mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-08-31 17:55:23 +02:00
PointerWrap and the Do() overloads around it are how every savestate is
written and read, and had no direct coverage. Everything read back came off
disk, so the corrupt-input paths matter as much as the round trips.
Three bugs, all in the bounds checking added in 58d4759ceb:
1. sizeof(T) is not a lower bound on how many bytes an element serializes to.
It only holds for the types DoHelper_ writes out raw. A std::string is 32-40
bytes in memory and serializes to as few as five; a T* serializes to whatever
T::DoState() writes. So DoVector/DoList/DoSet/DoMap could reject a perfectly
valid savestate whenever count * sizeof(element) exceeded the bytes left in
the buffer. That is not hypothetical: pspFileSystem is serialized dead last
in SaveStart::DoState, and MetaFileSystem::DoState does Do(p, currentDir) on
a std::map<int, std::string>, so the check runs with only a few hundred bytes
remaining and claims 44 bytes per entry against roughly 22 actual. Added
SerializeMinElemSize<T>(), mirroring DoHelper_'s own condition, and used it
in all five containers. The bound is only loosened, so nothing that loaded
before can stop loading.
2. Do(p, std::map<K, T *> &) deletes every value before reading the new ones,
and DoMap then returned on a bad count without clearing - leaving the map
full of freed pointers to be used or deleted again. Six live maps go through
this (sceMpeg, sceMp3, sceAac, sceFont, sceHeap, sceKernelThread's pending
calls), so a corrupt savestate meant a use-after-free. Clear before the guard
can bail out, in DoMap, DoMultimap and DoSet.
3. The wstring and u16string overloads validated stringLen < 0 but not 0, and
didn't require a whole number of characters. read() computes
stringLen / sizeof(char) - 1, so a length of 0 resized to SIZE_MAX and
memcpy'd with a wrapped-around size. PSPOskDialog::DoState serializes both
(inputChars at v2, a legacy wstring below that), so this was reachable: the
test aborts the process without the fix.
The test covers round trips of PODs, strings (empty, embedded NUL), vector,
map, set, list and map-of-pointers, section titles and version gating in both
directions, marker mismatches, measure-vs-write checkpoint disagreement, the
error latch dropping to MODE_NOOP, every truncation of a valid buffer, and
hand-corrupted counts and lengths.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GZq8ZtJmFY7bkX5FVkr3P9
117 lines
3.1 KiB
C++
117 lines
3.1 KiB
C++
// Copyright (C) 2003 Dolphin Project.
|
|
|
|
// This program is free software: you can redistribute it and/or modify
|
|
// it under the terms of the GNU General Public License as published by
|
|
// the Free Software Foundation, version 2.0 or later versions.
|
|
|
|
// This program is distributed in the hope that it will be useful,
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
// GNU General Public License 2.0 for more details.
|
|
|
|
// A copy of the GPL 2.0 should have been included with the program.
|
|
// If not, see http://www.gnu.org/licenses/
|
|
|
|
// Official SVN repository and contact information can be found at
|
|
// http://code.google.com/p/dolphin-emu/
|
|
|
|
#pragma once
|
|
|
|
// Templates for save state serialization. See Serializer.h.
|
|
#include <list>
|
|
#include "Common/Serialize/SerializeFuncs.h"
|
|
|
|
template<class T>
|
|
void DoList(PointerWrap &p, std::list<T> &x, T &default_val) {
|
|
u32 list_size = (u32)x.size();
|
|
Do(p, list_size);
|
|
// Guard against an attacker-controlled size driving a huge resize, same as DoVector.
|
|
if (p.mode == PointerWrap::MODE_READ || p.mode == PointerWrap::MODE_VERIFY) {
|
|
if (list_size > p.Remaining() / SerializeMinElemSize<T>()) {
|
|
p.SetError(PointerWrap::ERROR_FAILURE);
|
|
return;
|
|
}
|
|
}
|
|
x.resize(list_size, default_val);
|
|
|
|
for (T &elem : x)
|
|
Do(p, elem);
|
|
}
|
|
|
|
template<class T>
|
|
void Do(PointerWrap &p, std::list<T *> &x) {
|
|
T *dv = nullptr;
|
|
Do(p, x, dv);
|
|
}
|
|
|
|
template<class T>
|
|
void Do(PointerWrap &p, std::list<T> &x) {
|
|
T dv = T();
|
|
DoList(p, x, dv);
|
|
}
|
|
|
|
template<class T>
|
|
void Do(PointerWrap &p, std::list<T> &x, T &default_val) {
|
|
DoList(p, x, default_val);
|
|
}
|
|
|
|
template<class T, LinkedListItem<T> *(*TNew)(), void (*TFree)(LinkedListItem<T> *), void (*TDo)(PointerWrap &, T *)>
|
|
void DoLinkedList(PointerWrap &p, LinkedListItem<T> *&list_start, LinkedListItem<T> **list_end = nullptr) {
|
|
LinkedListItem<T> *list_cur = list_start;
|
|
LinkedListItem<T> *prev = nullptr;
|
|
|
|
while (true) {
|
|
u8 shouldExist = (list_cur ? 1 : 0);
|
|
Do(p, shouldExist);
|
|
if (shouldExist == 1) {
|
|
LinkedListItem<T> *cur = list_cur ? list_cur : TNew();
|
|
TDo(p, (T *)cur);
|
|
if (!list_cur) {
|
|
if (p.mode == PointerWrap::MODE_READ) {
|
|
cur->next = 0;
|
|
list_cur = cur;
|
|
if (prev)
|
|
prev->next = cur;
|
|
else
|
|
list_start = cur;
|
|
} else {
|
|
TFree(cur);
|
|
continue;
|
|
}
|
|
}
|
|
} else {
|
|
if (shouldExist != 0) {
|
|
WARN_LOG(Log::SaveState, "Savestate failure: incorrect item marker %d", shouldExist);
|
|
p.SetError(p.ERROR_FAILURE);
|
|
}
|
|
if (p.mode == PointerWrap::MODE_READ) {
|
|
if (prev)
|
|
prev->next = nullptr;
|
|
if (list_end)
|
|
*list_end = prev;
|
|
if (list_cur) {
|
|
if (list_start == list_cur)
|
|
list_start = nullptr;
|
|
do {
|
|
LinkedListItem<T> *next = list_cur->next;
|
|
TFree(list_cur);
|
|
list_cur = next;
|
|
} while (list_cur);
|
|
}
|
|
}
|
|
break;
|
|
}
|
|
prev = list_cur;
|
|
list_cur = list_cur->next;
|
|
}
|
|
}
|
|
|
|
inline void DoIgnoreUnusedLinkedList(PointerWrap &p) {
|
|
u8 shouldExist = 0;
|
|
Do(p, shouldExist);
|
|
if (shouldExist) {
|
|
// We don't support this linked list and haven't used it forever.
|
|
p.SetError(p.ERROR_FAILURE);
|
|
}
|
|
}
|