wasm2c: (Security) ensure tailcalls use initialized instance references for all cases - #2857
Conversation
|
Yeah, I'm a little confused why none of the tail-call tests would trigger this. Are there really zero test cases where a return_call is made to a function in the same module?? If so, that seems like what we need to be fixing... |
@keithw @sbc100 This will trigger only when a tail call into the same module also uses memory. Which is a combination I don't think is covered in the test suite. I have a test floating around somewhere that can trigger this, but I haven't merged this in yet. I can add that test in a separate commit, but I would like to land the security fix asap, as it may take a me a couple of days before I get free time to work on this again |
|
Yeah, I wouldn't add the test here -- it should be upstream. |
|
We do quite often add tests here, even when there is a plan to push them upstream eventually. lgtm either way though |
4ab1fc7 to
21075f0
Compare
This PR fixes a case in the tail-call implementation in wasm2c where the
instance_ptris not initialized before being passed to a callee --- on aReturnCallto a non-imported function. As an added defense in depthinstance_ptris explicitly initialized to zero to ensure such bugs would result in an unexploitable crash in the future.