedef struct GCtrace {
219219
GCHeader;
220-
uint8_t topslot; /* Top stack slot already checked to be allocated. */
221-
uint8_t linktype; /* Type of link. */
220+
uint16_t nsnap; /* Number of snapshots. */
222221
IRRef nins; /* Next IR instruction. Biased with REF_BIAS. */
223222
GCRef gclist;
224223
IRIns *ir; /* IR instructions/constants. Biased with REF_BIAS. */
225224
IRRef nk; /* Lowest IR constant. Biased with REF_BIAS. */
226-
uint16_t nsnap; /* Number of snapshots. */
227-
uint16_t nsnapmap; /* Number of snapshot map elements. */
225+
uint32_t nsnapmap; /* Number of snapshot map elements. */
228226
SnapShot *snap; /* Snapshot array. */
229227
SnapEntry *snapmap; /* Snapshot map. */
230228
GCRef startpt; /* Starting prototype. */
@@ -241,6 +239,8 @@ typedef struct GCtrace {
241239
TraceNo1 nextroot; /* Next root trace for same prototype. */
242240
TraceNo1 nextside; /* Next side trace of same root trace. */
243241
uint8_t sinktags; /* Trace has SINK tags. */
242+
uint8_t topslot; /* Top stack slot already checked to be allocated. */
243+
uint8_t linktype; /* Type of link. */
244244
uint8_t unused1;
245245
#ifdef LUAJIT_USE_GDBJIT
246246
void *gdbjit_entry; /* GDB JIT entry. */

src/lj_opt_loop.c

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -223,7 +223,7 @@ static void loop_subst_snap(jit_State *J, SnapShot *osnap,
223223
}
224224
J->guardemit.irt = 0;
225225
/* Setup new snapshot. */
226-
snap->mapofs = (uint16_t)nmapofs;
226+
snap->mapofs = (uint32_t)nmapofs;
227227
snap->ref = (IRRef1)J->cur.nins;
228228
snap->nslots = nslots;
229229
snap->topslot = osnap->topslot;
@@ -251,7 +251,7 @@ static void loop_subst_snap(jit_State *J, SnapShot *osnap,
251251
nmap += nn;
252252
while (omap < nextmap) /* Copy PC + frame links. */
253253
*nmap++ = *omap++;
254-
J->cur.nsnapmap = (uint16_t)(nmap - J->cur.snapmap);
254+
J->cur.nsnapmap = (uint32_t)(nmap - J->cur.snapmap);
255255
}
256256

257257
/* Unroll loop. */
@@ -362,7 +362,7 @@ static void loop_unroll(jit_State *J)
362362
}
363363
}
364364
if (!irt_isguard(J->guardemit)) /* Drop redundant snapshot. */
365-
J->cur.nsnapmap = (uint16_t)J->cur.snap[--J->cur.nsnap].mapofs;
365+
J->cur.nsnapmap = (uint32_t)J->cur.snap[--J->cur.nsnap].mapofs;
366366
lua_assert(J->cur.nsnapmap <= J->sizesnapmap);
367367
*psentinel = J->cur.snapmap[J->cur.snap[0].nent]; /* Restore PC. */
368368

@@ -376,7 +376,7 @@ static void loop_undo(jit_State *J, IRRef ins, SnapNo nsnap, MSize nsnapmap)
376376
SnapShot *snap = &J->cur.snap[nsnap-1];
377377
SnapEntry *map = J->cur.snapmap;
378378
map[snap->mapofs + snap->nent] = map[J->cur.snap[0].nent]; /* Restore PC. */
379-
J->cur.nsnapmap = (uint16_t)nsnapmap;
379+
J->cur.nsnapmap = (uint32_t)nsnapmap;
380380
J->cur.nsnap = nsnap;
381381
J->guardemit.irt = 0;
382382
lj_ir_rollback(J, ins);

src/lj_snap.c

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -129,12 +129,12 @@ static void snapshot_stack(jit_State *J, SnapShot *snap, MSize nsnapmap)
129129
p = &J->cur.snapmap[nsnapmap];
130130
nent = snapshot_slots(J, p, nslots);
131131
snap->topslot = (uint8_t)snapshot_framelinks(J, p + nent);
132-
snap->mapofs = (uint16_t)nsnapmap;
132+
snap->mapofs = (uint32_t)nsnapmap;
133133
snap->ref = (IRRef1)J->cur.nins;
134134
snap->nent = (uint8_t)nent;
135135
snap->nslots = (uint8_t)nslots;
136136
snap->count = 0;
137-
J->cur.nsnapmap = (uint16_t)(nsnapmap + nent + 1 + J->framedepth);
137+
J->cur.nsnapmap = (uint32_t)(nsnapmap + nent + 1 + J->framedepth);
138138
}
139139

140140
/* Add or merge a snapshot. */
@@ -294,7 +294,7 @@ void lj_snap_shrink(jit_State *J)
294294
snap->nent = (uint8_t)m;
295295
nlim = J->cur.nsnapmap - snap->mapofs - 1;
296296
while (n <= nlim) map[m++] = map[n++]; /* Move PC + frame links down. */
297-
J->cur.nsnapmap = (uint16_t)(snap->mapofs + m); /* Free up space in map. */
297+
J->cur.nsnapmap = (uint32_t)(snap->mapofs + m); /* Free up space in map. */
298298
}
299299

300300
/* -- Snapshot access ----------------------------------------------------- */

0 commit comments

Comments
 (0)