Skip to content

Commit

Permalink
Memory flattening: Check for overflow (WebAssembly#6233)
Browse files Browse the repository at this point in the history
Fixes a fuzz testcase for wasm-ctor-eval.

Add the beginnings of a polyfill for stdckdint.h to help that.
  • Loading branch information
kripken committed Jan 24, 2024
1 parent 1ce851d commit 6453fd5
Show file tree
Hide file tree
Showing 3 changed files with 65 additions and 1 deletion.
7 changes: 6 additions & 1 deletion src/ir/memory-utils.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,7 @@
*/

#include "ir/memory-utils.h"
#include "support/stdckdint.h"
#include "wasm.h"

namespace wasm::MemoryUtils {
Expand Down Expand Up @@ -94,7 +95,11 @@ bool flatten(Module& wasm) {
for (auto& segment : dataSegments) {
auto* offset = segment->offset->dynCast<Const>();
Index start = offset->value.getInteger();
Index end = start + segment->data.size();
Index size = segment->data.size();
Index end;
if (std::ckd_add(&end, start, size)) {
return false;
}
if (end > data.size()) {
data.resize(end);
}
Expand Down
43 changes: 43 additions & 0 deletions src/support/stdckdint.h
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
/*
* Copyright 2024 WebAssembly Community Group participants
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/

#ifndef wasm_stdckdint_h
#define wasm_stdckdint_h

// This is a partial "polyfill" for the C23 file stdckdint.h. It allows us to
// use that API even in older compilers.

namespace std {

template<typename T> bool ckd_add(T* output, T a, T b) {
#if __has_builtin(__builtin_add_overflow)
return __builtin_add_overflow(a, b, output);
#else
// Atm this polyfill only supports unsigned types.
static_assert(std::is_unsigned_v<T>);

T result = a + b;
if (result < a) {
return true;
}
*output = result;
return false;
#endif
}

} // namespace std

#endif // wasm_stdckdint_h
16 changes: 16 additions & 0 deletions test/lit/ctor-eval/flatten_overflow.wast
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
;; The data segment here is at an offset too large to fit into the memory due
;; to an overflow. That will cause us to fail during flatten, so there are no
;; changes to output here, but we should not error (if we don't check for
;; overflow, we'd segfault).

;; RUN: wasm-ctor-eval %s --ctors=test --kept-exports=test --quiet -all

(module
(memory $0 10 10)
(data $0 (i32.const -1) "a")

(export "test" (func $test))

(func $test
)
)

0 comments on commit 6453fd5

Please sign in to comment.