Patch: FYI: arraycopy fix
Tom Tromey
tromey@redhat.com
Wed Jul 23 15:31:00 GMT 2003
I'm checking this in on the trunk.
I've already added a new Mauve test for this.
This adds a couple more necessary checks to System.arraycopy.
Without these it was possible to fool arraycopy into an invalid copy.
For instance, this could happen if count was Integer.MAX_VALUE.
Tom
Index: ChangeLog
from Tom Tromey <tromey@redhat.com>
* java/lang/natSystem.cc (arraycopy): Check for overflow.
Index: java/lang/natSystem.cc
===================================================================
RCS file: /cvs/gcc/gcc/libjava/java/lang/natSystem.cc,v
retrieving revision 1.55
diff -u -r1.55 natSystem.cc
--- java/lang/natSystem.cc 19 Feb 2003 16:28:37 -0000 1.55
+++ java/lang/natSystem.cc 23 Jul 2003 15:29:17 -0000
@@ -66,8 +66,10 @@
__JArray *src_a = (__JArray *) src;
__JArray *dst_a = (__JArray *) dst;
if (src_offset < 0 || dst_offset < 0 || count < 0
- || src_offset + count > src_a->length
- || dst_offset + count > dst_a->length)
+ || (unsigned jint) src_offset > (unsigned jint) src_a->length
+ || (unsigned jint) (src_offset + count) > (unsigned jint) src_a->length
+ || (unsigned jint) dst_offset > (unsigned jint) dst_a->length
+ || (unsigned jint) (dst_offset + count) > (unsigned jint) dst_a->length)
throw new ArrayIndexOutOfBoundsException;
// Do-nothing cases.
More information about the Java-patches
mailing list