Commit 24b9ca9
authored
ffi: avoid memcpy() with a null pointer
Zero-length FFI memory operations accept a null pointer, but
ToArrayBuffer() and ExportBytes() call memcpy() unconditionally.
Passing a null pointer to memcpy() is undefined behavior even when
the size is zero.
Skip the copy when the length is zero, matching what Buffer::Copy()
already does for the same case.
An isolated reproduction compiled with -fsanitize=undefined reports
"null pointer passed as argument 1, which is declared to never be
null". The added test covers the reachable zero-length paths, but it
passes without the fix: libc does not fault on memcpy(NULL, NULL, 0),
and --enable-ubsan does not set -fno-sanitize-recover, so UBSan
reports the call without failing the process.
Signed-off-by: Christian Aurich Zanettini Martins <christian.aurichzm@gmail.com>
PR-URL: #66200
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Trivikram Kamat <trivikr.dev@gmail.com>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>1 parent bba3422 commit 24b9ca9
2 files changed
Lines changed: 12 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
662 | 662 | | |
663 | 663 | | |
664 | 664 | | |
665 | | - | |
| 665 | + | |
666 | 666 | | |
667 | 667 | | |
668 | 668 | | |
| |||
740 | 740 | | |
741 | 741 | | |
742 | 742 | | |
743 | | - | |
| 743 | + | |
| 744 | + | |
| 745 | + | |
744 | 746 | | |
745 | 747 | | |
746 | 748 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
243 | 243 | | |
244 | 244 | | |
245 | 245 | | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
246 | 254 | | |
247 | 255 | | |
248 | 256 | | |
| |||
0 commit comments