On Thu, 11 Jun 2026 13:37:30 GMT, Casper Norrbin <[email protected]> wrote:
>> Hi everyone, >> >> This fixes an overflow in `FlatArrayPayload::advance_index`. The method >> advanced an array payload offset by multiplying two `int` values before >> adding the result to a `ptrdiff_t`. For large flat arrays, the >> backward-overlap path in `FlatArrayKlass::copy_array` can call >> `advance_index(length - 1)`, and that multiplication can overflow before the >> value is widened. >> >> The fix widens the operands before multiplying, so the offset adjustment is >> computed in a `ptrdiff_t`. >> >> I also added a regression test that performs large overlapping copies on a >> flat value array. Before the fix, the backward overlapping copy fails in >> debug builds with an out-of-bounds assert. With the fix, both backward and >> forward overlapping copies complete successfully. >> >> Testing: >> - New test testing same-array flat copy behavior >> - Tiers 1-3 >> >> --------- >> - [x] I confirm that I make this contribution in accordance with the >> [OpenJDK Interim AI Policy](https://openjdk.org/legal/ai). > > Casper Norrbin has updated the pull request incrementally with one additional > commit since the last revision: > > added length test comment Thank you for the quick reviews! I don't know if I quite agree that a `ptrdiff_t` would be the right type to use to represent a size, but that can be discussed in a follow-up. For now, let's get this in. ------------- PR Comment: https://git.openjdk.org/valhalla/pull/2537#issuecomment-4691097962
