Integer overflow in deallocation
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 35/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Đình trệ
- Công nghệ
- rust
- Lĩnh vực
- operating-systems
Hướng nghiên cứu
Start at src/hole.rs around line 617 and compare the reported deallocation values with the minimized psram.rs example and the large_deallocation test. Investigate why the test does not reproduce the overflow despite using the same arena size, allocation, and alignment. Done means the reported deallocation no longer panics and a regression test covers the case.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Thanks for this crate!
I tried to find the size of my PSRAM by simply allocating large amounts of data with a Vec and stumbled upon an integer overflow:
When trying to free an allocation with size 1048572 and alignment 4, my program panicked at https://github.com/rust-osdev/linked-list-allocator/tree/main/src/hole.rs#L617
I added a few panics to see some variable and argument values. The panic happens with this addition arguments: 1048572 += 4294967295 where the right-hand side is usize::MAX for this architecture.
I tried on the latest release 0.10.5 first but could also reproduce on the latest main commit
Minimized example:
https://github.com/ede1998/ireplay/blob/86e2f72509eaf308c133086e1daa133819e68852/src/bin/psram.rs
I tried to reduce the case even further by writing a test in this crate but could not reproduce it that way even though I compiled and ran it with 32bit x86 instead of 64 bit to ensure that usize::MAX is the same. As far as I could tell, there should be no significant difference between my minimized example and the test in terms of code: Both init an arena of the same size and then allocate and deallocate the same number of bytes with the same alignment.
Command
CARGO_TARGET_I686_UNKNOWN_LINUX_GNU_LINKER=$( nix eval --raw --impure --expr 'let pkgs = import {}; in "${pkgs.pkgsi686Linux.stdenv.cc}/bin/${pkgs.pkgsi686Linux.stdenv.cc.targetPrefix}cc"');cargo test --target=i686-unknown-linux-gnu large_deallocation
#[test]
fn large_deallocation() {
// static mut ARENA: [MaybeUninit<u8>; 3_000_000] = [MaybeUninit::uninit(); 3_000_000];
// let mut heap = Heap::from_slice(unsafe { &mut ARENA });
static mut ARENA: [u8; 3_000_000] = [0; 3_000_000];
let mut heap = Heap::empty();
unsafe {
heap.init(ARENA.as_mut_ptr(), 2097152);
}
let layout = Layout::from_size_align(1048572, 4).unwrap();
let data = heap
.allocate_first_fit(layout)
.expect("Succesful allocation");
unsafe {
heap.deallocate(data, layout);
}
}
- Ngôn ngữ chính
- Rust
- Star
- 242
- Fork
- 56
- Chỉ số merge pull request
- Không có pull request nào được merge trong 30 ngày
Chuẩn bị môi trường
Chúng tôi chưa kiểm tra các tệp thiết lập môi trường của dự án này. Hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của rust-osdev/linked-list-allocator
-
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 45/100
-
Support for reallocationsĐang mở
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
-
Độ khó 5/5 Hơn một tuần Mức phù hợp với người mới 25/100
rust-osdev/linked-list-allocator#86 · 3 reaction ·
-
help wanted
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
rust-osdev/linked-list-allocator#83 · 2 bình luận ·
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 35/100
rust-osdev/linked-list-allocator#76 · 3 bình luận ·
Tất cả issue của rust-osdev/linked-list-allocator
Issue tương tự
-
`categorize_command` has no `uv` arm, so every `rtk uv …` row counts as `other` in the ecosystem mixĐang mởarea:api bug good first issue priority:low
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 92/100
rtk-ai/rtk#4316 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 92/100
Maintainer thường phản hồi trong vòng 1 ngày
-
area/cli kind/bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 90/100
Maintainer thường phản hồi trong vòng 1 ngày
-
enhancement
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
-
good first issue open-endedness: low type: new feature
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100