From 91f08424fdc8d83e5506f4c1e054d0db01f92e40 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Henrik=20Rydg=C3=A5rd?= Date: Mon, 31 Aug 2026 15:37:32 +0200 Subject: [PATCH] MemArena: report mapping failures instead of returning success Horizon's CreateView printed 'Fatal error creating the view' and then returned base anyway, so the caller recorded an unmapped address as a live view. Posix's ftruncate failure was logged with a '// Should this be a failure?' - it is: the mmaps afterwards succeed against a short file and the first touch past its end raises SIGBUS, which is only hooked under __APPLE__. --- Common/MemArenaHorizon.cpp | 8 +++++--- Common/MemArenaPosix.cpp | 6 +++++- 2 files changed, 10 insertions(+), 4 deletions(-) diff --git a/Common/MemArenaHorizon.cpp b/Common/MemArenaHorizon.cpp index a57028ffa7..380fc1a8bb 100644 --- a/Common/MemArenaHorizon.cpp +++ b/Common/MemArenaHorizon.cpp @@ -50,11 +50,13 @@ void *MemArena::CreateView(s64 offset, size_t size, void *base) { if (R_FAILED(rc)) { printf("Fatal error creating the view... base: %p offset: %p size: %p src: %p err: %d\n", (void *)base, (void *)offset, (void *)size, (void *)(memoryCodeBase + offset), rc); - } else { - printf("Created the view... base: %p offset: %p size: %p src: %p err: %d\n", - (void *)base, (void *)offset, (void *)size, (void *)(memoryCodeBase + offset), rc); + // Returning base here reports success, so the caller happily uses an unmapped address + // and we take a fault later with nothing pointing back at this. + return nullptr; } + printf("Created the view... base: %p offset: %p size: %p src: %p err: %d\n", + (void *)base, (void *)offset, (void *)size, (void *)(memoryCodeBase + offset), rc); return base; } diff --git a/Common/MemArenaPosix.cpp b/Common/MemArenaPosix.cpp index a413f4eaf2..38598a2d7e 100644 --- a/Common/MemArenaPosix.cpp +++ b/Common/MemArenaPosix.cpp @@ -97,7 +97,11 @@ bool MemArena::GrabMemSpace(size_t size) { } if (ftruncate(fd, size) != 0) { ERROR_LOG(Log::MemMap, "Failed to ftruncate %d (%s) to size %08x", (int)fd, ram_temp_file.c_str(), (int)size); - // Should this be a failure? + // This is a failure: the mmaps below succeed against a short file, and touching a page past + // its end raises SIGBUS - which is only hooked on __APPLE__, so elsewhere it's a bare crash. + close(fd); + fd = -1; + return false; } #endif return true;