On Thu, 11 Jun 2026 12:08:27 GMT, Casper Norrbin <[email protected]> wrote:
> Hi everyone, > > This fixes an overflow in `FlatArrayPayload::advance_index`. The method > advanced an array payload offset by multiplying two `int` values before > adding the result to a `ptrdiff_t`. For large flat arrays, the > backward-overlap path in `FlatArrayKlass::copy_array` can call > `advance_index(length - 1)`, and that multiplication can overflow before the > value is widened. > > The fix widens the operands before multiplying, so the offset adjustment is > computed in a `ptrdiff_t`. > > I also added a regression test that performs large overlapping copies on a > flat value array. Before the fix, the backward overlapping copy fails in > debug builds with an out-of-bounds assert. With the fix, both backward and > forward overlapping copies complete successfully. > > Testing: > - New test testing same-array flat copy behavior > - Tiers 1-3 > > --------- > - [x] I confirm that I make this contribution in accordance with the [OpenJDK > Interim AI Policy](https://openjdk.org/legal/ai). Marked as reviewed by jsjolen (no project role). test/hotspot/jtreg/runtime/valhalla/inlinetypes/FlatArrayLargeOverlapCopyTest.java line 40: > 38: > 39: public class FlatArrayLargeOverlapCopyTest { > 40: private static final int LENGTH = 290_000_000; Add a comment for why this particular value was chosen. ------------- PR Review: https://git.openjdk.org/valhalla/pull/2537#pullrequestreview-4476699920 PR Review Comment: https://git.openjdk.org/valhalla/pull/2537#discussion_r3395858580
