fix(audio): harden AudioOut2 stack out-buffer writes against canary smash (#532)

Titles that stack-allocate AudioOut2 outs next to the frame canary were
corrupted by oversized or mistyped HLE writes; keep ContextPush pacing.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
MarcelMediaDev
2026-07-23 13:34:40 +01:00
committed by GitHub
parent 956da769a3
commit e13cb28267
5 changed files with 657 additions and 72 deletions
+31 -1
View File
@@ -7,15 +7,18 @@ namespace SharpEmu.Libs.Tests;
// A single contiguous guest region backed by a byte[]. Enough to hand C strings and small
// structures to HLE exports under test without a live guest.
internal sealed class FakeCpuMemory : ICpuMemory
internal sealed class FakeCpuMemory : ICpuMemory, IGuestMemoryAllocator
{
private readonly ulong _base;
private readonly byte[] _storage;
private ulong _allocBump;
public FakeCpuMemory(ulong baseAddress, int size)
{
_base = baseAddress;
_storage = new byte[size];
// Bump from the top so test fixtures at low offsets stay intact.
_allocBump = baseAddress + (ulong)size;
}
public bool TryRead(ulong virtualAddress, Span<byte> destination)
@@ -40,6 +43,33 @@ internal sealed class FakeCpuMemory : ICpuMemory
return true;
}
public bool TryAllocateGuestMemory(ulong size, ulong alignment, out ulong address)
{
address = 0;
if (size == 0 || alignment == 0 || (alignment & (alignment - 1)) != 0)
{
return false;
}
var alignedSize = (size + alignment - 1) & ~(alignment - 1);
if (alignedSize > _allocBump - _base)
{
return false;
}
var next = (_allocBump - alignedSize) & ~(alignment - 1);
if (next < _base)
{
return false;
}
_allocBump = next;
address = next;
return true;
}
public bool TryFreeGuestMemory(ulong address) => false;
public ulong WriteCString(ulong virtualAddress, string text)
{
var bytes = System.Text.Encoding.UTF8.GetBytes(text);