Files
ppsspp/Common/Serialize/SerializeMap.h
T
Henrik RydgårdandClaude Opus 5.5 7ad9a64cf4 Serialize: Clear pointer maps and sets right after deleting their values
DoMap and DoSet cleared them, but only once the count had been read. A
state truncated right there left the deleted pointers in place, to be
freed again when the failed load reset the game.

Co-Authored-By: Claude Opus 5.5 (1M context) <[email protected]>
2026-09-28 09:34:06 -06:00

187 lines
4.8 KiB
C++

// Copyright (C) 2003 Dolphin Project.
// This program is free software: you can redistribute it and/or modify
// it under the terms of the GNU General Public License as published by
// the Free Software Foundation, version 2.0 or later versions.
// This program is distributed in the hope that it will be useful,
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
// GNU General Public License 2.0 for more details.
// A copy of the GPL 2.0 should have been included with the program.
// If not, see http://www.gnu.org/licenses/
// Official SVN repository and contact information can be found at
// http://code.google.com/p/dolphin-emu/
#pragma once
// Templates for save state serialization. See Serializer.h.
#include <map>
#include <unordered_map>
#include "Common/Serialize/SerializeFuncs.h"
template<class M>
void DoMap(PointerWrap &p, M &x, typename M::mapped_type &default_val) {
unsigned int number = (unsigned int)x.size();
Do(p, number);
switch (p.mode) {
case PointerWrap::MODE_READ:
{
x.clear();
// Guard against an attacker-controlled count driving an enormous number of
// loop iterations/allocations, same spirit as DoVector's guard.
constexpr size_t minElemSize = SerializeMinElemSize<typename M::key_type>() + SerializeMinElemSize<typename M::mapped_type>();
if (number > p.Remaining() / minElemSize) {
p.SetError(PointerWrap::ERROR_FAILURE);
return;
}
while (number > 0) {
typename M::key_type first = typename M::key_type();
Do(p, first);
typename M::mapped_type second = default_val;
Do(p, second);
x[first] = second;
--number;
}
break;
}
case PointerWrap::MODE_WRITE:
case PointerWrap::MODE_MEASURE:
case PointerWrap::MODE_VERIFY:
{
typename M::iterator itr = x.begin();
while (number > 0) {
typename M::key_type first = itr->first;
Do(p, first);
Do(p, itr->second);
--number;
++itr;
}
break;
}
case PointerWrap::MODE_NOOP:
break;
}
}
template<class K, class T>
void Do(PointerWrap &p, std::map<K, T *> &x) {
if (p.mode == PointerWrap::MODE_READ) {
for (auto &iter : x) {
delete iter.second;
}
// Right away: if reading the count fails, DoMap won't get as far as clearing.
x.clear();
}
T *dv = nullptr;
DoMap(p, x, dv);
}
template<class K, class T>
void Do(PointerWrap &p, std::map<K, T> &x) {
T dv = T();
DoMap(p, x, dv);
}
template<class K, class T>
void Do(PointerWrap &p, std::unordered_map<K, T *> &x) {
if (p.mode == PointerWrap::MODE_READ) {
for (auto &iter : x) {
delete iter.second;
}
// Right away: if reading the count fails, DoMap won't get as far as clearing.
x.clear();
}
T *dv = nullptr;
DoMap(p, x, dv);
}
template<class K, class T>
void Do(PointerWrap &p, std::unordered_map<K, T> &x) {
T dv = T();
DoMap(p, x, dv);
}
template<class M>
void DoMultimap(PointerWrap &p, M &x, typename M::mapped_type &default_val) {
unsigned int number = (unsigned int)x.size();
Do(p, number);
switch (p.mode) {
case PointerWrap::MODE_READ:
{
x.clear();
// Guard against an attacker-controlled count driving an enormous number of
// loop iterations/allocations, same spirit as DoVector's guard.
constexpr size_t minElemSize = SerializeMinElemSize<typename M::key_type>() + SerializeMinElemSize<typename M::mapped_type>();
if (number > p.Remaining() / minElemSize) {
p.SetError(PointerWrap::ERROR_FAILURE);
return;
}
while (number > 0) {
typename M::key_type first = typename M::key_type();
Do(p, first);
typename M::mapped_type second = default_val;
Do(p, second);
x.insert(std::make_pair(first, second));
--number;
}
break;
}
case PointerWrap::MODE_WRITE:
case PointerWrap::MODE_MEASURE:
case PointerWrap::MODE_VERIFY:
{
typename M::iterator itr = x.begin();
while (number > 0) {
Do(p, itr->first);
Do(p, itr->second);
--number;
++itr;
}
break;
}
case PointerWrap::MODE_NOOP:
break;
}
}
template<class K, class T>
void Do(PointerWrap &p, std::multimap<K, T *> &x) {
if (p.mode == PointerWrap::MODE_READ) {
for (auto &iter : x) {
delete iter.second;
}
// Right away: if reading the count fails, DoMap won't get as far as clearing.
x.clear();
}
T *dv = nullptr;
DoMultimap(p, x, dv);
}
template<class K, class T>
void Do(PointerWrap &p, std::multimap<K, T> &x) {
T dv = T();
DoMultimap(p, x, dv);
}
template<class K, class T>
void Do(PointerWrap &p, std::unordered_multimap<K, T *> &x) {
if (p.mode == PointerWrap::MODE_READ) {
for (auto &iter : x) {
delete iter.second;
}
// Right away: if reading the count fails, DoMap won't get as far as clearing.
x.clear();
}
T *dv = nullptr;
DoMultimap(p, x, dv);
}
template<class K, class T>
void Do(PointerWrap &p, std::unordered_multimap<K, T> &x) {
T dv = T();
DoMultimap(p, x, dv);
}