aboutsummaryrefslogtreecommitdiffstats
path: root/erts/emulator/test
diff options
context:
space:
mode:
authorTomas Abrahamsson <[email protected]>2018-12-13 22:36:03 +0100
committerTomas Abrahamsson <[email protected]>2018-12-13 22:36:03 +0100
commit1e6ab2fdac21c7847b7fda32fed1ea35883a535e (patch)
treef6ca6afe4af45f3f8f95070924bceaf79d820e69 /erts/emulator/test
parent3825199794da28d79b21052a2e69e2335921d55e (diff)
downloadotp-1e6ab2fdac21c7847b7fda32fed1ea35883a535e.tar.gz
otp-1e6ab2fdac21c7847b7fda32fed1ea35883a535e.tar.bz2
otp-1e6ab2fdac21c7847b7fda32fed1ea35883a535e.zip
erts: Fix possible heap corruption getting atomics
Due to comparison as a signed integer, when getting an unsigned atomic in the range 2^63-1..2^64-1 (when the most significant bit was set), the heap could get corrupted when the integer was retrieved: hsz would get set to zero, but the code proceeded to build a bignum. Steps to reproduce (at least on x86_64): $ erl 1> A = atomics:new(1,[{signed,false}]). 2> atomics:put(A,1,18446744073709551615). 3> atomics:get(A,1). At the last step, the shell would print some garbage and hang.
Diffstat (limited to 'erts/emulator/test')
-rw-r--r--erts/emulator/test/atomics_SUITE.erl3
1 files changed, 3 insertions, 0 deletions
diff --git a/erts/emulator/test/atomics_SUITE.erl b/erts/emulator/test/atomics_SUITE.erl
index 8c42354770..a5407c42ee 100644
--- a/erts/emulator/test/atomics_SUITE.erl
+++ b/erts/emulator/test/atomics_SUITE.erl
@@ -126,6 +126,9 @@ unsigned_limits(Config) when is_list(Config) ->
Min = atomics:add_get(Ref, 1, 1),
Max = atomics:sub_get(Ref, 1, 1),
+ atomics:put(Ref, 1, Max),
+ io:format("Max=~p~n", [atomics:get(Ref, 1)]),
+
{'EXIT',{badarg,_}} = (catch atomics:add(Ref, 1, Max+1)),
IncrMin = -(1 bsl (Bits-1)),
ok = atomics:put(Ref, 1, -IncrMin),