RFR: 8262295: C2: Out-of-Bounds Array Load from Clone Source [v3]

Roland Westrelin roland at openjdk.java.net
Mon Mar 22 08:18:43 UTC 2021


On Fri, 19 Mar 2021 13:19:04 GMT, Richard Reingruber <rrich at openjdk.org> wrote:

>> This c2 fix makes the optimization of loads from the result array of a
>> Object.clone() call dependent on a compile time range check in order to prevent
>> out-of-bounds array loads described in JDK-8262295.
>> 
>> Testing: The included reproducer test. The fix passed also our CI testing: JCK
>> and JTREG, also in Xcomp mode, SPECjvm2008, SPECjbb2015, SAP specific tests with
>> fastdebug and release builds on all platforms.
>> 
>> Alternatively the transformed load could be made dependent on a range check at
>> runtime. Based on our automated benchmarking it wouldn't be worth
>> it. Our benchmark results include quite a bit of noise though.
>
> Richard Reingruber has updated the pull request incrementally with one additional commit since the last revision:
> 
>   Avoid overflow in expression sizetype->_lo * elemsize + header

Looks good to me.

-------------

Marked as reviewed by roland (Reviewer).

PR: https://git.openjdk.java.net/jdk/pull/2708


More information about the hotspot-compiler-dev mailing list