Files
LithosAnanake/src/memory_management.c
T
Claude c36bd99e1e Fix EXECUTE/?/DUMP/TYPE/DECIMAL-HEX-OCTAL/ALIGN defects from proof sweep
proof/FINDINGS.md's Isabelle/HOL word-source sweep (§4) flagged five real
defects; this fixes all five and records resolution in that doc:

- EXECUTE (system_words.c): cast a popped cell straight to a DictEntry*
  and called through it with only a null check. Now validates via a new
  shared vm_dict_entry_ok(), promoted out of starforth_words.c's
  ENTROPY@/ENTROPY! guard (dictionary_management.c) so EXECUTE gets the
  same live-entry check.

- ? and DUMP (format_words.c): dereferenced the popped cell as a raw host
  pointer, bypassing vm_addr_ok entirely (out-of-VM-bounds read). Both now
  go through VM_ADDR/vm_addr_ok/vm_load_cell/vm_ptr like every other
  memory word (@, `,`, editor_words.c).

- TYPE (io_words.c): bounds check computed addr+count in signed 64-bit
  arithmetic, which can overflow and bypass the check on large operands.
  Replaced with vm_addr_ok(), which is written to avoid that overflow.

- DECIMAL/HEX/OCTAL (format_words.c): wrote only the BASE memory cell,
  never vm->base, the host-mirror field number-output words actually read
  via current_base() -- so these words silently affected number parsing
  but never printing. Now call the existing vm_set_base() (previously
  only used at boot init), which updates both. vm_get_base/vm_set_base
  promoted to public declarations in include/vm.h.

- ALIGN vs ALLOT/,/C,/2, (dictionary_words.c): disagreed on dictionary
  growth ceiling (2MB vs 5MB). Investigated which was correct rather than
  blindly widening: vm_get_block_addr() maps block N to
  vm->memory + N*BLOCK_SIZE across the full 5MB arena, and
  USER_BLOCKS_START (block 2048) lines up exactly with
  DICTIONARY_MEMORY_SIZE -- so ALLOT/,/C,/2, letting `here` grow past 2MB
  could silently corrupt live block/user data sharing that memory.
  Tightened ALLOT/,/C,/2, to DICTIONARY_MEMORY_SIZE to match ALIGN.

Verified: hosted (amd64) and kernel (amd64, __STARKERNEL__) both build
clean with -Wall -Werror; hosted POST suite 1012/1012 passing (0
regressions); manually exercised EXECUTE, ?/DUMP, TYPE, HEX/DECIMAL/OCTAL,
and large-ALLOT rejection in the REPL.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_014Qf6YcnHgaEtEygq3knx19
2026-09-05 14:07:11 +00:00

140 lines
4.8 KiB
C
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
/*
StarForth — Steady-State Virtual Machine Runtime
Copyright (c) 2023–2025 Robert A. James
All rights reserved.
This file is part of the StarForth project.
Licensed under the StarForth License, Version 1.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at:
https://github.com/star.4th@proton.me/StarForth/LICENSE.txt
This software is provided "AS IS", WITHOUT WARRANTY OF ANY KIND,
express or implied, including but not limited to the warranties of
merchantability, fitness for a particular purpose, and noninfringement.
See the License for the specific language governing permissions and
limitations under the License.
StarForth — Steady-State Virtual Machine Runtime
Copyright (c) 2023–2025 Robert A. James
All rights reserved.
This file is part of the StarForth project.
Licensed under the StarForth License, Version 1.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at:
https://github.com/star.4th@proton.me/StarForth/LICENSE.txt
This software is provided "AS IS", WITHOUT WARRANTY OF ANY KIND,
express or implied, including but not limited to the warranties of
merchantability, fitness for a particular purpose, and noninfringement.
See the License for the specific language governing permissions and
limitations under the License.
*/
#include "../include/vm.h"
#include "../include/log.h"
/**
* @brief Allocates memory from the VM's dictionary space
* @param vm Pointer to the VM instance
* @param bytes Number of bytes to allocate
* @return Pointer to the allocated memory or NULL if allocation fails
* @note The allocation is done from the VM's dictionary space which is limited to DICTIONARY_MEMORY_SIZE
*/
void *vm_allot(VM *vm, size_t bytes) {
if (!vm || !vm->memory) {
log_message(LOG_ERROR, "vm_allot: VM or memory is NULL");
return NULL;
}
/* Ensure we don't allocate beyond dictionary space (first DICTIONARY_BLOCKS blocks = DICTIONARY_MEMORY_SIZE bytes) */
log_message(LOG_DEBUG, "vm_allot: Requesting %zu bytes, current here=%zu, limit=%d",
bytes, vm->here, DICTIONARY_MEMORY_SIZE);
if (vm->here + bytes >= DICTIONARY_MEMORY_SIZE) {
log_message(LOG_ERROR, "Dictionary space full (here=%zu, bytes=%zu, dict_limit=%d)",
vm->here, bytes, DICTIONARY_MEMORY_SIZE);
vm->error = 1;
return NULL;
}
void *ptr = vm->memory + vm->here;
vm->here += bytes;
/* Log which block we're using */
int current_block = vm->here / BLOCK_SIZE;
log_message(LOG_DEBUG, "ALLOT: Allocated %zu bytes at offset %zu (block %d)",
bytes, vm->here - bytes, current_block);
return ptr;
}
/**
* @brief Aligns the VM's dictionary pointer (here) to the cell boundary
* @param vm Pointer to the VM instance
* @note Adds padding bytes if necessary to ensure proper alignment for cell_t type
*/
void vm_align(VM *vm) {
size_t align = sizeof(cell_t);
size_t misalignment = vm->here % align;
if (misalignment != 0) {
size_t padding = align - misalignment;
void *pad = vm_allot(vm, padding);
if (pad == NULL) {
log_message(LOG_ERROR, "vm_align: Out of memory while aligning");
vm->error = 1;
return;
}
/* Optional: zero out the padding */
unsigned char *bytes = (unsigned char *) pad;
for (size_t i = 0; i < padding; ++i) {
bytes[i] = 0;
}
log_message(LOG_DEBUG, "vm_align: Added %zu byte(s) of padding", padding);
}
}
/**
* @brief Gets the memory address for a specified block number
* @param vm Pointer to the VM instance
* @param block_num Block number to get the address for
* @return Pointer to the start of the block or NULL if block number is invalid
* @note Blocks are fixed-size memory regions of BLOCK_SIZE bytes
*/
void *vm_get_block_addr(VM *vm, int block_num) {
if (block_num < 0 || block_num >= MAX_BLOCKS) {
log_message(LOG_ERROR, "vm_get_block_addr: Invalid block number %d", block_num);
return NULL;
}
return vm->memory + (block_num * BLOCK_SIZE);
}
/* Convert address to block number */
/**
* @brief Converts a memory address to its corresponding block number
* @param vm Pointer to the VM instance
* @param addr Memory address to convert
* @return Block number (0 to MAX_BLOCKS-1) or -1 if address is outside VM memory
* @note Used for determining which block a memory address belongs to
*/
int vm_addr_to_block(VM *vm, void *addr) {
if (addr < (void *) vm->memory ||
addr >= (void *) (vm->memory + VM_MEMORY_SIZE)) {
return -1; /* Outside VM memory */
}
uintptr_t offset = (uintptr_t) addr - (uintptr_t) vm->memory;
return (int) (offset / BLOCK_SIZE);
}