From 5c9bb80638ec05b32eaa129a8c763ac6bb3a5cb4 Mon Sep 17 00:00:00 2001 From: JosJuice Date: Sat, 13 Apr 2024 12:08:43 +0200 Subject: Memmap: Replace GetPointer with GetSpanForAddress To ensure memory safety, callers of GetPointer have to perform a bounds check. But how is this bounds check supposed to be performed? GetPointerForRange contained one implementation of a bounds check, but it was cumbersome, and it also isn't obvious why it's correct. To make doing the right thing easier, this commit changes GetPointer to return a span that tells the caller how many bytes it's allowed to access. --- Source/Core/VideoBackends/Software/TextureSampler.cpp | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) (limited to 'Source/Core/VideoBackends/Software/TextureSampler.cpp') diff --git a/Source/Core/VideoBackends/Software/TextureSampler.cpp b/Source/Core/VideoBackends/Software/TextureSampler.cpp index d5222384f0..f9182441bb 100644 --- a/Source/Core/VideoBackends/Software/TextureSampler.cpp +++ b/Source/Core/VideoBackends/Software/TextureSampler.cpp @@ -5,6 +5,7 @@ #include #include +#include #include "Common/CommonTypes.h" #include "Common/MsgHandler.h" @@ -137,7 +138,9 @@ void SampleMip(s32 s, s32 t, s32 mip, bool linear, u8 texmap, u8* sample) auto& memory = system.GetMemory(); const u32 imageBase = texUnit.texImage3.image_base << 5; - imageSrc = memory.GetPointer(imageBase); + // TODO: For memory safety, we need to check the size of this span + std::span span = memory.GetSpanForAddress(imageBase); + imageSrc = span.data(); } int image_width_minus_1 = ti0.width; -- cgit v1.2.3