Clamp aligned_offset in MemorySnapshotSanitized

MemorySanitizer::Sanitize() computes the number of leading unaligned
bytes from the snapshot's base address and uses it as the length of a
memcpy into the data buffer and as the subtrahend for the word count.
When the snapshot is shorter than the alignment offset (an unaligned
base address with a sub-word region), the leading memcpy writes past the
end of the buffer and the word count underflows.

Clamp the offset to the buffer size so that short unaligned regions are
defaced in place.

Add MemorySnapshotSanitized.ShortUnalignedRegion64/32 unit tests
covering every (offset, size) pair below the pointer width.

Bug: 500097298
Change-Id: Ib58b96250631f760329f16d30a0e7b8b062394f2
Reviewed-on: https://chromium-review.googlesource.com/c/crashpad/crashpad/+/8138617
Reviewed-by: Mark Mentovai <mark@chromium.org>
Commit-Queue: Joshua Peraza <jperaza@chromium.org>
3 files changed
tree: 8bc577321f415e425c5e5f4f25c9decf299b3b01
  1. build/
  2. client/
  3. compat/
  4. doc/
  5. handler/
  6. infra/
  7. minidump/
  8. snapshot/
  9. test/
  10. third_party/
  11. tools/
  12. util/
  13. .clang-format
  14. .gitattributes
  15. .gitignore
  16. .gn
  17. .style.yapf
  18. .vpython3
  19. AUTHORS
  20. BUILD.gn
  21. codereview.settings
  22. CONTRIBUTORS
  23. DEPS
  24. LICENSE
  25. navbar.md
  26. OWNERS
  27. package.h
  28. README.md
README.md

Crashpad

Crashpad is a crash-reporting system.

Documentation

Source Code

Crashpad’s source code is hosted in a Git repository at https://chromium.googlesource.com/crashpad/crashpad.

Other Links