diff options
| author | Ulf Hermann <ulf.hermann@qt.io> | 2026-08-24 18:51:23 +0000 |
|---|---|---|
| committer | Ulf Hermann <ulf.hermann@qt.io> | 2026-09-11 18:46:12 +0000 |
| commit | 6796892f125b49a0b7e770f323bf65e5ad11bef9 (patch) | |
| tree | aebb5aa882bedd6ee1a91db4541508f1dd1f1048 | |
| parent | a304f7e07d4f5f942f82b81cfe7ef8a68d282f93 (diff) | |
V4: Make Yarr's stack limit check work under sanitizers
isSafeToRecurse() determined the current stack position by taking the
address of one of its own locals. AddressSanitizer's fake stack moves
address-taken locals to the heap, so that address bears no relation to
the real stack and the comparison against the limit is meaningless. In
practice it always compares as "out of stack", which makes every regular
expression created at run time fail to compile.
Use QV4::currentStackPointer() instead
Amends commit ab4a47837027ef6f14029fce196564c5fb657c08.
Pick-to: 6.12 6.11
Task-number: QTBUG-148295
Change-Id: I7652bfac9a913fd28643ff645787b89f2cf2a6b8
Reviewed-by: Fabian Kosmale <fabian.kosmale@qt.io>
Reviewed-by: Olivier De Cannière <olivier.decanniere@qt.io>
| -rw-r--r-- | src/3rdparty/masm/yarr/YarrPattern.cpp | 14 |
1 files changed, 11 insertions, 3 deletions
diff --git a/src/3rdparty/masm/yarr/YarrPattern.cpp b/src/3rdparty/masm/yarr/YarrPattern.cpp index 9c1cdadf3f..11e0444fea 100644 --- a/src/3rdparty/masm/yarr/YarrPattern.cpp +++ b/src/3rdparty/masm/yarr/YarrPattern.cpp @@ -36,6 +36,8 @@ #include <wtf/Vector.h> #include <wtf/text/WTFString.h> +#include <private/qv4stacklimits_p.h> + namespace JSC { namespace Yarr { #include "RegExpJitTables.h" @@ -1090,9 +1092,15 @@ private: { if (!m_stackLimit) return true; - int8_t* curr = reinterpret_cast<int8_t*>(&curr); - int8_t* limit = reinterpret_cast<int8_t*>(m_stackLimit); - return curr >= limit; + // Do not take the address of a local here. Sanitizers may move such variables off the + // real stack, which would make the comparison below meaningless. + const int8_t* curr = reinterpret_cast<const int8_t*>(QV4::currentStackPointer()); + const int8_t* limit = reinterpret_cast<const int8_t*>(m_stackLimit); +#if Q_STACK_GROWTH_DIRECTION > 0 + return curr < limit; +#else + return curr > limit; +#endif } YarrPattern& m_pattern; |
