undefect. CWE-407 — 63 sites patched across 27 ecosystems

Authors: russell@unturf.com · brackishbert@gmail.com · foxhop.net · TimeHexOn.com

Patches, unit tests, benchmarks, whitepaper, and outreach briefs.
Public domain — no copyright claimed. Use freely.
This commit is contained in:
russell@unturf.com 2026-03-26 17:11:57 -04:00
commit 0a580b313d
70422 changed files with 17213626 additions and 0 deletions

View file

@ -0,0 +1,135 @@
/*
* Copyright (c) 2025, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
/*
* @test
* @bug 8370344
* @library /test/lib
* @run junit/native TestSharedCloseJvmti
*/
import jdk.test.lib.Utils;
import jdk.test.lib.process.OutputAnalyzer;
import jdk.test.lib.process.ProcessTools;
import org.junit.jupiter.api.Test;
import java.lang.foreign.Arena;
import java.lang.foreign.MemorySegment;
import java.lang.foreign.ValueLayout;
import java.nio.file.Path;
import java.util.ArrayList;
import java.util.List;
import java.util.concurrent.CountDownLatch;
import java.util.concurrent.TimeUnit;
import java.util.concurrent.TimeoutException;
public class TestSharedCloseJvmti {
private static final String JVMTI_AGENT_LIB = Path.of(Utils.TEST_NATIVE_PATH, System.mapLibraryName("SharedCloseAgent"))
.toAbsolutePath().toString();
@Test
void eventDuringScopedAccess() throws Throwable {
List<String> command = new ArrayList<>(List.of(
"-agentpath:" + JVMTI_AGENT_LIB,
"-Xcheck:jni",
EventDuringScopedAccessRunner.class.getName()
));
try {
ProcessBuilder pb = ProcessTools.createTestJavaProcessBuilder(command);
Process process = ProcessTools.startProcess("fork", pb, null, null, 1L, TimeUnit.MINUTES);
OutputAnalyzer output = new OutputAnalyzer(process);
output.shouldHaveExitValue(0);
output.stderrShouldContain("Exception in thread \"Trigger\" jdk.internal.misc.ScopedMemoryAccess$ScopedAccessError: Invalid memory access");
} catch (TimeoutException e) {
throw new RuntimeException("Timeout while waiting for forked process");
}
}
public static class EventDuringScopedAccessRunner {
static final int ADDED_FRAMES = 10;
static final CountDownLatch MAIN_LATCH = new CountDownLatch(1);
static final CountDownLatch TARGET_LATCH = new CountDownLatch(1);
static volatile int SINK;
public static void main(String[] args) throws Throwable {
try (Arena arena = Arena.ofShared()) {
MemorySegment segment = arena.allocate(4);
// run in separate thread so that waiting on
// latch doesn't block main thread
Thread.ofPlatform().name("Trigger").start(() -> {
SINK = segment.get(ValueLayout.JAVA_INT, 0); // should throw
System.err.println("No exception thrown during outer memory access");
System.exit(1);
});
// wait until trigger thread is in JVMTI event callback
MAIN_LATCH.await();
}
// Notify trigger thread that arena was closed
TARGET_LATCH.countDown();
}
static boolean reentrant = false;
// called by jvmti agent
// we get here after checking arena liveness
private static void target() {
String callerName = StackWalker.getInstance(StackWalker.Option.RETAIN_CLASS_REFERENCE).walk(frames ->
frames.skip(2).findFirst().orElseThrow().getClassName());
if (!callerName.equals("jdk.internal.misc.ScopedMemoryAccess")) {
return;
}
if (reentrant) {
// put some frames on the stack, so stack walk does not see @Scoped method
addFrames(0);
} else {
reentrant = true;
try (Arena arena = Arena.ofConfined()) {
SINK = arena.allocate(4).get(ValueLayout.JAVA_INT, 0); // should throw
System.err.println("No exception thrown during reentrant memory access");
System.exit(1);
}
reentrant = false;
}
}
private static void addFrames(int depth) {
if (depth >= ADDED_FRAMES) {
// notify main thread to close the arena
MAIN_LATCH.countDown();
try {
// wait here until main thread has closed arena
TARGET_LATCH.await();
} catch (InterruptedException ex) {
throw new RuntimeException("Unexpected interruption");
}
return;
}
addFrames(depth + 1);
}
}
}

View file

@ -0,0 +1,152 @@
/*
* Copyright (c) 2025, Oracle and/or its affiliates. All rights reserved.
* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER.
*
* This code is free software; you can redistribute it and/or modify it
* under the terms of the GNU General Public License version 2 only, as
* published by the Free Software Foundation.
*
* This code is distributed in the hope that it will be useful, but WITHOUT
* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or
* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License
* version 2 for more details (a copy is included in the LICENSE file that
* accompanied this code).
*
* You should have received a copy of the GNU General Public License version
* 2 along with this work; if not, write to the Free Software Foundation,
* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA.
*
* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA
* or visit www.oracle.com if you need additional information or have any
* questions.
*/
#include <jvmti.h>
#include <cstring>
#include <cstdlib>
static jclass MAIN_CLS;
static jmethodID TARGET_ID;
static jclass EXCEPTION_CLS;
static const char* TARGET_CLASS_NAME = "TestSharedCloseJvmti$EventDuringScopedAccessRunner";
static const char* TARGET_METHOD_NAME = "target";
static const char* TARGET_METHOD_SIG = "()V";
static const char* INTERCEPT_CLASS_NAME = "Ljdk/internal/foreign/MemorySessionImpl;";
static const char* INTERCEPT_METHOD_NAME = "checkValidStateRaw";
static const char* EXCEPTION_CLASS_NAME = "Ljdk/internal/misc/ScopedMemoryAccess$ScopedAccessError;";
void start(jvmtiEnv*, JNIEnv* jni_env, jthread) {
jclass cls = jni_env->FindClass(TARGET_CLASS_NAME);
if (cls == nullptr) {
jni_env->ExceptionDescribe();
return;
}
MAIN_CLS = (jclass) jni_env->NewGlobalRef(cls);
TARGET_ID = jni_env->GetStaticMethodID(cls, TARGET_METHOD_NAME, TARGET_METHOD_SIG);
if (TARGET_ID == nullptr) {
jni_env->ExceptionDescribe();
return;
}
jclass ex_cls = jni_env->FindClass(EXCEPTION_CLASS_NAME);
if (ex_cls == nullptr) {
jni_env->ExceptionDescribe();
return;
}
EXCEPTION_CLS = (jclass) jni_env->NewGlobalRef(ex_cls);
}
void method_exit(jvmtiEnv *jvmti_env, JNIEnv* jni_env, jthread thread, jmethodID method,
jboolean was_popped_by_exception, jvalue return_value) {
char* method_name = nullptr;
jvmtiError err = jvmti_env->GetMethodName(method, &method_name, nullptr, nullptr);
if (err != JVMTI_ERROR_NONE) {
return;
}
bool is_intercept_method = strcmp(method_name, INTERCEPT_METHOD_NAME) == 0;
jvmti_env->Deallocate((unsigned char*) method_name);
if (!is_intercept_method) {
return;
}
jclass cls;
err = jvmti_env->GetMethodDeclaringClass(method, &cls);
if (err != JVMTI_ERROR_NONE) {
return;
}
char* class_sig = nullptr;
err = jvmti_env->GetClassSignature(cls, &class_sig, nullptr);
if (err != JVMTI_ERROR_NONE) {
return;
}
bool is_intercept_class = strcmp(class_sig, INTERCEPT_CLASS_NAME) == 0;
jvmti_env->Deallocate((unsigned char*) class_sig);
if (!is_intercept_class) {
return;
}
jni_env->CallStaticVoidMethod(MAIN_CLS, TARGET_ID);
jthrowable ex = jni_env->ExceptionOccurred();
if (ex != nullptr) {
// we can not return with a pending exception from this JMVTI callback,
// and there is no way to propagate it to the caller so that the memory
// access will be interrupted.
// We log the exception for testing purposes end then terminate the process.
jni_env->ExceptionDescribe();
if (jni_env->IsInstanceOf(ex, EXCEPTION_CLS)) {
exit(0); // success
}
// else, another exception was thrown. Let the java logic handle the lack of
// ScopedAccessError
}
}
JNIEXPORT jint JNICALL
Agent_OnLoad(JavaVM *vm, char *options, void *reserved) {
jvmtiEnv* env;
jint jni_err = vm->GetEnv((void**) &env, JVMTI_VERSION);
if (jni_err != JNI_OK) {
return jni_err;
}
jvmtiCapabilities capabilities;
memset(&capabilities, 0, sizeof(jvmtiCapabilities));
capabilities.can_generate_method_exit_events = 1;
jvmtiError err = env->AddCapabilities(&capabilities);
if (err != JVMTI_ERROR_NONE) {
return err;
}
jvmtiEventCallbacks callbacks;
callbacks.VMInit = start;
callbacks.MethodExit = method_exit;
err = env->SetEventCallbacks(&callbacks, (jint) sizeof(callbacks));
if (err != JVMTI_ERROR_NONE) {
return err;
}
err = env->SetEventNotificationMode(JVMTI_ENABLE, JVMTI_EVENT_METHOD_EXIT, nullptr);
if (err != JVMTI_ERROR_NONE) {
return err;
}
err = env->SetEventNotificationMode(JVMTI_ENABLE, JVMTI_EVENT_VM_INIT, nullptr);
if (err != JVMTI_ERROR_NONE) {
return err;
}
return 0;
}