On Thu, 11 Jun 2026 13:37:30 GMT, Casper Norrbin <[email protected]> wrote:
>> Hi everyone, >> >> This fixes an overflow in `FlatArrayPayload::advance_index`. The method >> advanced an array payload offset by multiplying two `int` values before >> adding the result to a `ptrdiff_t`. For large flat arrays, the >> backward-overlap path in `FlatArrayKlass::copy_array` can call >> `advance_index(length - 1)`, and that multiplication can overflow before the >> value is widened. >> >> The fix widens the operands before multiplying, so the offset adjustment is >> computed in a `ptrdiff_t`. >> >> I also added a regression test that performs large overlapping copies on a >> flat value array. Before the fix, the backward overlapping copy fails in >> debug builds with an out-of-bounds assert. With the fix, both backward and >> forward overlapping copies complete successfully. >> >> Testing: >> - New test testing same-array flat copy behavior >> - Tiers 1-3 >> >> --------- >> - [x] I confirm that I make this contribution in accordance with the >> [OpenJDK Interim AI Policy](https://openjdk.org/legal/ai). > > Casper Norrbin has updated the pull request incrementally with one additional > commit since the last revision: > > added length test comment I agree that we need larger types for the calculation in `FlatArrayPayload::advance_index`. However, we could change the type of `FlatArrayPayload::Storage::_element_size` to `ptrdiff_t` since we only seem to use it that way now. I'm fine with us addressing that in a follow-up. Also the test does use a non-trivial amount of memory, but I think the array being ~2200MB is reasonable and shouldn't clash with other tests running concurrently. ------------- Marked as reviewed by jsikstro (Committer). PR Review: https://git.openjdk.org/valhalla/pull/2537#pullrequestreview-4483188922
