From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on server-vie001.gnuweeb.org X-Spam-Level: *** X-Spam-Status: No, score=3.8 required=5.0 tests=DKIM_ADSP_CUSTOM_MED, DKIM_INVALID,DKIM_SIGNED,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,NML_ADSP_CUSTOM_MED,NO_DNS_FOR_FROM, SPF_PASS autolearn=no autolearn_force=no version=3.4.6 Authentication-Results: server-vie001.gnuweeb.org; dkim=pass (2048-bit key; unprotected) header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20251104 header.b=gA/Z9iQo; dkim-atps=neutral Received: by server-vie001.gnuweeb.org (Postfix, from userid 1000) id A2E042EC215D; Tue, 28 Jul 2026 08:46:35 +0000 (UTC) Authentication-Results: server-vie001.gnuweeb.org; dmarc=pass (p=none dis=none) header.from=gmail.com Received-SPF: Pass (mailfrom) identity=mailfrom; client-ip=2a00:1450:4864:20::32f; helo=mail-wm1-x32f.google.com; envelope-from=david.laight.linux@gmail.com; receiver= Received: from mail-wm1-x32f.google.com (mail-wm1-x32f.google.com [IPv6:2a00:1450:4864:20::32f]) by server-vie001.gnuweeb.org (Postfix) with ESMTPS id 450592EC214F for ; Tue, 28 Jul 2026 08:46:33 +0000 (UTC) Received: by mail-wm1-x32f.google.com with SMTP id 5b1f17b1804b1-4954f5e8020so17308115e9.2 for ; Tue, 28 Jul 2026 01:46:32 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785228388; x=1785833188; darn=gnuweeb.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=TY5i83xUXytTq3W3hDjBOHFIBU26TkcCDfOy7gh1KLI=; b=gA/Z9iQokOlFmo59Cy2yaWOOvZQS+3HgsebVuaEGa53dKosJlcg4qzto/TL1t8m3Mq tmjh85fUcKVcOdXOYeZLjLUJX23aw9VUgJXDeYZhR0I5muUelrrSZr0VwzHQdAKPYgDV RSrbz3h/TPwoOya++WHQGPlOgYeke7xSxwxLuIUERDiUUA4wgTEkKy6kQ3Ev8340Gx12 CZsKFMlMOyp9VUmjxCRsVrh8eHNGf2B9HmQqDDz2EZsaFO+5bSZdnN75qHWJHujDSfRG plDp2qborMUL8nkVTq9f05aymwk76r5VFhPj/M6lhK3WbYnXZ4EzBpWi68zcPr0OynVA hdHg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785228388; x=1785833188; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=TY5i83xUXytTq3W3hDjBOHFIBU26TkcCDfOy7gh1KLI=; b=Y08F/dGOK+58vG+xl1qmh9BAO4odaXzmmvULMLuRdZs49dKHmheUTiWHxAJ42JQ44D 98+y325G1kjQnOmAcpwUEKo/YcPuaOPGDLmh/pR0WBcfGWvo6tTizLDli04MQGsW68qj VT2Fqa9d3d9y0P+66hbzfc7UqIJkeEbVRHsJZlfL8k+Od+oYANAu4obCiWMNDT8yhpXC bs9iTyeNjurHHEwD3Sjam61yCFsBqYxSS/Mm+uDcXKWCyu6cE4TXhqeSS/pEwjYO3jAl WXJPC7/No8G5KHJKzh5t21c4cdQnca2aAVFg70EptNh3PZR9VYVubV3ovV43Ls/DYJvg DdBQ== X-Forwarded-Encrypted: i=1; AHgh+RqLwejuBvbD3RPWR/Qd1/b/tcA/iGSv54U7MJBlkZJt2dpgPLzKMYsRTW51qrkVdgOyM4hh@gnuweeb.org X-Gm-Message-State: AOJu0Yxg0C5dnerBi/LF4uv7X177IAa2zZk65VjySlq4Gshr/ZL9qJcp 4k++i4iovuFN42tk0jlb1KoMe70dxrE71IBqhXoYSnqaOq8vGHSR2VRU X-Gm-Gg: AR+sD11hR1wnX3Ipl16GrZiU0c0Gh2v/smxwhGji3zuMr2dMP5aJ/Q7iTiOo9ctE5o4 Rqfvmx/XXSKIpO4KFD/8HzvMhfoHTVBwuQyrjIueKbGi/pT1o/9Z1XLamtyppZNcoU7WR/JocPN W7mXck2KCnUzaKhdXS7qErWQqc5XGV2SajTUZ0Ys+DAcUfCYGggeNeIWEYYZaf9aW4yGUZuZqCW jwoepzfWfdV8vC5geg7m8UU8XbgfokgqQqw/o8nQMhYodqJeYAsO1Mv845kfklrxVQ7qohvHrev mGnlQHau40cpcPvCG4uMeSxjlsTMN3DW0yabP9B58Wp52ppAbc0MFtH5lyBeA87wWyxi+r2Zxzo IRUcY327x+FDrkFW3mx8Wk29yOxG+I/6xuJ32OXZ7Bhw5+cGBNMu46CcpJR7urD4XHSmkaAzL4K +3f0MC+Nrx5n6Zl32TP5NjDsd8OaVtg+PZUbz4q11BZ5Lup3Jk2w== X-Received: by 2002:a05:600c:3b13:b0:495:5890:8f6c with SMTP id 5b1f17b1804b1-496c653d3dcmr17415025e9.7.1785228387869; Tue, 28 Jul 2026 01:46:27 -0700 (PDT) Received: from pumpkin (82-69-66-36.dsl.in-addr.zen.co.uk. [82.69.66.36]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4957f9b8b67sm340321705e9.4.2026.07.28.01.46.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 01:46:27 -0700 (PDT) Date: Tue, 28 Jul 2026 09:46:25 +0100 From: David Laight To: Ammar Faizi Cc: Willy Tarreau , Thomas =?UTF-8?B?V2Vpw59zY2h1aA==?= , Linux Kernel Mailing List , Linux Kselftest Mailing List , LLVM Mailing List , Yichun Zhang , Alviro Iskandar Setiawan , Shuah Khan , Nathan Chancellor , Nick Desaulniers , Bill Wendling , Justin Stitt , gwml@gnuweeb.org Subject: Re: [PATCH 2/4] tools/nolibc: stdlib: avoid signed overflow in abs() and friends Message-ID: <20260728094626.0fb1a467@pumpkin> In-Reply-To: <20260726101306.3772237-3-ammarfaizi2@openresty.com> References: <20260726101306.3772237-1-ammarfaizi2@openresty.com> <20260726101306.3772237-3-ammarfaizi2@openresty.com> X-Mailer: Claws Mail 4.1.1 (GTK 3.24.38; arm-unknown-linux-gnueabihf) MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit List-Id: On Sun, 26 Jul 2026 17:13:03 +0700 Ammar Faizi wrote: > Negating the smallest negative value of a signed type overflows, which > is undefined behavior. The selftests are built with: > > -fsanitize=undefined -fsanitize-trap=all > > so a caller passing INT_MIN does not merely get an unspecified answer, > it dies (on both x86-64 and i386): Thinking more, that is probably the correct thing to do. 'Undefined behaviour' means exactly that. It tends to be used for things that might cause traps on some architectures. But I believe 'undefined behaviour' is exactly that, erasing your hard disk (or starting a nuclear war) are both valid. David > > A simple test program: > > printf("x = %d\n", abs(INT_MIN)); > > $ ./ab > Illegal instruction (core dumped) > > (gdb) bt > #0 0x0000000000401009 in main () > (gdb) x/6i main > 0x401000
: mov $0x80000000,%eax > 0x401005 : neg %eax > 0x401007 : jno 0x40100b > => 0x401009 : ud2 > 0x40100b : push %rax > 0x40100c : mov $0x80000000,%esi > > Negate in the corresponding unsigned type instead. The value still > cannot be represented in the result type, so the minimum is returned > unchanged. > > Cc: Yichun Zhang > Cc: Alviro Iskandar Setiawan > Fixes: bf5e8a78bede ("tools/nolibc: add abs() and friends") > Signed-off-by: Ammar Faizi > --- > tools/include/nolibc/stdlib.h | 12 +++++++++--- > 1 file changed, 9 insertions(+), 3 deletions(-) > > diff --git a/tools/include/nolibc/stdlib.h b/tools/include/nolibc/stdlib.h > index 1816c2368b68..8d86044f759f 100644 > --- a/tools/include/nolibc/stdlib.h > +++ b/tools/include/nolibc/stdlib.h > @@ -32,22 +32,28 @@ static __attribute__((unused)) char itoa_buffer[21]; > * As much as possible, please keep functions alphabetically sorted. > */ > > +/* > + * The absolute value of the smallest negative value is not representable in > + * the result type. Negate in the unsigned type so that the overflow is > + * defined and return it unchanged, like the other libcs do. > + */ > + > static __inline__ > int abs(int j) > { > - return j >= 0 ? j : -j; > + return j >= 0 ? j : (int)-(unsigned int)j; > } > > static __inline__ > long labs(long j) > { > - return j >= 0 ? j : -j; > + return j >= 0 ? j : (long)-(unsigned long)j; > } > > static __inline__ > long long llabs(long long j) > { > - return j >= 0 ? j : -j; > + return j >= 0 ? j : (long long)-(unsigned long long)j; > } > > /* must be exported, as it's used by libgcc for various divide functions */