mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-08-31 17:55:23 +02:00
PointerWrap and the Do() overloads around it are how every savestate is
written and read, and had no direct coverage. Everything read back came off
disk, so the corrupt-input paths matter as much as the round trips.
Three bugs, all in the bounds checking added in 58d4759ceb:
1. sizeof(T) is not a lower bound on how many bytes an element serializes to.
It only holds for the types DoHelper_ writes out raw. A std::string is 32-40
bytes in memory and serializes to as few as five; a T* serializes to whatever
T::DoState() writes. So DoVector/DoList/DoSet/DoMap could reject a perfectly
valid savestate whenever count * sizeof(element) exceeded the bytes left in
the buffer. That is not hypothetical: pspFileSystem is serialized dead last
in SaveStart::DoState, and MetaFileSystem::DoState does Do(p, currentDir) on
a std::map<int, std::string>, so the check runs with only a few hundred bytes
remaining and claims 44 bytes per entry against roughly 22 actual. Added
SerializeMinElemSize<T>(), mirroring DoHelper_'s own condition, and used it
in all five containers. The bound is only loosened, so nothing that loaded
before can stop loading.
2. Do(p, std::map<K, T *> &) deletes every value before reading the new ones,
and DoMap then returned on a bad count without clearing - leaving the map
full of freed pointers to be used or deleted again. Six live maps go through
this (sceMpeg, sceMp3, sceAac, sceFont, sceHeap, sceKernelThread's pending
calls), so a corrupt savestate meant a use-after-free. Clear before the guard
can bail out, in DoMap, DoMultimap and DoSet.
3. The wstring and u16string overloads validated stringLen < 0 but not 0, and
didn't require a whole number of characters. read() computes
stringLen / sizeof(char) - 1, so a length of 0 resized to SIZE_MAX and
memcpy'd with a wrapped-around size. PSPOskDialog::DoState serializes both
(inputChars at v2, a legacy wstring below that), so this was reachable: the
test aborts the process without the fix.
The test covers round trips of PODs, strings (empty, embedded NUL), vector,
map, set, list and map-of-pointers, section titles and version gating in both
directions, marker mismatches, measure-vs-write checkpoint disagreement, the
error latch dropping to MODE_NOOP, every truncation of a valid buffer, and
hand-corrupted counts and lengths.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01GZq8ZtJmFY7bkX5FVkr3P9
183 lines
4.7 KiB
C++
183 lines
4.7 KiB
C++
// Copyright (C) 2003 Dolphin Project.
|
|
|
|
// This program is free software: you can redistribute it and/or modify
|
|
// it under the terms of the GNU General Public License as published by
|
|
// the Free Software Foundation, version 2.0 or later versions.
|
|
|
|
// This program is distributed in the hope that it will be useful,
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
// GNU General Public License 2.0 for more details.
|
|
|
|
// A copy of the GPL 2.0 should have been included with the program.
|
|
// If not, see http://www.gnu.org/licenses/
|
|
|
|
// Official SVN repository and contact information can be found at
|
|
// http://code.google.com/p/dolphin-emu/
|
|
|
|
#pragma once
|
|
|
|
// Templates for save state serialization. See Serializer.h.
|
|
#include <map>
|
|
#include <unordered_map>
|
|
#include "Common/Serialize/SerializeFuncs.h"
|
|
|
|
template<class M>
|
|
void DoMap(PointerWrap &p, M &x, typename M::mapped_type &default_val) {
|
|
unsigned int number = (unsigned int)x.size();
|
|
Do(p, number);
|
|
switch (p.mode) {
|
|
case PointerWrap::MODE_READ:
|
|
{
|
|
// Clear before the guard below can bail out: for a map of pointers, our caller has
|
|
// already deleted every value, so leaving them in place would be a use-after-free.
|
|
x.clear();
|
|
// Guard against an attacker-controlled count driving an enormous number of
|
|
// loop iterations/allocations, same spirit as DoVector's guard.
|
|
constexpr size_t minElemSize = SerializeMinElemSize<typename M::key_type>() + SerializeMinElemSize<typename M::mapped_type>();
|
|
if (number > p.Remaining() / minElemSize) {
|
|
p.SetError(PointerWrap::ERROR_FAILURE);
|
|
return;
|
|
}
|
|
while (number > 0) {
|
|
typename M::key_type first = typename M::key_type();
|
|
Do(p, first);
|
|
typename M::mapped_type second = default_val;
|
|
Do(p, second);
|
|
x[first] = second;
|
|
--number;
|
|
}
|
|
break;
|
|
}
|
|
case PointerWrap::MODE_WRITE:
|
|
case PointerWrap::MODE_MEASURE:
|
|
case PointerWrap::MODE_VERIFY:
|
|
{
|
|
typename M::iterator itr = x.begin();
|
|
while (number > 0) {
|
|
typename M::key_type first = itr->first;
|
|
Do(p, first);
|
|
Do(p, itr->second);
|
|
--number;
|
|
++itr;
|
|
}
|
|
break;
|
|
}
|
|
case PointerWrap::MODE_NOOP:
|
|
break;
|
|
}
|
|
}
|
|
|
|
template<class K, class T>
|
|
void Do(PointerWrap &p, std::map<K, T *> &x) {
|
|
if (p.mode == PointerWrap::MODE_READ) {
|
|
for (auto &iter : x) {
|
|
delete iter.second;
|
|
}
|
|
}
|
|
T *dv = nullptr;
|
|
DoMap(p, x, dv);
|
|
}
|
|
|
|
template<class K, class T>
|
|
void Do(PointerWrap &p, std::map<K, T> &x) {
|
|
T dv = T();
|
|
DoMap(p, x, dv);
|
|
}
|
|
|
|
template<class K, class T>
|
|
void Do(PointerWrap &p, std::unordered_map<K, T *> &x) {
|
|
if (p.mode == PointerWrap::MODE_READ) {
|
|
for (auto &iter : x) {
|
|
delete iter.second;
|
|
}
|
|
}
|
|
T *dv = nullptr;
|
|
DoMap(p, x, dv);
|
|
}
|
|
|
|
template<class K, class T>
|
|
void Do(PointerWrap &p, std::unordered_map<K, T> &x) {
|
|
T dv = T();
|
|
DoMap(p, x, dv);
|
|
}
|
|
|
|
template<class M>
|
|
void DoMultimap(PointerWrap &p, M &x, typename M::mapped_type &default_val) {
|
|
unsigned int number = (unsigned int)x.size();
|
|
Do(p, number);
|
|
switch (p.mode) {
|
|
case PointerWrap::MODE_READ:
|
|
{
|
|
// Clear before the guard below can bail out: for a map of pointers, our caller has
|
|
// already deleted every value, so leaving them in place would be a use-after-free.
|
|
x.clear();
|
|
// Guard against an attacker-controlled count driving an enormous number of
|
|
// loop iterations/allocations, same spirit as DoVector's guard.
|
|
constexpr size_t minElemSize = SerializeMinElemSize<typename M::key_type>() + SerializeMinElemSize<typename M::mapped_type>();
|
|
if (number > p.Remaining() / minElemSize) {
|
|
p.SetError(PointerWrap::ERROR_FAILURE);
|
|
return;
|
|
}
|
|
while (number > 0) {
|
|
typename M::key_type first = typename M::key_type();
|
|
Do(p, first);
|
|
typename M::mapped_type second = default_val;
|
|
Do(p, second);
|
|
x.insert(std::make_pair(first, second));
|
|
--number;
|
|
}
|
|
break;
|
|
}
|
|
case PointerWrap::MODE_WRITE:
|
|
case PointerWrap::MODE_MEASURE:
|
|
case PointerWrap::MODE_VERIFY:
|
|
{
|
|
typename M::iterator itr = x.begin();
|
|
while (number > 0) {
|
|
Do(p, itr->first);
|
|
Do(p, itr->second);
|
|
--number;
|
|
++itr;
|
|
}
|
|
break;
|
|
}
|
|
case PointerWrap::MODE_NOOP:
|
|
break;
|
|
}
|
|
}
|
|
|
|
template<class K, class T>
|
|
void Do(PointerWrap &p, std::multimap<K, T *> &x) {
|
|
if (p.mode == PointerWrap::MODE_READ) {
|
|
for (auto &iter : x) {
|
|
delete iter.second;
|
|
}
|
|
}
|
|
T *dv = nullptr;
|
|
DoMultimap(p, x, dv);
|
|
}
|
|
|
|
template<class K, class T>
|
|
void Do(PointerWrap &p, std::multimap<K, T> &x) {
|
|
T dv = T();
|
|
DoMultimap(p, x, dv);
|
|
}
|
|
|
|
template<class K, class T>
|
|
void Do(PointerWrap &p, std::unordered_multimap<K, T *> &x) {
|
|
if (p.mode == PointerWrap::MODE_READ) {
|
|
for (auto &iter : x) {
|
|
delete iter.second;
|
|
}
|
|
}
|
|
T *dv = nullptr;
|
|
DoMultimap(p, x, dv);
|
|
}
|
|
|
|
template<class K, class T>
|
|
void Do(PointerWrap &p, std::unordered_multimap<K, T> &x) {
|
|
T dv = T();
|
|
DoMultimap(p, x, dv);
|
|
}
|