proof/FINDINGS.md's Isabelle/HOL word-source sweep (§4) flagged five real defects; this fixes all five and records resolution in that doc: - EXECUTE (system_words.c): cast a popped cell straight to a DictEntry* and called through it with only a null check. Now validates via a new shared vm_dict_entry_ok(), promoted out of starforth_words.c's ENTROPY@/ENTROPY! guard (dictionary_management.c) so EXECUTE gets the same live-entry check. - ? and DUMP (format_words.c): dereferenced the popped cell as a raw host pointer, bypassing vm_addr_ok entirely (out-of-VM-bounds read). Both now go through VM_ADDR/vm_addr_ok/vm_load_cell/vm_ptr like every other memory word (@, `,`, editor_words.c). - TYPE (io_words.c): bounds check computed addr+count in signed 64-bit arithmetic, which can overflow and bypass the check on large operands. Replaced with vm_addr_ok(), which is written to avoid that overflow. - DECIMAL/HEX/OCTAL (format_words.c): wrote only the BASE memory cell, never vm->base, the host-mirror field number-output words actually read via current_base() -- so these words silently affected number parsing but never printing. Now call the existing vm_set_base() (previously only used at boot init), which updates both. vm_get_base/vm_set_base promoted to public declarations in include/vm.h. - ALIGN vs ALLOT/,/C,/2, (dictionary_words.c): disagreed on dictionary growth ceiling (2MB vs 5MB). Investigated which was correct rather than blindly widening: vm_get_block_addr() maps block N to vm->memory + N*BLOCK_SIZE across the full 5MB arena, and USER_BLOCKS_START (block 2048) lines up exactly with DICTIONARY_MEMORY_SIZE -- so ALLOT/,/C,/2, letting `here` grow past 2MB could silently corrupt live block/user data sharing that memory. Tightened ALLOT/,/C,/2, to DICTIONARY_MEMORY_SIZE to match ALIGN. Verified: hosted (amd64) and kernel (amd64, __STARKERNEL__) both build clean with -Wall -Werror; hosted POST suite 1012/1012 passing (0 regressions); manually exercised EXECUTE, ?/DUMP, TYPE, HEX/DECIMAL/OCTAL, and large-ALLOT rejection in the REPL. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014Qf6YcnHgaEtEygq3knx19
140 lines
4.8 KiB
C
140 lines
4.8 KiB
C
/*
|
||
StarForth — Steady-State Virtual Machine Runtime
|
||
|
||
Copyright (c) 2023–2025 Robert A. James
|
||
All rights reserved.
|
||
|
||
This file is part of the StarForth project.
|
||
|
||
Licensed under the StarForth License, Version 1.0 (the "License");
|
||
you may not use this file except in compliance with the License.
|
||
|
||
You may obtain a copy of the License at:
|
||
https://github.com/star.4th@proton.me/StarForth/LICENSE.txt
|
||
|
||
This software is provided "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
||
express or implied, including but not limited to the warranties of
|
||
merchantability, fitness for a particular purpose, and noninfringement.
|
||
|
||
See the License for the specific language governing permissions and
|
||
limitations under the License.
|
||
|
||
StarForth — Steady-State Virtual Machine Runtime
|
||
Copyright (c) 2023–2025 Robert A. James
|
||
All rights reserved.
|
||
|
||
This file is part of the StarForth project.
|
||
|
||
Licensed under the StarForth License, Version 1.0 (the "License");
|
||
you may not use this file except in compliance with the License.
|
||
|
||
You may obtain a copy of the License at:
|
||
https://github.com/star.4th@proton.me/StarForth/LICENSE.txt
|
||
|
||
This software is provided "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
||
express or implied, including but not limited to the warranties of
|
||
merchantability, fitness for a particular purpose, and noninfringement.
|
||
|
||
See the License for the specific language governing permissions and
|
||
limitations under the License.
|
||
|
||
*/
|
||
|
||
#include "../include/vm.h"
|
||
#include "../include/log.h"
|
||
|
||
/**
|
||
* @brief Allocates memory from the VM's dictionary space
|
||
* @param vm Pointer to the VM instance
|
||
* @param bytes Number of bytes to allocate
|
||
* @return Pointer to the allocated memory or NULL if allocation fails
|
||
* @note The allocation is done from the VM's dictionary space which is limited to DICTIONARY_MEMORY_SIZE
|
||
*/
|
||
void *vm_allot(VM *vm, size_t bytes) {
|
||
if (!vm || !vm->memory) {
|
||
log_message(LOG_ERROR, "vm_allot: VM or memory is NULL");
|
||
return NULL;
|
||
}
|
||
|
||
/* Ensure we don't allocate beyond dictionary space (first DICTIONARY_BLOCKS blocks = DICTIONARY_MEMORY_SIZE bytes) */
|
||
log_message(LOG_DEBUG, "vm_allot: Requesting %zu bytes, current here=%zu, limit=%d",
|
||
bytes, vm->here, DICTIONARY_MEMORY_SIZE);
|
||
|
||
if (vm->here + bytes >= DICTIONARY_MEMORY_SIZE) {
|
||
log_message(LOG_ERROR, "Dictionary space full (here=%zu, bytes=%zu, dict_limit=%d)",
|
||
vm->here, bytes, DICTIONARY_MEMORY_SIZE);
|
||
vm->error = 1;
|
||
return NULL;
|
||
}
|
||
|
||
void *ptr = vm->memory + vm->here;
|
||
vm->here += bytes;
|
||
|
||
/* Log which block we're using */
|
||
int current_block = vm->here / BLOCK_SIZE;
|
||
log_message(LOG_DEBUG, "ALLOT: Allocated %zu bytes at offset %zu (block %d)",
|
||
bytes, vm->here - bytes, current_block);
|
||
|
||
return ptr;
|
||
}
|
||
|
||
/**
|
||
* @brief Aligns the VM's dictionary pointer (here) to the cell boundary
|
||
* @param vm Pointer to the VM instance
|
||
* @note Adds padding bytes if necessary to ensure proper alignment for cell_t type
|
||
*/
|
||
void vm_align(VM *vm) {
|
||
size_t align = sizeof(cell_t);
|
||
size_t misalignment = vm->here % align;
|
||
|
||
if (misalignment != 0) {
|
||
size_t padding = align - misalignment;
|
||
void *pad = vm_allot(vm, padding);
|
||
if (pad == NULL) {
|
||
log_message(LOG_ERROR, "vm_align: Out of memory while aligning");
|
||
vm->error = 1;
|
||
return;
|
||
}
|
||
|
||
/* Optional: zero out the padding */
|
||
unsigned char *bytes = (unsigned char *) pad;
|
||
for (size_t i = 0; i < padding; ++i) {
|
||
bytes[i] = 0;
|
||
}
|
||
|
||
log_message(LOG_DEBUG, "vm_align: Added %zu byte(s) of padding", padding);
|
||
}
|
||
}
|
||
|
||
/**
|
||
* @brief Gets the memory address for a specified block number
|
||
* @param vm Pointer to the VM instance
|
||
* @param block_num Block number to get the address for
|
||
* @return Pointer to the start of the block or NULL if block number is invalid
|
||
* @note Blocks are fixed-size memory regions of BLOCK_SIZE bytes
|
||
*/
|
||
void *vm_get_block_addr(VM *vm, int block_num) {
|
||
if (block_num < 0 || block_num >= MAX_BLOCKS) {
|
||
log_message(LOG_ERROR, "vm_get_block_addr: Invalid block number %d", block_num);
|
||
return NULL;
|
||
}
|
||
return vm->memory + (block_num * BLOCK_SIZE);
|
||
}
|
||
|
||
/* Convert address to block number */
|
||
/**
|
||
* @brief Converts a memory address to its corresponding block number
|
||
* @param vm Pointer to the VM instance
|
||
* @param addr Memory address to convert
|
||
* @return Block number (0 to MAX_BLOCKS-1) or -1 if address is outside VM memory
|
||
* @note Used for determining which block a memory address belongs to
|
||
*/
|
||
int vm_addr_to_block(VM *vm, void *addr) {
|
||
if (addr < (void *) vm->memory ||
|
||
addr >= (void *) (vm->memory + VM_MEMORY_SIZE)) {
|
||
return -1; /* Outside VM memory */
|
||
}
|
||
|
||
uintptr_t offset = (uintptr_t) addr - (uintptr_t) vm->memory;
|
||
return (int) (offset / BLOCK_SIZE);
|
||
} |