View Javadoc
1   /*
2    * Licensed to the Apache Software Foundation (ASF) under one
3    * or more contributor license agreements.  See the NOTICE file
4    * distributed with this work for additional information
5    * regarding copyright ownership.  The ASF licenses this file
6    * to you under the Apache License, Version 2.0 (the
7    * "License"); you may not use this file except in compliance
8    * with the License.  You may obtain a copy of the License at
9    *
10   *   https://www.apache.org/licenses/LICENSE-2.0
11   *
12   * Unless required by applicable law or agreed to in writing,
13   * software distributed under the License is distributed on an
14   * "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
15   * KIND, either express or implied.  See the License for the
16   * specific language governing permissions and limitations
17   * under the License.
18   */
19  package org.apache.bcel.generic;
20  
21  import java.io.DataOutputStream;
22  import java.io.IOException;
23  
24  import org.apache.bcel.classfile.ClassFormatException;
25  import org.apache.bcel.util.ByteSequence;
26  
27  /**
28   * TABLESWITCH - Switch within given range of values, that is, low..high
29   *
30   * @see SWITCH
31   */
32  public class TABLESWITCH extends Select {
33  
34      /**
35       * Empty constructor needed for Instruction.readInstruction. Not to be used otherwise.
36       */
37      TABLESWITCH() {
38      }
39  
40      /**
41       * Constructs a TABLESWITCH instruction.
42       *
43       * @param match sorted array of match values, match[0] must be low value, match[match_length - 1] high value.
44       * @param targets where to branch for matched values.
45       * @param defaultTarget default branch.
46       */
47      public TABLESWITCH(final int[] match, final InstructionHandle[] targets, final InstructionHandle defaultTarget) {
48          super(org.apache.bcel.Const.TABLESWITCH, match, targets, defaultTarget);
49          /* Alignment remainder assumed 0 here, until dump time */
50          final short length = (short) (13 + getMatchLength() * 4);
51          super.setLength(length);
52          setFixedLength(length);
53      }
54  
55      /**
56       * Call corresponding visitor method(s). The order is: Call visitor methods of implemented interfaces first, then call
57       * methods according to the class hierarchy in descending order, that is, the most specific visitXXX() call comes last.
58       *
59       * @param v Visitor object.
60       */
61      @Override
62      public void accept(final Visitor v) {
63          v.visitVariableLengthInstruction(this);
64          v.visitStackConsumer(this);
65          v.visitBranchInstruction(this);
66          v.visitSelect(this);
67          v.visitTABLESWITCH(this);
68      }
69  
70      /**
71       * Dumps instruction as byte code to stream out.
72       *
73       * @param out Output stream.
74       */
75      @Override
76      public void dump(final DataOutputStream out) throws IOException {
77          super.dump(out);
78          final int matchLength = getMatchLength();
79          final int low = matchLength > 0 ? super.getMatch(0) : 0;
80          out.writeInt(low);
81          final int high = matchLength > 0 ? super.getMatch(matchLength - 1) : 0;
82          out.writeInt(high);
83          for (int i = 0; i < matchLength; i++) {
84              out.writeInt(setIndices(i, getTargetOffset(super.getTarget(i))));
85          }
86      }
87  
88      /**
89       * Reads needed data (for example index) from file.
90       */
91      @Override
92      protected void initFromFile(final ByteSequence bytes, final boolean wide) throws IOException {
93          super.initFromFile(bytes, wide);
94          final int low = bytes.readInt();
95          final int high = bytes.readInt();
96          // Compute in long arithmetic to guard against integer overflow, and require the match table to actually fit into the remaining code bytes (4 bytes
97          // per jump offset). The low and high fields are attacker-controlled in a malicious class file and could otherwise request a multi-gigabyte
98          // allocation, or a negative array size, before a single table entry is read.
99          final long matchLengthLong = (long) high - low + 1;
100         if (matchLengthLong < 0 || matchLengthLong > bytes.available() / 4) {
101             throw new ClassFormatException(
102                     "Invalid tableswitch: low=" + low + ", high=" + high + ", but only " + bytes.available() + " bytes of code remain.");
103         }
104         final int matchLength = (int) matchLengthLong;
105         setMatchLength(matchLength);
106         final short fixedLength = (short) (13 + matchLength * 4);
107         setFixedLength(fixedLength);
108         super.setLength((short) (fixedLength + super.getPadding()));
109         super.setMatches(new int[matchLength]);
110         super.setIndices(new int[matchLength]);
111         super.setTargets(new InstructionHandle[matchLength]);
112         for (int i = 0; i < matchLength; i++) {
113             super.setMatch(i, low + i);
114             super.setIndices(i, bytes.readInt());
115         }
116     }
117 }