Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

8266626: Check that the target address of a native call is not NULL #530

Closed
Closed
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
@@ -168,7 +168,8 @@ static CLinker getInstance() {
* @param type the method type.
* @param function the function descriptor.
* @return the downcall method handle.
* @throws IllegalArgumentException in the case of a method type and function descriptor mismatch.
* @throws IllegalArgumentException in the case of a method type and function descriptor mismatch, or if the symbol
* is {@link MemoryAddress#NULL}
Copy link
Collaborator

@mcimadamore mcimadamore May 10, 2021

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Is the indentation deliberate? What about NPE?

Copy link
Member Author

@JornVernee JornVernee May 10, 2021

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, the indentation is deliberate.

I'll add the NPE as well, looks like that was missing from before.

Copy link
Member Author

@JornVernee JornVernee May 10, 2021

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actually, I think the NPE is covered by this comment on the class

 * <p> Unless otherwise specified, passing a {@code null} argument, or an array argument containing one or more {@code null}
 * elements to a method in this class causes a {@link NullPointerException NullPointerException} to be thrown. </p>

Copy link
Collaborator

@mcimadamore mcimadamore May 10, 2021

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ah true

*/
MethodHandle downcallHandle(Addressable symbol, SegmentAllocator allocator, MethodType type, FunctionDescriptor function);

@@ -182,6 +183,9 @@ static CLinker getInstance() {
* additional prefix parameter (inserted immediately after the address parameter), of type {@link SegmentAllocator}),
* which will be used by the linker runtime to allocate structs returned by-value.
* <p>
* The returned method handle will throw an {@link IllegalArgumentException} if the target address passed to it is
* {@link MemoryAddress#NULL}, or a {@link NullPointerException} if the target address is {@code null}.
* <p>
* This method is <a href="package-summary.html#restricted"><em>restricted</em></a>.
* Restricted method are unsafe, and, if used incorrectly, their use might crash
* the JVM or, worse, silently result in memory corruption. Thus, clients should refrain from depending on
@@ -30,6 +30,7 @@
import jdk.incubator.foreign.FunctionDescriptor;
import jdk.incubator.foreign.MemorySegment;
import jdk.incubator.foreign.SegmentAllocator;
import jdk.internal.foreign.abi.SharedUtils;
import jdk.internal.reflect.CallerSensitive;
import jdk.internal.reflect.Reflection;

@@ -39,17 +40,18 @@
import java.util.Objects;

public abstract class AbstractCLinker implements CLinker {

@CallerSensitive
public final MethodHandle downcallHandle(Addressable symbol, MethodType type, FunctionDescriptor function) {
Reflection.ensureNativeAccess(Reflection.getCallerClass());
Objects.requireNonNull(symbol);
SharedUtils.checkSymbol(symbol);
return MethodHandles.insertArguments(downcallHandle(type, function), 0, symbol);
}

@CallerSensitive
public final MethodHandle downcallHandle(Addressable symbol, SegmentAllocator allocator, MethodType type, FunctionDescriptor function) {
Reflection.ensureNativeAccess(Reflection.getCallerClass());
Objects.requireNonNull(symbol);
SharedUtils.checkSymbol(symbol);
Objects.requireNonNull(allocator);
MethodHandle downcall = MethodHandles.insertArguments(downcallHandle(type, function), 0, symbol);
if (type.returnType().equals(MemorySegment.class)) {
@@ -90,11 +90,7 @@ public class ProgrammableInvoker {
methodType(Object.class, Addressable.class, SegmentAllocator.class, Object[].class, MethodHandle.class, Map.class, Map.class));
MH_WRAP_ALLOCATOR = lookup.findStatic(Binding.Context.class, "ofAllocator",
methodType(Binding.Context.class, SegmentAllocator.class));
MethodHandle MH_Addressable_address = lookup.findVirtual(Addressable.class, "address",
methodType(MemoryAddress.class));
MethodHandle MH_MemoryAddress_toRawLongValue = lookup.findVirtual(MemoryAddress.class, "toRawLongValue",
methodType(long.class));
MH_ADDR_TO_LONG = filterArguments(MH_MemoryAddress_toRawLongValue, 0, MH_Addressable_address);
MH_ADDR_TO_LONG = lookup.findStatic(ProgrammableInvoker.class, "unboxTargetAddress", methodType(long.class, Addressable.class));
} catch (ReflectiveOperationException e) {
throw new RuntimeException(e);
}
@@ -176,6 +172,11 @@ public MethodHandle getBoundMethodHandle() {
return handle;
}

private static long unboxTargetAddress(Addressable addr) {
MemoryAddress ma = SharedUtils.checkSymbol(addr);
return ma.toRawLongValue();
}

// Funnel from type to Object[]
private static MethodHandle makeCollectorHandle(MethodType type) {
return type.parameterCount() == 0
@@ -53,6 +53,7 @@
import java.nio.charset.Charset;
import java.util.List;
import java.util.Map;
import java.util.Objects;
import java.util.function.Consumer;
import java.util.stream.Collectors;
import java.util.stream.IntStream;
@@ -412,6 +413,14 @@ static MethodHandle wrapWithAllocator(MethodHandle specializedHandle,
return specializedHandle;
}

public static MemoryAddress checkSymbol(Addressable symbol) {
Objects.requireNonNull(symbol);
MemoryAddress symbolAddr = symbol.address();
if (symbolAddr.equals(MemoryAddress.NULL))
throw new IllegalArgumentException("Symbol is NULL: " + symbolAddr);
return symbolAddr;
}

// lazy init MH_ALLOC and MH_FREE handles
private static class AllocHolder {

@@ -45,7 +45,7 @@

public class TestIllegalLink {

private static final MemoryAddress dummyTarget = MemoryAddress.NULL;
private static final MemoryAddress dummyTarget = MemoryAddress.ofLong(1);
private static final CLinker ABI = CLinker.getInstance();

@Test(dataProvider = "types")
@@ -0,0 +1,61 @@
/*
* Copyright (c) 2021, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/

/*
* @test
* @requires ((os.arch == "amd64" | os.arch == "x86_64") & sun.arch.data.model == "64") | os.arch == "aarch64"
* @modules jdk.incubator.foreign
* @run testng/othervm
* --enable-native-access=ALL-UNNAMED
* TestNULLTarget
*/

import jdk.incubator.foreign.Addressable;
import jdk.incubator.foreign.CLinker;
import jdk.incubator.foreign.FunctionDescriptor;
import jdk.incubator.foreign.MemoryAddress;
import org.testng.annotations.Test;

import java.lang.invoke.MethodHandle;
import java.lang.invoke.MethodType;

public class TestNULLTarget {

static final CLinker LINKER = CLinker.getInstance();

@Test(expectedExceptions = IllegalArgumentException.class)
public void testNULLLinking() {
LINKER.downcallHandle(
MemoryAddress.NULL,
MethodType.methodType(void.class),
FunctionDescriptor.ofVoid());
}

@Test(expectedExceptions = IllegalArgumentException.class)
public void testNULLVirtual() throws Throwable {
MethodHandle mh = LINKER.downcallHandle(
MethodType.methodType(void.class),
FunctionDescriptor.ofVoid());
mh.invokeExact((Addressable) MemoryAddress.NULL);
}
}
@@ -145,8 +145,8 @@ static <Z> void addDefaultMapping(Class<Z> carrier, Z value) {
addDefaultMapping(Charset.class, Charset.defaultCharset());
addDefaultMapping(Consumer.class, x -> {});
addDefaultMapping(MethodType.class, MethodType.methodType(void.class));
addDefaultMapping(MemoryAddress.class, MemoryAddress.NULL);
addDefaultMapping(Addressable.class, MemoryAddress.NULL);
addDefaultMapping(MemoryAddress.class, MemoryAddress.ofLong(1));
addDefaultMapping(Addressable.class, MemoryAddress.ofLong(1));
addDefaultMapping(MemoryLayout.class, MemoryLayouts.JAVA_INT);
addDefaultMapping(ValueLayout.class, MemoryLayouts.JAVA_INT);
addDefaultMapping(GroupLayout.class, MemoryLayout.structLayout(MemoryLayouts.JAVA_INT));
@@ -70,4 +70,9 @@ public void testVirtualCalls() throws Throwable {
assertEquals((int) func.invokeExact((Addressable) funcC), 3);
}

@Test(expectedExceptions = NullPointerException.class)
public void testNullTarget() throws Throwable {
int x = (int) func.invokeExact((Addressable) null);
}

}