Integer overflow in deallocation
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 35/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Ferma
- Stack tecnologico
- rust
- Ambito
- operating-systems
Direzione di ricerca
Start at src/hole.rs around line 617 and compare the reported deallocation values with the minimized psram.rs example and the large_deallocation test. Investigate why the test does not reproduce the overflow despite using the same arena size, allocation, and alignment. Done means the reported deallocation no longer panics and a regression test covers the case.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Thanks for this crate!
I tried to find the size of my PSRAM by simply allocating large amounts of data with a Vec and stumbled upon an integer overflow:
When trying to free an allocation with size 1048572 and alignment 4, my program panicked at https://github.com/rust-osdev/linked-list-allocator/tree/main/src/hole.rs#L617
I added a few panics to see some variable and argument values. The panic happens with this addition arguments: 1048572 += 4294967295 where the right-hand side is usize::MAX for this architecture.
I tried on the latest release 0.10.5 first but could also reproduce on the latest main commit
Minimized example:
https://github.com/ede1998/ireplay/blob/86e2f72509eaf308c133086e1daa133819e68852/src/bin/psram.rs
I tried to reduce the case even further by writing a test in this crate but could not reproduce it that way even though I compiled and ran it with 32bit x86 instead of 64 bit to ensure that usize::MAX is the same. As far as I could tell, there should be no significant difference between my minimized example and the test in terms of code: Both init an arena of the same size and then allocate and deallocate the same number of bytes with the same alignment.
Command
CARGO_TARGET_I686_UNKNOWN_LINUX_GNU_LINKER=$( nix eval --raw --impure --expr 'let pkgs = import {}; in "${pkgs.pkgsi686Linux.stdenv.cc}/bin/${pkgs.pkgsi686Linux.stdenv.cc.targetPrefix}cc"');cargo test --target=i686-unknown-linux-gnu large_deallocation
#[test]
fn large_deallocation() {
// static mut ARENA: [MaybeUninit<u8>; 3_000_000] = [MaybeUninit::uninit(); 3_000_000];
// let mut heap = Heap::from_slice(unsafe { &mut ARENA });
static mut ARENA: [u8; 3_000_000] = [0; 3_000_000];
let mut heap = Heap::empty();
unsafe {
heap.init(ARENA.as_mut_ptr(), 2097152);
}
let layout = Layout::from_size_align(1048572, 4).unwrap();
let data = heap
.allocate_first_fit(layout)
.expect("Succesful allocation");
unsafe {
heap.deallocate(data, layout);
}
}
- Lingua principale
- Rust
- Stelle
- 242
- Fork
- 56
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Non abbiamo ancora controllato i file di configurazione di questo progetto. Parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di rust-osdev/linked-list-allocator
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 45/100
-
Support for reallocationsAperta
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
rust-osdev/linked-list-allocator#86 · 3 reazioni ·
-
help wanted
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
rust-osdev/linked-list-allocator#83 · 2 commenti ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
rust-osdev/linked-list-allocator#76 · 3 commenti ·
Tutte le issue di rust-osdev/linked-list-allocator
Issue simili
-
`sysknife history --help` says --since takes ISO-8601, and the parser refuses offsets and bare datesApertabug easy good first issue help wanted
Difficoltà 1/5 1-3 ore Idoneità per principianti 94/100
lacs-project/sysknife#519 ·
I maintainer di solito rispondono entro 1 giorno
-
enhancement
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 72/100
-
area:breg bug criticality:p3 triage:needs-implementation
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
registrystack/registry-stack#1699 ·
I maintainer di solito rispondono entro 1 giorno
-
documentation
Difficoltà 1/5 1-3 ore Idoneità per principianti 84/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
lbjlaq/Antigravity-Manager#3539 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno