xref: /aosp_15_r20/art/test/998-redefine-use-after-free/src-ex/DexCacheSmash.java (revision 795d594fd825385562da6b089ea9b2033f3abf5a)
1*795d594fSAndroid Build Coastguard Worker /*
2*795d594fSAndroid Build Coastguard Worker  * Copyright (C) 2017 The Android Open Source Project
3*795d594fSAndroid Build Coastguard Worker  *
4*795d594fSAndroid Build Coastguard Worker  * Licensed under the Apache License, Version 2.0 (the "License");
5*795d594fSAndroid Build Coastguard Worker  * you may not use this file except in compliance with the License.
6*795d594fSAndroid Build Coastguard Worker  * You may obtain a copy of the License at
7*795d594fSAndroid Build Coastguard Worker  *
8*795d594fSAndroid Build Coastguard Worker  *      http://www.apache.org/licenses/LICENSE-2.0
9*795d594fSAndroid Build Coastguard Worker  *
10*795d594fSAndroid Build Coastguard Worker  * Unless required by applicable law or agreed to in writing, software
11*795d594fSAndroid Build Coastguard Worker  * distributed under the License is distributed on an "AS IS" BASIS,
12*795d594fSAndroid Build Coastguard Worker  * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13*795d594fSAndroid Build Coastguard Worker  * See the License for the specific language governing permissions and
14*795d594fSAndroid Build Coastguard Worker  * limitations under the License.
15*795d594fSAndroid Build Coastguard Worker  */
16*795d594fSAndroid Build Coastguard Worker 
17*795d594fSAndroid Build Coastguard Worker import art.Redefinition;
18*795d594fSAndroid Build Coastguard Worker import java.util.Base64;
19*795d594fSAndroid Build Coastguard Worker 
20*795d594fSAndroid Build Coastguard Worker public class DexCacheSmash {
21*795d594fSAndroid Build Coastguard Worker     static class Transform {
foo()22*795d594fSAndroid Build Coastguard Worker         public void foo() {}
bar()23*795d594fSAndroid Build Coastguard Worker         public void bar() {}
getId()24*795d594fSAndroid Build Coastguard Worker         public String getId() {
25*795d594fSAndroid Build Coastguard Worker             return "TRANSFORM_INITIAL";
26*795d594fSAndroid Build Coastguard Worker         }
27*795d594fSAndroid Build Coastguard Worker     }
28*795d594fSAndroid Build Coastguard Worker 
29*795d594fSAndroid Build Coastguard Worker     static class Transform2 {
getId()30*795d594fSAndroid Build Coastguard Worker         public String getId() {
31*795d594fSAndroid Build Coastguard Worker             return "TRANSFORM2_INITIAL";
32*795d594fSAndroid Build Coastguard Worker         }
33*795d594fSAndroid Build Coastguard Worker     }
34*795d594fSAndroid Build Coastguard Worker 
35*795d594fSAndroid Build Coastguard Worker     /**
36*795d594fSAndroid Build Coastguard Worker      * A base64 encoding of the dex/class file of the Transform class above.
37*795d594fSAndroid Build Coastguard Worker      */
38*795d594fSAndroid Build Coastguard Worker     static final byte[] TRANSFORM_INITIAL_CLASS_FILE_BYTES = Base64.getDecoder().decode(
39*795d594fSAndroid Build Coastguard Worker             "yv66vgAAADQAFwoABAAPCAAQBwASBwAVAQAGPGluaXQ+AQADKClWAQAEQ29kZQEAD0xpbmVOdW1i" +
40*795d594fSAndroid Build Coastguard Worker             "ZXJUYWJsZQEAA2ZvbwEAA2JhcgEABWdldElkAQAUKClMamF2YS9sYW5nL1N0cmluZzsBAApTb3Vy" +
41*795d594fSAndroid Build Coastguard Worker             "Y2VGaWxlAQASRGV4Q2FjaGVTbWFzaC5qYXZhDAAFAAYBABFUUkFOU0ZPUk1fSU5JVElBTAcAFgEA" +
42*795d594fSAndroid Build Coastguard Worker             "F0RleENhY2hlU21hc2gkVHJhbnNmb3JtAQAJVHJhbnNmb3JtAQAMSW5uZXJDbGFzc2VzAQAQamF2" +
43*795d594fSAndroid Build Coastguard Worker             "YS9sYW5nL09iamVjdAEADURleENhY2hlU21hc2gAIAADAAQAAAAAAAQAAAAFAAYAAQAHAAAAHQAB" +
44*795d594fSAndroid Build Coastguard Worker             "AAEAAAAFKrcAAbEAAAABAAgAAAAGAAEAAAATAAEACQAGAAEABwAAABkAAAABAAAAAbEAAAABAAgA" +
45*795d594fSAndroid Build Coastguard Worker             "AAAGAAEAAAAUAAEACgAGAAEABwAAABkAAAABAAAAAbEAAAABAAgAAAAGAAEAAAAVAAEACwAMAAEA" +
46*795d594fSAndroid Build Coastguard Worker             "BwAAABsAAQABAAAAAxICsAAAAAEACAAAAAYAAQAAABcAAgANAAAAAgAOABQAAAAKAAEAAwARABMA" +
47*795d594fSAndroid Build Coastguard Worker             "CA==");
48*795d594fSAndroid Build Coastguard Worker     static final byte[] TRANSFORM_INITIAL_DEX_FILE_BYTES = Base64.getDecoder().decode(
49*795d594fSAndroid Build Coastguard Worker             "ZGV4CjAzNQDhg9CfghG1SRlLClguRuFYsqihr4F7NsGQAwAAcAAAAHhWNBIAAAAAAAAAAOQCAAAS" +
50*795d594fSAndroid Build Coastguard Worker             "AAAAcAAAAAcAAAC4AAAAAgAAANQAAAAAAAAAAAAAAAUAAADsAAAAAQAAABQBAABcAgAANAEAAKgB" +
51*795d594fSAndroid Build Coastguard Worker             "AACwAQAAxAEAAMcBAADiAQAA8wEAABcCAAA3AgAASwIAAF8CAAByAgAAfQIAAIACAACNAgAAkgIA" +
52*795d594fSAndroid Build Coastguard Worker             "AJcCAACeAgAApAIAAAMAAAAEAAAABQAAAAYAAAAHAAAACAAAAAsAAAACAAAABQAAAAAAAAALAAAA" +
53*795d594fSAndroid Build Coastguard Worker             "BgAAAAAAAAAAAAEAAAAAAAAAAQANAAAAAAABAA4AAAAAAAAADwAAAAQAAQAAAAAAAAAAAAAAAAAE" +
54*795d594fSAndroid Build Coastguard Worker             "AAAAAAAAAAEAAACYAQAAzgIAAAAAAAACAAAAvwIAAMUCAAABAAEAAQAAAKsCAAAEAAAAcBAEAAAA" +
55*795d594fSAndroid Build Coastguard Worker             "DgABAAEAAAAAALACAAABAAAADgAAAAEAAQAAAAAAtQIAAAEAAAAOAAAAAgABAAAAAAC6AgAAAwAA" +
56*795d594fSAndroid Build Coastguard Worker             "ABoACQARAAAANAEAAAAAAAAAAAAAAAAAAAY8aW5pdD4AEkRleENhY2hlU21hc2guamF2YQABTAAZ" +
57*795d594fSAndroid Build Coastguard Worker             "TERleENhY2hlU21hc2gkVHJhbnNmb3JtOwAPTERleENhY2hlU21hc2g7ACJMZGFsdmlrL2Fubm90" +
58*795d594fSAndroid Build Coastguard Worker             "YXRpb24vRW5jbG9zaW5nQ2xhc3M7AB5MZGFsdmlrL2Fubm90YXRpb24vSW5uZXJDbGFzczsAEkxq" +
59*795d594fSAndroid Build Coastguard Worker             "YXZhL2xhbmcvT2JqZWN0OwASTGphdmEvbGFuZy9TdHJpbmc7ABFUUkFOU0ZPUk1fSU5JVElBTAAJ" +
60*795d594fSAndroid Build Coastguard Worker             "VHJhbnNmb3JtAAFWAAthY2Nlc3NGbGFncwADYmFyAANmb28ABWdldElkAARuYW1lAAV2YWx1ZQAT" +
61*795d594fSAndroid Build Coastguard Worker             "AAcOABUABw4AFAAHDgAXAAcOAAICAREYAQIDAgwECBAXCgAAAQMAgIAEwAIBAdgCAQHsAgEBgAMO" +
62*795d594fSAndroid Build Coastguard Worker             "AAAAAAAAAAEAAAAAAAAAAQAAABIAAABwAAAAAgAAAAcAAAC4AAAAAwAAAAIAAADUAAAABQAAAAUA" +
63*795d594fSAndroid Build Coastguard Worker             "AADsAAAABgAAAAEAAAAUAQAAAxAAAAEAAAA0AQAAASAAAAQAAABAAQAABiAAAAEAAACYAQAAAiAA" +
64*795d594fSAndroid Build Coastguard Worker             "ABIAAACoAQAAAyAAAAQAAACrAgAABCAAAAIAAAC/AgAAACAAAAEAAADOAgAAABAAAAEAAADkAgAA");
65*795d594fSAndroid Build Coastguard Worker     static final Redefinition.CommonClassDefinition TRANSFORM_INITIAL =
66*795d594fSAndroid Build Coastguard Worker             new Redefinition.CommonClassDefinition(Transform.class,
67*795d594fSAndroid Build Coastguard Worker                     TRANSFORM_INITIAL_CLASS_FILE_BYTES, TRANSFORM_INITIAL_DEX_FILE_BYTES);
68*795d594fSAndroid Build Coastguard Worker 
69*795d594fSAndroid Build Coastguard Worker     /**
70*795d594fSAndroid Build Coastguard Worker      * A base64 encoding of the following (invalid) class.
71*795d594fSAndroid Build Coastguard Worker      *
72*795d594fSAndroid Build Coastguard Worker      *  .class LDexCacheSmash$Transform2;
73*795d594fSAndroid Build Coastguard Worker      *  .super Ljava/lang/Object;
74*795d594fSAndroid Build Coastguard Worker      *  .source "DexCacheSmash.java"
75*795d594fSAndroid Build Coastguard Worker      *
76*795d594fSAndroid Build Coastguard Worker      *  # annotations
77*795d594fSAndroid Build Coastguard Worker      *  .annotation system Ldalvik/annotation/EnclosingClass;
78*795d594fSAndroid Build Coastguard Worker      *      value = LDexCacheSmash;
79*795d594fSAndroid Build Coastguard Worker      *  .end annotation
80*795d594fSAndroid Build Coastguard Worker      *
81*795d594fSAndroid Build Coastguard Worker      *  .annotation system Ldalvik/annotation/InnerClass;
82*795d594fSAndroid Build Coastguard Worker      *      accessFlags = 0x8
83*795d594fSAndroid Build Coastguard Worker      *      name = "Transform2"
84*795d594fSAndroid Build Coastguard Worker      *  .end annotation
85*795d594fSAndroid Build Coastguard Worker      *
86*795d594fSAndroid Build Coastguard Worker      *
87*795d594fSAndroid Build Coastguard Worker      *  # direct methods
88*795d594fSAndroid Build Coastguard Worker      *  .method constructor <init>()V
89*795d594fSAndroid Build Coastguard Worker      *      .registers 1
90*795d594fSAndroid Build Coastguard Worker      *
91*795d594fSAndroid Build Coastguard Worker      *      .prologue
92*795d594fSAndroid Build Coastguard Worker      *      .line 26
93*795d594fSAndroid Build Coastguard Worker      *      invoke-direct {p0}, Ljava/lang/Object;-><init>()V
94*795d594fSAndroid Build Coastguard Worker      *
95*795d594fSAndroid Build Coastguard Worker      *      return-void
96*795d594fSAndroid Build Coastguard Worker      *  .end method
97*795d594fSAndroid Build Coastguard Worker      *
98*795d594fSAndroid Build Coastguard Worker      *
99*795d594fSAndroid Build Coastguard Worker      *  # virtual methods
100*795d594fSAndroid Build Coastguard Worker      *  .method public getId()Ljava/lang/String;
101*795d594fSAndroid Build Coastguard Worker      *      .registers 2
102*795d594fSAndroid Build Coastguard Worker      *
103*795d594fSAndroid Build Coastguard Worker      *      .prologue
104*795d594fSAndroid Build Coastguard Worker      *      .line 28
105*795d594fSAndroid Build Coastguard Worker      *      # NB Fails verification due to this function not returning a String.
106*795d594fSAndroid Build Coastguard Worker      *      return-void
107*795d594fSAndroid Build Coastguard Worker      *  .end method
108*795d594fSAndroid Build Coastguard Worker      */
109*795d594fSAndroid Build Coastguard Worker     static final byte[] TRANSFORM2_INVALID_CLASS_FILE_BYTES = Base64.getDecoder().decode(
110*795d594fSAndroid Build Coastguard Worker             "yv66vgAAADQAEwcAEgcAEQEABjxpbml0PgEAAygpVgEABENvZGUKAAIAEAEAD0xpbmVOdW1iZXJU" +
111*795d594fSAndroid Build Coastguard Worker             "YWJsZQEABWdldElkAQAUKClMamF2YS9sYW5nL1N0cmluZzsBAApTb3VyY2VGaWxlAQASRGV4Q2Fj" +
112*795d594fSAndroid Build Coastguard Worker             "aGVTbWFzaC5qYXZhAQAMSW5uZXJDbGFzc2VzBwAPAQAKVHJhbnNmb3JtMgEADURleENhY2hlU21h" +
113*795d594fSAndroid Build Coastguard Worker             "c2gMAAMABAEAEGphdmEvbGFuZy9PYmplY3QBABhEZXhDYWNoZVNtYXNoJFRyYW5zZm9ybTIAIAAB" +
114*795d594fSAndroid Build Coastguard Worker             "AAIAAAAAAAIAAAADAAQAAQAFAAAAHQABAAEAAAAFKrcABrEAAAABAAcAAAAGAAEAAAAaAAEACAAJ" +
115*795d594fSAndroid Build Coastguard Worker             "AAEABQAAABkAAQABAAAAAbEAAAABAAcAAAAGAAEAAAAcAAIACgAAAAIACwAMAAAACgABAAEADQAO" +
116*795d594fSAndroid Build Coastguard Worker             "AAg=");
117*795d594fSAndroid Build Coastguard Worker     static final byte[] TRANSFORM2_INVALID_DEX_FILE_BYTES = Base64.getDecoder().decode(
118*795d594fSAndroid Build Coastguard Worker             "ZGV4CjAzNQCFcegr6Ns+I7iEF4uLRkUX4yGrLhP6soEgAwAAcAAAAHhWNBIAAAAAAAAAAHQCAAAP" +
119*795d594fSAndroid Build Coastguard Worker             "AAAAcAAAAAcAAACsAAAAAgAAAMgAAAAAAAAAAAAAAAMAAADgAAAAAQAAAPgAAAAIAgAAGAEAABgB" +
120*795d594fSAndroid Build Coastguard Worker             "AAAgAQAANAEAADcBAABTAQAAZAEAAIgBAACoAQAAvAEAANABAADcAQAA3wEAAOwBAADzAQAA+QEA" +
121*795d594fSAndroid Build Coastguard Worker             "AAMAAAAEAAAABQAAAAYAAAAHAAAACAAAAAoAAAACAAAABQAAAAAAAAAKAAAABgAAAAAAAAAAAAEA" +
122*795d594fSAndroid Build Coastguard Worker             "AAAAAAAAAAAMAAAABAABAAAAAAAAAAAAAAAAAAQAAAAAAAAAAQAAACACAABmAgAAAAAAAAY8aW5p" +
123*795d594fSAndroid Build Coastguard Worker             "dD4AEkRleENhY2hlU21hc2guamF2YQABTAAaTERleENhY2hlU21hc2gkVHJhbnNmb3JtMjsAD0xE" +
124*795d594fSAndroid Build Coastguard Worker             "ZXhDYWNoZVNtYXNoOwAiTGRhbHZpay9hbm5vdGF0aW9uL0VuY2xvc2luZ0NsYXNzOwAeTGRhbHZp" +
125*795d594fSAndroid Build Coastguard Worker             "ay9hbm5vdGF0aW9uL0lubmVyQ2xhc3M7ABJMamF2YS9sYW5nL09iamVjdDsAEkxqYXZhL2xhbmcv" +
126*795d594fSAndroid Build Coastguard Worker             "U3RyaW5nOwAKVHJhbnNmb3JtMgABVgALYWNjZXNzRmxhZ3MABWdldElkAARuYW1lAAV2YWx1ZQAC" +
127*795d594fSAndroid Build Coastguard Worker             "AwILBAgNFwkCAgEOGAEAAAAAAAIAAAAJAgAAAAIAABQCAAAAAAAAAAAAAAAAAAAaAAcOABwABw4A" +
128*795d594fSAndroid Build Coastguard Worker             "AAABAAEAAQAAADACAAAEAAAAcBACAAAADgACAAEAAAAAADUCAAABAAAADgAAAAEBAICABLwEAQHU" +
129*795d594fSAndroid Build Coastguard Worker             "BA4AAAAAAAAAAQAAAAAAAAABAAAADwAAAHAAAAACAAAABwAAAKwAAAADAAAAAgAAAMgAAAAFAAAA" +
130*795d594fSAndroid Build Coastguard Worker             "AwAAAOAAAAAGAAAAAQAAAPgAAAACIAAADwAAABgBAAAEIAAAAgAAAAACAAADEAAAAgAAABACAAAG" +
131*795d594fSAndroid Build Coastguard Worker             "IAAAAQAAACACAAADIAAAAgAAADACAAABIAAAAgAAADwCAAAAIAAAAQAAAGYCAAAAEAAAAQAAAHQC" +
132*795d594fSAndroid Build Coastguard Worker             "AAA=");
133*795d594fSAndroid Build Coastguard Worker     static final Redefinition.CommonClassDefinition TRANSFORM2_INVALID =
134*795d594fSAndroid Build Coastguard Worker             new Redefinition.CommonClassDefinition(Transform2.class,
135*795d594fSAndroid Build Coastguard Worker                     TRANSFORM2_INVALID_CLASS_FILE_BYTES, TRANSFORM2_INVALID_DEX_FILE_BYTES);
136*795d594fSAndroid Build Coastguard Worker 
run()137*795d594fSAndroid Build Coastguard Worker     public static void run() throws Exception {
138*795d594fSAndroid Build Coastguard Worker         try {
139*795d594fSAndroid Build Coastguard Worker             Redefinition.doMultiClassRedefinition(TRANSFORM2_INVALID);
140*795d594fSAndroid Build Coastguard Worker         } catch (Exception e) {
141*795d594fSAndroid Build Coastguard Worker             if (!e.getMessage().contains("JVMTI_ERROR_FAILS_VERIFICATION")) {
142*795d594fSAndroid Build Coastguard Worker                 throw new Error(
143*795d594fSAndroid Build Coastguard Worker                         "Unexpected error: Expected failure due to JVMTI_ERROR_FAILS_VERIFICATION",
144*795d594fSAndroid Build Coastguard Worker                         e);
145*795d594fSAndroid Build Coastguard Worker             }
146*795d594fSAndroid Build Coastguard Worker         }
147*795d594fSAndroid Build Coastguard Worker         // Doing this redefinition after a redefinition that failed due to FAILS_VERIFICATION could
148*795d594fSAndroid Build Coastguard Worker         // cause a use-after-free of the Transform2's DexCache by the redefinition code if it
149*795d594fSAndroid Build Coastguard Worker         // happens that the native pointer of the art::DexFile created for the Transform
150*795d594fSAndroid Build Coastguard Worker         // redefinition aliases the one created for Transform2's failed redefinition.
151*795d594fSAndroid Build Coastguard Worker         //
152*795d594fSAndroid Build Coastguard Worker         // Due to the order of checks performed by the redefinition code FAILS_VERIFICATION is the
153*795d594fSAndroid Build Coastguard Worker         // only failure mode that can cause Use-after-frees in this way.
154*795d594fSAndroid Build Coastguard Worker         //
155*795d594fSAndroid Build Coastguard Worker         // This should never throw any exceptions (except perhaps OOME in very strange
156*795d594fSAndroid Build Coastguard Worker         // circumstances).
157*795d594fSAndroid Build Coastguard Worker         Redefinition.doMultiClassRedefinition(TRANSFORM_INITIAL);
158*795d594fSAndroid Build Coastguard Worker     }
159*795d594fSAndroid Build Coastguard Worker }
160