x86-64 Pjmptbl: normalize the argument before indexing into the jump table - #595
Merged
Conversation
Contributor
Author
|
It turns out that RISC-V 64 bits has a similar issue, although much less serious: the 32-bit index argument is implicitly extended to a signed 64-bit integer. So, in the unlikely case where the jump table has more than 2^31 entries, we're addressing the wrong entry. Commit bc5a65f proposes to fix this by zero-extending the index while multiplying it by 4. It adds one shift-right instruction to the code generated for |
Contributor
Author
|
The RISC-V fix was overkill: we're generating worse code for a case that never happens in practice. I just added a run-time assertion that the jump table has at most 2^31 entries, which guarantees that the index has the correct 64-bit value. |
…p table The index argument of Pjmptbl is an unsigned 32-bit integer, not a 64-bit integer, so it must be converted to 64 bits (by zeroing the top 32 bits) before it can be used as an index into the jump table.
… elements The index argument of Pbtbl is an unsigned 32-bit integer. However, RV64 stores it sign-extended in a 64-bit register. This could cause an incorrect access in the jump table if the index is 2^31 or more. However, this can only happen if the jump table itself has at least 2^31 entries, which is highly unlikely (a source C program that would produce such a huge table would itself be huge and CompCert would probably run out of memory compiling it). To be on the safe side, we just add a run-time assertion that the jump table is no bigger than 2^31 entries.
xavierleroy
force-pushed
the
x86_64-jmptbl
branch
from
August 27, 2026 10:05
07a59d8 to
1e42571
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The index argument of
Pjmptblis an unsigned 32-bit integer, not a 64-bit integer, so it must be converted to 64 bits (by zeroing the top 32 bits) before being used as an index into the jump table.Issue reported by Christos Papakonstantinou (Cantina Security).