mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-08-31 09:45:24 +02:00
PointerWrap and the Do() overloads around it are how every savestate is
written and read, and had no direct coverage. Everything read back came off
disk, so the corrupt-input paths matter as much as the round trips.
Three bugs, all in the bounds checking added in 58d4759ceb:
1. sizeof(T) is not a lower bound on how many bytes an element serializes to.
It only holds for the types DoHelper_ writes out raw. A std::string is 32-40
bytes in memory and serializes to as few as five; a T* serializes to whatever
T::DoState() writes. So DoVector/DoList/DoSet/DoMap could reject a perfectly
valid savestate whenever count * sizeof(element) exceeded the bytes left in
the buffer. That is not hypothetical: pspFileSystem is serialized dead last
in SaveStart::DoState, and MetaFileSystem::DoState does Do(p, currentDir) on
a std::map<int, std::string>, so the check runs with only a few hundred bytes
remaining and claims 44 bytes per entry against roughly 22 actual. Added
SerializeMinElemSize<T>(), mirroring DoHelper_'s own condition, and used it
in all five containers. The bound is only loosened, so nothing that loaded
before can stop loading.
2. Do(p, std::map<K, T *> &) deletes every value before reading the new ones,
and DoMap then returned on a bad count without clearing - leaving the map
full of freed pointers to be used or deleted again. Six live maps go through
this (sceMpeg, sceMp3, sceAac, sceFont, sceHeap, sceKernelThread's pending
calls), so a corrupt savestate meant a use-after-free. Clear before the guard
can bail out, in DoMap, DoMultimap and DoSet.
3. The wstring and u16string overloads validated stringLen < 0 but not 0, and
didn't require a whole number of characters. read() computes
stringLen / sizeof(char) - 1, so a length of 0 resized to SIZE_MAX and
memcpy'd with a wrapped-around size. PSPOskDialog::DoState serializes both
(inputChars at v2, a legacy wstring below that), so this was reachable: the
test aborts the process without the fix.
The test covers round trips of PODs, strings (empty, embedded NUL), vector,
map, set, list and map-of-pointers, section titles and version gating in both
directions, marker mismatches, measure-vs-write checkpoint disagreement, the
error latch dropping to MODE_NOOP, every truncation of a valid buffer, and
hand-corrupted counts and lengths.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GZq8ZtJmFY7bkX5FVkr3P9
76 lines
2.0 KiB
C++
76 lines
2.0 KiB
C++
// Copyright (C) 2003 Dolphin Project.
|
|
|
|
// This program is free software: you can redistribute it and/or modify
|
|
// it under the terms of the GNU General Public License as published by
|
|
// the Free Software Foundation, version 2.0 or later versions.
|
|
|
|
// This program is distributed in the hope that it will be useful,
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
// GNU General Public License 2.0 for more details.
|
|
|
|
// A copy of the GPL 2.0 should have been included with the program.
|
|
// If not, see http://www.gnu.org/licenses/
|
|
|
|
// Official SVN repository and contact information can be found at
|
|
// http://code.google.com/p/dolphin-emu/
|
|
|
|
#pragma once
|
|
|
|
// Templates for save state serialization. See Serializer.h.
|
|
#include <set>
|
|
#include "Common/Serialize/SerializeFuncs.h"
|
|
|
|
template <class T>
|
|
void DoSet(PointerWrap &p, std::set<T> &x) {
|
|
unsigned int number = (unsigned int)x.size();
|
|
Do(p, number);
|
|
|
|
switch (p.mode) {
|
|
case PointerWrap::MODE_READ:
|
|
{
|
|
// Clear before the guard below can bail out: for a set of pointers, our caller has
|
|
// already deleted every element, so leaving them in place would be a use-after-free.
|
|
x.clear();
|
|
// Guard against an attacker-controlled count driving an enormous number of
|
|
// loop iterations/allocations, same spirit as DoVector's guard.
|
|
if (number > p.Remaining() / SerializeMinElemSize<T>()) {
|
|
p.SetError(PointerWrap::ERROR_FAILURE);
|
|
return;
|
|
}
|
|
while (number-- > 0) {
|
|
T it = T();
|
|
Do(p, it);
|
|
x.insert(it);
|
|
}
|
|
}
|
|
break;
|
|
case PointerWrap::MODE_WRITE:
|
|
case PointerWrap::MODE_MEASURE:
|
|
case PointerWrap::MODE_VERIFY:
|
|
{
|
|
typename std::set<T>::iterator itr = x.begin();
|
|
while (number-- > 0)
|
|
Do(p, *itr++);
|
|
}
|
|
break;
|
|
case PointerWrap::MODE_NOOP:
|
|
break;
|
|
}
|
|
}
|
|
|
|
template <class T>
|
|
void Do(PointerWrap &p, std::set<T *> &x) {
|
|
if (p.mode == PointerWrap::MODE_READ) {
|
|
for (T *s : x) {
|
|
delete s;
|
|
}
|
|
}
|
|
DoSet(p, x);
|
|
}
|
|
|
|
template <class T>
|
|
void Do(PointerWrap &p, std::set<T> &x) {
|
|
DoSet(p, x);
|
|
}
|