diff options
author | Florian Hahn <flo@fhahn.com> | 2019-07-14 12:35:50 +0000 |
---|---|---|
committer | Florian Hahn <flo@fhahn.com> | 2019-07-14 12:35:50 +0000 |
commit | 864474c9c72a647e1d9bc7546df86103ce043f4f (patch) | |
tree | c585ae7e2f6d2500f9728a1e99058e4d01c1a8e6 /llvm/lib/Bitcode/Reader/BitcodeReader.cpp | |
parent | f66f5ff38ab25043aed6e379b27a298196e764b9 (diff) | |
download | bcm5719-llvm-864474c9c72a647e1d9bc7546df86103ce043f4f.tar.gz bcm5719-llvm-864474c9c72a647e1d9bc7546df86103ce043f4f.zip |
[BitcodeReader] Use tighter upper bound to validate forward references.
At the moment, bitcode files with invalid forward reference can easily
cause the bitcode reader to run out of memory, by creating a forward
reference with a very high index.
We can use the size of the bitcode file as an upper bound, because a
valid bitcode file can never contain more records. This should be
sufficient to fail early in most cases. The only exception is large
files with invalid forward references close to the file size.
There are a couple of clusterfuzz runs that fail with out-of-memory
because of very high forward references and they should be fixed by this
patch.
A concrete example for this is D64507, which causes out-of-memory on
systems with low memory, like the hexagon upstream bots.
Reviewers: t.p.northover, thegameg, jfb, efriedma, hfinkel
Reviewed By: jfb
Differential Revision: https://reviews.llvm.org/D64577
llvm-svn: 366017
Diffstat (limited to 'llvm/lib/Bitcode/Reader/BitcodeReader.cpp')
-rw-r--r-- | llvm/lib/Bitcode/Reader/BitcodeReader.cpp | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/llvm/lib/Bitcode/Reader/BitcodeReader.cpp b/llvm/lib/Bitcode/Reader/BitcodeReader.cpp index 09bd0f4ec71..d07edefcffa 100644 --- a/llvm/lib/Bitcode/Reader/BitcodeReader.cpp +++ b/llvm/lib/Bitcode/Reader/BitcodeReader.cpp @@ -858,7 +858,7 @@ BitcodeReader::BitcodeReader(BitstreamCursor Stream, StringRef Strtab, StringRef ProducerIdentification, LLVMContext &Context) : BitcodeReaderBase(std::move(Stream), Strtab), Context(Context), - ValueList(Context) { + ValueList(Context, Stream.SizeInBytes()) { this->ProducerIdentification = ProducerIdentification; } |