From 6f452ac46f17b89f8a9f661ffc8fadc663ae124e Mon Sep 17 00:00:00 2001 From: Coleen Phillimore Date: Mon, 3 Nov 2025 12:37:00 +0000 Subject: [PATCH] 8364360: Defining hidden class with no room in constant pool crashes the VM Reviewed-by: matsaave, liach, dholmes --- .../share/classfile/classFileParser.cpp | 1 + .../runtime/ClassFile/HiddenClassesTest.java | 63 +++++++++++++++++++ 2 files changed, 64 insertions(+) create mode 100644 test/hotspot/jtreg/runtime/ClassFile/HiddenClassesTest.java diff --git a/src/hotspot/share/classfile/classFileParser.cpp b/src/hotspot/share/classfile/classFileParser.cpp index 87f2da91288..eb8a2a389b9 100644 --- a/src/hotspot/share/classfile/classFileParser.cpp +++ b/src/hotspot/share/classfile/classFileParser.cpp @@ -5523,6 +5523,7 @@ void ClassFileParser::parse_stream(const ClassFileStream* const stream, _orig_cp_size = cp_size; if (is_hidden()) { // Add a slot for hidden class name. + guarantee_property((u4)cp_size < 0xffff, "Overflow in constant pool size for hidden class %s", CHECK); cp_size++; } diff --git a/test/hotspot/jtreg/runtime/ClassFile/HiddenClassesTest.java b/test/hotspot/jtreg/runtime/ClassFile/HiddenClassesTest.java new file mode 100644 index 00000000000..0c67ce829ae --- /dev/null +++ b/test/hotspot/jtreg/runtime/ClassFile/HiddenClassesTest.java @@ -0,0 +1,63 @@ +/* +* Copyright (c) 2025, Oracle and/or its affiliates. All rights reserved. +* DO NOT ALTER OR REMOVE COPYRIGHT NOTICES OR THIS FILE HEADER. +* +* This code is free software; you can redistribute it and/or modify it +* under the terms of the GNU General Public License version 2 only, as +* published by the Free Software Foundation. +* +* This code is distributed in the hope that it will be useful, but WITHOUT +* ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or +* FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License +* version 2 for more details (a copy is included in the LICENSE file that +* accompanied this code). +* +* You should have received a copy of the GNU General Public License version +* 2 along with this work; if not, write to the Free Software Foundation, +* Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA. +* +* Please contact Oracle, 500 Oracle Parkway, Redwood Shores, CA 94065 USA +* or visit www.oracle.com if you need additional information or have any +* questions. +*/ + +/* + * @test + * @summary Test that parsing a hidden class with max constant pool entries + * doesn't crash the VM when adding an entry for the hidden class name. + * Instead throws ClassFormatError. + * @bug 8364360 + * @modules java.base/jdk.internal.access + * java.base/jdk.internal.reflect + * @library /testlibrary/asm + * @run main HiddenClassesTest + */ + +import java.lang.invoke.MethodHandles; + +import org.objectweb.asm.ClassWriter; +import static org.objectweb.asm.Opcodes.ACC_PUBLIC; +import static org.objectweb.asm.Opcodes.V17; + +public class HiddenClassesTest { + + public static void main(String[] args) throws Exception { + var cw = new ClassWriter(0); + cw.visit(V17, ACC_PUBLIC, "Hidden", null, "java/lang/Object", null); + // This magic number causes a constant pool index overflow with this asm generated class. + int i = 0; + while (i < 65535-1) { + i = cw.newUTF8(Integer.toString(i)); + } + try { + MethodHandles.lookup().defineHiddenClass(cw.toByteArray(), false); + throw new RuntimeException("Test Failed: ClassFormatError expected."); + } catch (ClassFormatError cfe) { + String message = cfe.getMessage(); + if (message == null || !message.contains("Overflow in constant pool size for hidden class")) { + throw new RuntimeException("Test Failed: wrong ClassFormatError " + message); + } + System.out.println("ClassFormatError thrown as expected. Message: " + cfe.getMessage()); + } + } +}