Hi everyone,

This fixes an overflow in `FlatArrayPayload::advance_index`. The method 
advanced an array payload offset by multiplying two `int` values before adding 
the result to a `ptrdiff_t`. For large flat arrays, the backward-overlap path 
in `FlatArrayKlass::copy_array` can call `advance_index(length - 1)`, and that 
multiplication can overflow before the value is widened.

The fix widens the operands before multiplying, so the offset adjustment is 
computed in a `ptrdiff_t`.

I also added a regression test that performs large overlapping copies on a flat 
value array. Before the fix, the backward overlapping copy fails in debug 
builds with an out-of-bounds assert. With the fix, both backward and forward 
overlapping copies complete successfully.

Testing:
- New test testing same-array flat copy behavior
- Tiers 1-3

---------
- [x] I confirm that I make this contribution in accordance with the [OpenJDK 
Interim AI Policy](https://openjdk.org/legal/ai).

-------------

Commit messages:
 - widen int multiplication to ptrdiff_t

Changes: https://git.openjdk.org/valhalla/pull/2537/files
  Webrev: https://webrevs.openjdk.org/?repo=valhalla&pr=2537&range=00
  Issue: https://bugs.openjdk.org/browse/JDK-8386342
  Stats: 76 lines in 2 files changed: 75 ins; 0 del; 1 mod
  Patch: https://git.openjdk.org/valhalla/pull/2537.diff
  Fetch: git fetch https://git.openjdk.org/valhalla.git pull/2537/head:pull/2537

PR: https://git.openjdk.org/valhalla/pull/2537

Reply via email to