Skip to content

Commit 7cba5e9

Browse files
committed
fix: UB when upcasting yoga sentinel value
1 parent 8e74464 commit 7cba5e9

1 file changed

Lines changed: 8 additions & 2 deletions

File tree

  • packages/react-native/ReactCommon/yoga/yoga

‎packages/react-native/ReactCommon/yoga/yoga/YGNode.cpp‎

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -279,11 +279,17 @@ size_t YGNodeGetChildCount(const YGNodeConstRef node) {
279279
}
280280

281281
YGNodeRef YGNodeGetOwner(const YGNodeRef node) {
282-
return resolveRef(node)->getOwner();
282+
// The owner is returned verbatim as an opaque handle. It may hold a
283+
// non-dereferenceable sentinel value, so it must not undergo a
284+
// derived-to-base conversion that asserts pointer alignment/validity.
285+
return reinterpret_cast<YGNodeRef>(resolveRef(node)->getOwner());
283286
}
284287

285288
YGNodeRef YGNodeGetParent(const YGNodeRef node) {
286-
return resolveRef(node)->getOwner();
289+
// The owner is returned verbatim as an opaque handle. It may hold a
290+
// non-dereferenceable sentinel value, so it must not undergo a
291+
// derived-to-base conversion that asserts pointer alignment/validity.
292+
return reinterpret_cast<YGNodeRef>(resolveRef(node)->getOwner());
287293
}
288294

289295
void YGNodeSetConfig(YGNodeRef node, YGConfigRef config) {

0 commit comments

Comments
 (0)