RFR: 8358289: [asan] runtime/cds/appcds/aotCode/AOTCodeFlags.java reports heap-buffer-overflow in ArchiveBuilder

Vladimir Kozlov kvn at openjdk.org
Tue Jun 3 02:06:07 UTC 2025


There is difference between AdapterFingerPrint allocation size [compute_size](https://github.com/openjdk/jdk/blob/master/src/hotspot/share/runtime/sharedRuntime.cpp#L2227) which may not be aligned to HeapWord size and [size](https://github.com/openjdk/jdk/blob/master/src/hotspot/share/runtime/sharedRuntime.cpp#L2421) used for copying during AOT cache build which is aligned and can be bigger than allocation size. 

I added asserts to `AdapterFingerPrint` and `AdapterHandlerEntry` to make sure sizes are correct. Both are used in AOT cache build.

I also moved `FreeHeap()` from `~AdapterFingerPrint()` to enforce the comment and simplify executed code.

Thanks to @MBaesken for finding the issue and @iklam for pointing the cause.

Testing tier1-3, xcomp, stress. Higher tiers are still running.

-------------

Commit messages:
 - 8358289: [asan] runtime/cds/appcds/aotCode/AOTCodeFlags.java reports heap-buffer-overflow in ArchiveBuilder

Changes: https://git.openjdk.org/jdk/pull/25604/files
  Webrev: https://webrevs.openjdk.org/?repo=jdk&pr=25604&range=00
  Issue: https://bugs.openjdk.org/browse/JDK-8358289
  Stats: 7 lines in 2 files changed: 3 ins; 0 del; 4 mod
  Patch: https://git.openjdk.org/jdk/pull/25604.diff
  Fetch: git fetch https://git.openjdk.org/jdk.git pull/25604/head:pull/25604

PR: https://git.openjdk.org/jdk/pull/25604


More information about the hotspot-dev mailing list