Skip to content

FFI: initializing a VLA from a table writes past the end of the allocation #1521

Description

@chernetskyi

Environment: v2.1 @ c6ffc14, all targets. Reproduced on macOS arm64, with and without the JIT.

local ffi = require("ffi")
local a = ffi.new("int[?]", 2, {1, 2, 3, 4, 5, 6, 7, 8})
print(ffi.sizeof(a), a[2])

Expected: too many initializers for 'int [?]'. The flat-list form already does this: ffi.new("int[?]", 2, 1, 2, 3) raises the error.

Actual: all eight elements are written into the 8-byte allocation, with no error. With AddressSanitizer (-DLUAJIT_USE_SYSMALLOC):

ERROR: AddressSanitizer: heap-buffer-overflow
WRITE of size 4 ...
    #1 lj_cconv_ct_ct lj_cconv.c
    #2 lj_cconv_ct_tv lj_cconv.c:641
    #3 cconv_array_tab lj_cconv.c:484
    #4 lj_cf_ffi_new lib_ffi.c:510
... is located 0 bytes after 32-byte region

The VLA constructor from ffi.typeof("int[?]") behaves the same way.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions