1 /*
2 * Licensed to the Apache Software Foundation (ASF) under one
3 * or more contributor license agreements. See the NOTICE file
4 * distributed with this work for additional information
5 * regarding copyright ownership. The ASF licenses this file
6 * to you under the Apache License, Version 2.0 (the
7 * "License"); you may not use this file except in compliance
8 * with the License. You may obtain a copy of the License at
9 *
10 * https://www.apache.org/licenses/LICENSE-2.0
11 *
12 * Unless required by applicable law or agreed to in writing,
13 * software distributed under the License is distributed on an
14 * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15 * KIND, either express or implied. See the License for the
16 * specific language governing permissions and limitations
17 * under the License.
18 */
19 package org.apache.bcel.generic;
20
21 import java.io.DataOutputStream;
22 import java.io.IOException;
23
24 import org.apache.bcel.classfile.ClassFormatException;
25 import org.apache.bcel.util.ByteSequence;
26
27 /**
28 * TABLESWITCH - Switch within given range of values, that is, low..high
29 *
30 * @see SWITCH
31 */
32 public class TABLESWITCH extends Select {
33
34 /**
35 * Empty constructor needed for Instruction.readInstruction. Not to be used otherwise.
36 */
37 TABLESWITCH() {
38 }
39
40 /**
41 * Constructs a TABLESWITCH instruction.
42 *
43 * @param match sorted array of match values, match[0] must be low value, match[match_length - 1] high value.
44 * @param targets where to branch for matched values.
45 * @param defaultTarget default branch.
46 */
47 public TABLESWITCH(final int[] match, final InstructionHandle[] targets, final InstructionHandle defaultTarget) {
48 super(org.apache.bcel.Const.TABLESWITCH, match, targets, defaultTarget);
49 /* Alignment remainder assumed 0 here, until dump time */
50 final short length = (short) (13 + getMatchLength() * 4);
51 super.setLength(length);
52 setFixedLength(length);
53 }
54
55 /**
56 * Call corresponding visitor method(s). The order is: Call visitor methods of implemented interfaces first, then call
57 * methods according to the class hierarchy in descending order, that is, the most specific visitXXX() call comes last.
58 *
59 * @param v Visitor object.
60 */
61 @Override
62 public void accept(final Visitor v) {
63 v.visitVariableLengthInstruction(this);
64 v.visitStackConsumer(this);
65 v.visitBranchInstruction(this);
66 v.visitSelect(this);
67 v.visitTABLESWITCH(this);
68 }
69
70 /**
71 * Dumps instruction as byte code to stream out.
72 *
73 * @param out Output stream.
74 */
75 @Override
76 public void dump(final DataOutputStream out) throws IOException {
77 super.dump(out);
78 final int matchLength = getMatchLength();
79 final int low = matchLength > 0 ? super.getMatch(0) : 0;
80 out.writeInt(low);
81 final int high = matchLength > 0 ? super.getMatch(matchLength - 1) : 0;
82 out.writeInt(high);
83 for (int i = 0; i < matchLength; i++) {
84 out.writeInt(setIndices(i, getTargetOffset(super.getTarget(i))));
85 }
86 }
87
88 /**
89 * Reads needed data (for example index) from file.
90 */
91 @Override
92 protected void initFromFile(final ByteSequence bytes, final boolean wide) throws IOException {
93 super.initFromFile(bytes, wide);
94 final int low = bytes.readInt();
95 final int high = bytes.readInt();
96 // Compute in long arithmetic to guard against integer overflow, and require the match table to actually fit into the remaining code bytes (4 bytes
97 // per jump offset). The low and high fields are attacker-controlled in a malicious class file and could otherwise request a multi-gigabyte
98 // allocation, or a negative array size, before a single table entry is read.
99 final long matchLengthLong = (long) high - low + 1;
100 if (matchLengthLong < 0 || matchLengthLong > bytes.available() / 4) {
101 throw new ClassFormatException(
102 "Invalid tableswitch: low=" + low + ", high=" + high + ", but only " + bytes.available() + " bytes of code remain.");
103 }
104 final int matchLength = (int) matchLengthLong;
105 setMatchLength(matchLength);
106 final short fixedLength = (short) (13 + matchLength * 4);
107 setFixedLength(fixedLength);
108 super.setLength((short) (fixedLength + super.getPadding()));
109 super.setMatches(new int[matchLength]);
110 super.setIndices(new int[matchLength]);
111 super.setTargets(new InstructionHandle[matchLength]);
112 for (int i = 0; i < matchLength; i++) {
113 super.setMatch(i, low + i);
114 super.setIndices(i, bytes.readInt());
115 }
116 }
117 }