Skip to content

CABI: trap on misaligned error-context.debug-message ptr - #740

Open
rvolosatovs wants to merge 1 commit into
WebAssembly:mainfrom
rvolosatovs:fix/err-ctx-ptr
Open

rvolosatovs wants to merge 1 commit into
WebAssembly:mainfrom
rvolosatovs:fix/err-ctx-ptr

Conversation

@rvolosatovs

Copy link
Copy Markdown
Contributor

canon_error_context_debug_message stored the debug string's (pointer, length) pair at the guest-supplied ptr with store_string, which writes through store_int without any alignment or bounds check. A misaligned ptr was thus accepted, and an out-of-bounds ptr silently grew the Python bytearray backing linear memory (appending at its current end) instead of trapping.

Check ptr the same way lower_flat_values checks an out-param pointer before storing a spilled tuple: trap unless ptr is aligned to alignment(string) and ptr + elem_size(string) is within memory, then go through store, whose assertions these checks discharge. The checks run before opts.realloc is called.

Refs bytecodealliance/wasmtime#14626

canon_error_context_debug_message stored the debug string's (pointer,
length) pair at the guest-supplied `ptr` with store_string, which writes
through store_int without any alignment or bounds check. A misaligned `ptr`
was thus accepted, and an out-of-bounds `ptr` silently grew the Python
bytearray backing linear memory (appending at its current end) instead of
trapping.

Check `ptr` the same way lower_flat_values checks an out-param pointer
before storing a spilled tuple: trap unless `ptr` is aligned to
alignment(string) and `ptr + elem_size(string)` is within memory, then go
through store, whose assertions these checks discharge. The checks run
before opts.realloc is called.

Assisted-by: claude:claude-opus-5-5
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant