mirror of
https://github.com/hrydgard/ppsspp.git
synced 2026-10-01 14:58:14 +00:00
Check framebuffer copy sources, and fix two easy crashes
The three framebuffer upload paths took Memory::GetPointerUnchecked() on a
GE-supplied source address and then read height rows of it, without ever checking
that span was mapped. Only the destination was validated (and DoBlockTransfer's own
memcpy is carefully guarded, so the intent was clearly there). A copy whose source
starts near the end of RAM walks straight off the end of the view. Clamp the row
count to what's actually mapped, and warn when we do.
GhidraClient dereferenced getArray()->value for both "symbols" and "types" without a
null check, and the getTag() test underneath could never catch it - getArray() has
already filtered by tag, so it returns either a JSON_ARRAY node or nullptr. Any
HTTP 200 that parses as JSON but isn't the shape we expect - {}, a bare array, an
incompatible ghidra-rest-api, or the host/port pointed at some other JSON service -
crashed the worker thread. FetchTypes() runs first, so that's the one you'd hit.
RiscV and LoongArch CPU detection divided TotalLogicalCount() by ProcessorCount()
before checking it. ProcessorCount() returns 0 whenever /proc/cpuinfo can't be read
or doesn't parse, which is SIGFPE during static init of the cpu_info global - before
anything could handle it. The existing <= 0 guard sat after the division.
314 pspautotests pass; frametests show the same 3 pre-existing failures as master.
This commit is contained in:
1 parent
3bd9e23f91
commit
98e8ffe7cd
4 files changed
+61
-13
No files matched your search
+12
-4
@@ -79,11 +79,15 @@ bool GhidraClient::FetchSymbols() {
|
||||
pendingResult_.error = "symbols parsing error";
|
||||
return false;
|
||||
}
|
||||
const JsonValue entries = reader.root().getArray("symbols")->value;
|
||||
if (entries.getTag() != JSON_ARRAY) {
|
||||
const JsonNode *entriesNode = reader.root().getArray("symbols");
|
||||
if (!entriesNode) {
|
||||
// Null for a missing key, a non-array value, or a root that isn't an object at all -
|
||||
// so any JSON that parses but isn't what we expect. The getTag() check below it could
|
||||
// never catch that, since getArray() already filtered by tag.
|
||||
pendingResult_.error = "symbols is not an array";
|
||||
return false;
|
||||
}
|
||||
const JsonValue entries = entriesNode->value;
|
||||
|
||||
for (const auto pEntry : entries) {
|
||||
JsonGet entry = pEntry->value;
|
||||
@@ -109,11 +113,15 @@ bool GhidraClient::FetchTypes() {
|
||||
pendingResult_.error = "types parsing error";
|
||||
return false;
|
||||
}
|
||||
const JsonValue entries = reader.root().getArray("types")->value;
|
||||
if (entries.getTag() != JSON_ARRAY) {
|
||||
const JsonNode *entriesNode = reader.root().getArray("types");
|
||||
if (!entriesNode) {
|
||||
// Null for a missing key, a non-array value, or a root that isn't an object at all -
|
||||
// so any JSON that parses but isn't what we expect. The getTag() check below it could
|
||||
// never catch that, since getArray() already filtered by tag.
|
||||
pendingResult_.error = "types is not an array";
|
||||
return false;
|
||||
}
|
||||
const JsonValue entries = entriesNode->value;
|
||||
|
||||
for (const auto pEntry : entries) {
|
||||
const JsonGet entry = pEntry->value;
|
||||
|
||||
Reference in new issue
Block a user