On Sat, 4 Jul 2026 04:49:54 GMT, David CARLIER <[email protected]> wrote:
> Found while auditing the JVMTI local-variable accessors. > > `VM_BaseGetOrSetLocal` bounds-checks the requested slot before touching the > frame's `StackValueCollection`. For a `long`/`double` the value spans two > slots, so the check adds an `extra_slot` of 1: `_index + extra_slot >= > method->max_locals()`. When an agent passes `slot == INT_MAX`, `_index + > extra_slot` signed-overflows to `INT_MIN`, which is below `max_locals()`, so > the guard is bypassed and we go on to index `locals->at(INT_MAX)` — out of > bounds. That is an assertion failure in fastdebug and a SIGSEGV or silent > corruption in product. > > Doing the arithmetic on the other side (`_index >= method->max_locals() - > extra_slot`) avoids the overflow. The same check appears in both > `check_slot_type_lvt` and `check_slot_type_no_lvt`, so both are fixed. > > Additional testing: > - [x] Linux x86_64 server fastdebug, `serviceability/jvmti/GetLocalVariable` > - [ ] Regular testing pipelines > > --------- > - [x] I confirm that I make this contribution in accordance with the [OpenJDK > Interim AI Policy](https://openjdk.org/legal/ai). This pull request has now been integrated. Changeset: 6987a359 Author: David CARLIER <[email protected]> Committer: Serguei Spitsyn <[email protected]> URL: https://git.openjdk.org/jdk/commit/6987a3593fc7581f04992b034d3dbb0469d09f1f Stats: 192 lines in 3 files changed: 190 ins; 0 del; 2 mod 8387718: JVMTI GetLocal/SetLocal: slot bounds check overflows for long/double slots Reviewed-by: dholmes, sspitsyn ------------- PR: https://git.openjdk.org/jdk/pull/31772
