From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from [87.239.111.99] (localhost [127.0.0.1]) by dev.tarantool.org (Postfix) with ESMTP id CB06A70A883; Sun, 26 Nov 2023 18:12:34 +0300 (MSK) DKIM-Filter: OpenDKIM Filter v2.11.0 dev.tarantool.org CB06A70A883 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tarantool.org; s=dev; t=1701011554; bh=YtW4TYch+4vV/eAkssY4mSOgYXHKbzAPjAi4s0p3QP0=; h=Date:To:References:In-Reply-To:Subject:List-Id:List-Unsubscribe: List-Archive:List-Post:List-Help:List-Subscribe:From:Reply-To: From; b=bUfD4FYMwqAAP/K5Y7euCDbSjUGvlHYaVFGm78yun/uaNkT7onBkmJ728uFehmSWM DAyd+ru9mqpIChJT1pMqGE6s/PWIag06hSZipJjAH2kgbSjE8Ib5WLkf5YxuqDiJNW UVUND2CO0BTDN9ZIpUtvpzB/hBmnwgIELAtAjZCU= Received: from smtp55.i.mail.ru (smtp55.i.mail.ru [95.163.41.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by dev.tarantool.org (Postfix) with ESMTPS id 614A16FA61 for ; Sun, 26 Nov 2023 18:12:33 +0300 (MSK) DKIM-Filter: OpenDKIM Filter v2.11.0 dev.tarantool.org 614A16FA61 Received: by smtp55.i.mail.ru with esmtpa (envelope-from ) id 1r7GoC-008dOR-0q; Sun, 26 Nov 2023 18:12:32 +0300 Message-ID: <4319a7ac-5bd3-4b25-b3ad-2a89d0ddc537@tarantool.org> Date: Sun, 26 Nov 2023 18:12:31 +0300 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird To: Maksim Kokryashkin , tarantool-patches@dev.tarantool.org, skaplun@tarantool.org, m.kokryashkin@tarantool.org References: <20231004125034.64110-1-max.kokryashkin@gmail.com> <20231004125034.64110-2-max.kokryashkin@gmail.com> Content-Language: en-US In-Reply-To: <20231004125034.64110-2-max.kokryashkin@gmail.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Mailru-Src: smtp X-4EC0790: 10 X-7564579A: 646B95376F6C166E X-77F55803: 4F1203BC0FB41BD91D460360092162747FECD3F9344D284EA950B8561DD176EE182A05F5380850409368A822B95F12B14240C6DAC0AF163F786AC77705064E9DED5E4FDB71B90D9A X-7FA49CB5: FF5795518A3D127A4AD6D5ED66289B5278DA827A17800CE7370F4F695FFFC24BEA1F7E6F0F101C67BD4B6F7A4D31EC0BCC500DACC3FED6E28638F802B75D45FF8AA50765F7900637205505A8D8EF484BEA1F7E6F0F101C6723150C8DA25C47586E58E00D9D99D84E1BDDB23E98D2D38B73AB1701401CD871D0AA408F356A3BE888AD796384C2A95ECC7F00164DA146DAFE8445B8C89999728AA50765F7900637CAEE156C82D3D7D9389733CBF5DBD5E9C8A9BA7A39EFB766F5D81C698A659EA7CC7F00164DA146DA9985D098DBDEAEC8ED96AA85C75E140D117882F4460429728AD0CFFFB425014E868A13BD56FB6657D81D268191BDAD3DC09775C1D3CA48CFBB339968D8EBD1C6BA3038C0950A5D36C8A9BA7A39EFB766D91E3A1F190DE8FDBA3038C0950A5D36D5E8D9A59859A8B6A69576E7C60DFDE476E601842F6C81A1F004C906525384303E02D724532EE2C3F43C7A68FF6260569E8FC8737B5C224936DA1BED736F9328E827F84554CEF50127C277FBC8AE2E8BA83251EDC214901ED5E8D9A59859A8B6816F06BAE7E44B0A089D37D7C0E48F6C5571747095F342E88FB05168BE4CE3AF X-C1DE0DAB: 0D63561A33F958A59350BF406783499AEEF5E017D126B486058869D06ED57F52F87CCE6106E1FC07E67D4AC08A07B9B064E7220B7C550592CB5012B2E24CD356 X-C8649E89: 1C3962B70DF3F0ADE00A9FD3E00BEEDF3FED46C3ACD6F73ED3581295AF09D3DF87807E0823442EA2ED31085941D9CD0AF7F820E7B07EA4CF6FA3B9B41E67CABB5F87910060C10F321C2936862EE1D89C37D3E2EDA44C04C1DDCE95BB4BF576A62A47D1427BC164A7801F1F4B6E615274F745CEBF3529287DA74DFFEFA5DC0E7F02C26D483E81D6BE0DBAE6F56676BC7117BB6831D7356A2DEC5B5AD62611EEC62B5AFB4261A09AF0 X-D57D3AED: 3ZO7eAau8CL7WIMRKs4sN3D3tLDjz0dLbV79QFUyzQ2Ujvy7cMT6pYYqY16iZVKkSc3dCLJ7zSJH7+u4VD18S7Vl4ZUrpaVfd2+vE6kuoey4m4VkSEu530nj6fImhcD4MUrOEAnl0W826KZ9Q+tr5ycPtXkTV4k65bRjmOUUP8cvGozZ33TWg5HZplvhhXbhDGzqmQDTd6OAevLeAnq3Ra9uf7zvY2zzsIhlcp/Y7m53TZgf2aB4JOg4gkr2biojNlZijCPCuzi3uCE1WE1u/Q== X-Mailru-Sender: C4F68CFF4024C8867DFDF7C7F2588458AF128C4059D6BE392EE12218683D51EFF3988C97BF8F0C60282EC151BADDC1D3523A6D01B4765B2DFB59E2DDD9FE06B14FA522850F29BC30B0DAF586E7D11B3E67EA787935ED9F1B X-Mras: Ok Subject: Re: [Tarantool-patches] [PATCH luajit v3 1/2] snap: check J->pc is within its proto bytecode X-BeenThere: tarantool-patches@dev.tarantool.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: Tarantool development patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , From: Sergey Bronnikov via Tarantool-patches Reply-To: Sergey Bronnikov Errors-To: tarantool-patches-bounces@dev.tarantool.org Sender: "Tarantool-patches" Hi, Maxim LGTM On 10/4/23 15:50, Maksim Kokryashkin wrote: > From: Mike Pall > > (cherry-picked from commit 5c46f47736f7609be407c88d531ecd1689d40a79) > > This commit adds an assertion to ensure that the `pc` of the > snapshot being made is located within the current prototype. > Violation of this assertion's condition may lead to all kinds > of buggy behavior on restoration from that snapshot, depending > on what is located in memory at the address under `pc`. > > NOTICE: This patch is only a part of the original commit, > and the other part is backported in the following commit. The > patch was split into two, so the test case becomes easier to > implement since it can now depend on this assertion instead > of memory layout. > > Maxim Kokryashkin: > * added the description for the problem > > Part of tarantool/tarantool#9145 > --- > src/lj_snap.c | 3 +++ > 1 file changed, 3 insertions(+) > > diff --git a/src/lj_snap.c b/src/lj_snap.c > index 6c5e5e53..3f0fccec 100644 > --- a/src/lj_snap.c > +++ b/src/lj_snap.c > @@ -115,6 +115,9 @@ static MSize snapshot_framelinks(jit_State *J, SnapEntry *map, uint8_t *topslot) > #else > MSize f = 0; > map[f++] = SNAP_MKPC(J->pc); /* The current PC is always the first entry. */ > + lj_assertJ(!J->pt || > + (J->pc >= proto_bc(J->pt) && > + J->pc < proto_bc(J->pt) + J->pt->sizebc), "bad snapshot PC"); > #endif > while (frame > lim) { /* Backwards traversal of all frames above base. */ > if (frame_islua(frame)) {