On Mon, 6 Jul 2026 05:17:20 GMT, David Holmes <[email protected]> wrote:
>> David CARLIER has updated the pull request incrementally with one additional >> commit since the last revision: >> >> 8387718: JVMTI GetLocal/SetLocal: slot bounds check overflows for >> long/double slots >> >> VM_BaseGetOrSetLocal bounds-checks the requested slot before touching the >> frame's StackValueCollection. For a long/double the value spans two slots, >> so >> the check adds an extra_slot of 1: _index + extra_slot >= >> method->max_locals(). >> When an agent passes slot == INT_MAX, _index + extra_slot signed-overflows >> to >> INT_MIN, which is below max_locals(), so the guard is bypassed and we go >> on to >> index locals->at(INT_MAX) -- out of bounds. That is an assertion failure in >> fastdebug and a SIGSEGV or silent corruption in product. >> >> Doing the arithmetic on the other side (_index >= method->max_locals() - >> extra_slot) avoids the overflow. The same check appears in both >> check_slot_type_lvt and check_slot_type_no_lvt, so both are fixed. > > This seems fine to me. Thanks for the test updates. I guess, we need @dholmes-ora to re-approve this in order to be integrated. ------------- PR Comment: https://git.openjdk.org/jdk/pull/31772#issuecomment-4998799196
