From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from [87.239.111.99] (localhost [127.0.0.1]) by dev.tarantool.org (Postfix) with ESMTP id BC6616F15A; Fri, 24 Jul 2026 12:39:57 +0300 (MSK) DKIM-Filter: OpenDKIM Filter v2.11.0 dev.tarantool.org BC6616F15A DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tarantool.org; s=dev; t=1784885997; bh=3A925RTkOi5aklZ79UqZOHrySqb1c7N2yFPwgEqzj6s=; h=Date:To:Cc:References:In-Reply-To:Subject:List-Id: List-Unsubscribe:List-Archive:List-Post:List-Help:List-Subscribe: From:Reply-To:From; b=BIw1a2J/rXD5c8c5hq7nHWdfGNMsAPh+Vz5VO8obdni715GmW1tF1DkWs1h8MbcPB Vnblu0kKRhtwrrdYshTQ2XzXGPeUjQa+pLjrxQ01sUtIxbeW2D71b0qzidmitT3V6i rOIyhPluEgqeazB6STi5EUdFMrY0Rh67gDDSt27c= Received: from send174.i.mail.ru (send174.i.mail.ru [95.163.59.13]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by dev.tarantool.org (Postfix) with ESMTPS id E77426F15A for ; Fri, 24 Jul 2026 12:39:56 +0300 (MSK) DKIM-Filter: OpenDKIM Filter v2.11.0 dev.tarantool.org E77426F15A Received: by exim-smtp-66d48668b6-c6rjk with esmtpa (envelope-from ) id 1wnCNn-000000005i7-24nN; Fri, 24 Jul 2026 12:39:56 +0300 Content-Type: multipart/alternative; boundary="------------r2eJzFheGRAollR8iBJumDXb" Message-ID: <238a941e-57e7-4737-ab2f-ae740723507b@tarantool.org> Date: Fri, 24 Jul 2026 12:39:53 +0300 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Content-Language: en-US To: Sergey Kaplun , Evgeniy Temirgaleev Cc: tarantool-patches@dev.tarantool.org References: <20260720125943.2531443-1-skaplun@tarantool.org> In-Reply-To: <20260720125943.2531443-1-skaplun@tarantool.org> X-Mailru-Src: smtp X-4EC0790: 10 X-7564579A: 78E4E2B564C1792B X-77F55803: 4F1203BC0FB41BD93ED3C6BF6FFA701F47C7C3D94A5A406F9166DAAD7C6D9BC8182A05F53808504052D4CBAF9EC470123DE06ABAFEAF6705BA17AB09528F4D0434C0F47F8AC9EB173B45A48541D55DDE X-7FA49CB5: FF5795518A3D127A4AD6D5ED66289B5278DA827A17800CE7BF5628FE6781D09AEA1F7E6F0F101C67BD4B6F7A4D31EC0BCC500DACC3FED6E28638F802B75D45FF8AA50765F7900637AC83A81C8FD4AD23D82A6BABE6F325AC2E85FA5F3EDFCBAA7353EFBB55337566DDF253B6BCADDB79865D53237F61E4A33935117EDF9E75D874A48A02C4D3586C389733CBF5DBD5E913377AFFFEAFD269176DF2183F8FC7C0B687D752F9FE62218941B15DA834481FCF19DD082D7633A0EF3E4896CB9E6436389733CBF5DBD5E9D5E8D9A59859A8B68CE9D8A6861299E6CC7F00164DA146DA6F5DAA56C3B73B237318B6A418E8EAB86D1867E19FE14079C09775C1D3CA48CF3D321E7403792E342EB15956EA79C166A417C69337E82CC275ECD9A6C639B01B78DA827A17800CE7509F8262B3B2DD16731C566533BA786AA5CC5B56E945C8DA X-C1DE0DAB: 0D63561A33F958A51AB76A7BAB7321DF5002B1117B3ED696068971B1F410F52B69995D676B7B4CBE823CB91A9FED034534781492E4B8EEAD85CCBA673D36D1A4BDAD6C7F3747799A X-C8649E89: 1C3962B70DF3F0AD73CAD6646DEDE191716CD42B3DD1D34CAB70F9BE574AE9C625B6776AC983F447FC0B9F89525902EE6F57B2FD27647F25E66C117BDB76D659D4581C24EB573A34B04464EA2B2A333640B4A32B353DFCFA69F27F12F32C159F322B59A15B01DFADB8341EE9D5BE9A0A626AEF57F6E6AEA8C9F35D840A22CC1E16B5B327561FFF4B6536EB022892E5344C41F94D744909CE2512F26BEC029E55448553D2254B8D95CD72808BE417F3B9E0E7457915DAA85F X-D57D3AED: 3ZO7eAau8CL7WIMRKs4sN3D3tLDjz0dLbV79QFUyzQ2Ujvy7cMT6pYYqY16iZVKkSc3dCLJ7zSJH7+u4VD18S7Vl4ZUrpaVfd2+vE6kuoey4m4VkSEu53w8ahmwBjZKM/YPHZyZHvz5uv+WouB9+ObcCpyrx6l7KImUglyhkEat/+ysWwi0gdhEs0JGjl6ggRWTy1haxBpVdbIX1nthFXMZebaIdHP2ghjoIc/363UZI6Kf1ptIMVWmxowtcrDwUb8r2U9uHkTQ= X-DA7885C5: 1CD14B9332825345F255D290C0D534F92AE6917ABDBF254AB92EBCCBAAF72D66D843A6C7A01DE5485B1A4C17EAA7BC4BEF2421ABFA55128DAF83EF9164C44C7E X-Mailru-Sender: 689FA8AB762F7393520AF17B8A65FDE25C644EB4340682C820FFA02F69CE9588B9ACFE790951ED06EF86D5F70DA33880E41E8EF7A07863ECB274557F927329BE2DDF8182D28ACDB545BD1C3CC395C826B4A721A3011E896F X-Mras: Ok Subject: Re: [Tarantool-patches] [PATCH luajit] FFI: Shrink container of packed bitfield. X-BeenThere: tarantool-patches@dev.tarantool.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: Tarantool development patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , From: Sergey Bronnikov via Tarantool-patches Reply-To: Sergey Bronnikov Errors-To: tarantool-patches-bounces@dev.tarantool.org Sender: "Tarantool-patches" This is a multi-part message in MIME format. --------------r2eJzFheGRAollR8iBJumDXb Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit Hello, Sergey, thanks for the patch! LGTM Sergey On 7/20/26 15:59, Sergey Kaplun wrote: > From: Mike Pall > > Reported by Huang Haiyang. > > (cherry picked from commit e4c7d8b38040518d42599eef8ddb5e67aa967a9c) > > The bitfield of packed structure uses the original type size, which > leads to heap-buffer-overflow access on conversions. > > This patch fixes it by adjusting the size of the bitfield container when > necessary. > > Sergey Kaplun: > * added the description and the test for the problem > > Part of tarantool/tarantool#12880 > --- > > Branch:https://github.com/tarantool/luajit/tree/skaplun/lj-1451-ffi-packed-bitfield > Related issues: > *https://github.com/LuaJIT/LuaJIT/issues/1451 > *https://github.com/tarantool/tarantool/issues/12880 > > src/lj_cparse.c | 2 ++ > .../lj-1451-ffi-packed-bitfield.test.lua | 28 +++++++++++++++++++ > 2 files changed, 30 insertions(+) > create mode 100644 test/tarantool-tests/lj-1451-ffi-packed-bitfield.test.lua > > diff --git a/src/lj_cparse.c b/src/lj_cparse.c > index ff23b44b..1b3ce7ec 100644 > --- a/src/lj_cparse.c > +++ b/src/lj_cparse.c > @@ -1341,6 +1341,8 @@ static void cp_struct_layout(CPState *cp, CTypeID sid, CTInfo sattr) > CTALIGN(lj_fls(sz)); > ct->size = (bofs >> 3); /* Store field offset. */ > } else { > + if (csz > amask+1 && bsz <= amask+1) > + csz = amask+1; /* Shrink container of packed bitfield. */ > ct->info = CTINFO(CT_BITFIELD, > (info & (CTF_QUAL|CTF_UNSIGNED|CTF_BOOL)) + > (csz << (CTSHIFT_BITCSZ-3)) + (bsz << CTSHIFT_BITBSZ)); > diff --git a/test/tarantool-tests/lj-1451-ffi-packed-bitfield.test.lua b/test/tarantool-tests/lj-1451-ffi-packed-bitfield.test.lua > new file mode 100644 > index 00000000..07e53f76 > --- /dev/null > +++ b/test/tarantool-tests/lj-1451-ffi-packed-bitfield.test.lua > @@ -0,0 +1,28 @@ > +local tap = require('tap') > + > +-- Test file to demonstrate LuaJIT's incorrect behaviour of the > +-- `#pragma` pack directive for bitfields in structures. > +-- See also:https://github.com/LuaJIT/LuaJIT/issues/1451. > + > +local test = tap.test('lj-1451-ffi-packed-bitfield') > + > +local ffi = require('ffi') > + > +ffi.cdef[[ > +#pragma pack(push, 2) > +typedef struct { > + unsigned intbitfield:1; > +} packed_struct; > +#pragma pack(pop) > +]] > + > +test:plan(2) > + > +local packed = ffi.new('packed_struct') > + > +test:is(packed.bitfield, 0, 'correct 0-initialization') > + > +packed.bitfield = 1 > +test:is(packed.bitfield, 1, 'bitfield set correctly') > + > +test:done(true) --------------r2eJzFheGRAollR8iBJumDXb Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: 7bit

Hello, Sergey,

thanks for the patch! LGTM

Sergey

On 7/20/26 15:59, Sergey Kaplun wrote:
From: Mike Pall <mike>

Reported by Huang Haiyang.

(cherry picked from commit e4c7d8b38040518d42599eef8ddb5e67aa967a9c)

The bitfield of packed structure uses the original type size, which
leads to heap-buffer-overflow access on conversions.

This patch fixes it by adjusting the size of the bitfield container when
necessary.

Sergey Kaplun:
* added the description and the test for the problem

Part of tarantool/tarantool#12880
---

Branch: https://github.com/tarantool/luajit/tree/skaplun/lj-1451-ffi-packed-bitfield
Related issues:
* https://github.com/LuaJIT/LuaJIT/issues/1451
* https://github.com/tarantool/tarantool/issues/12880

 src/lj_cparse.c                               |  2 ++
 .../lj-1451-ffi-packed-bitfield.test.lua      | 28 +++++++++++++++++++
 2 files changed, 30 insertions(+)
 create mode 100644 test/tarantool-tests/lj-1451-ffi-packed-bitfield.test.lua

diff --git a/src/lj_cparse.c b/src/lj_cparse.c
index ff23b44b..1b3ce7ec 100644
--- a/src/lj_cparse.c
+++ b/src/lj_cparse.c
@@ -1341,6 +1341,8 @@ static void cp_struct_layout(CPState *cp, CTypeID sid, CTInfo sattr)
 		     CTALIGN(lj_fls(sz));
 	  ct->size = (bofs >> 3);  /* Store field offset. */
 	} else {
+	  if (csz > amask+1 && bsz <= amask+1)
+	    csz = amask+1;  /* Shrink container of packed bitfield. */
 	  ct->info = CTINFO(CT_BITFIELD,
 	    (info & (CTF_QUAL|CTF_UNSIGNED|CTF_BOOL)) +
 	    (csz << (CTSHIFT_BITCSZ-3)) + (bsz << CTSHIFT_BITBSZ));
diff --git a/test/tarantool-tests/lj-1451-ffi-packed-bitfield.test.lua b/test/tarantool-tests/lj-1451-ffi-packed-bitfield.test.lua
new file mode 100644
index 00000000..07e53f76
--- /dev/null
+++ b/test/tarantool-tests/lj-1451-ffi-packed-bitfield.test.lua
@@ -0,0 +1,28 @@
+local tap = require('tap')
+
+-- Test file to demonstrate LuaJIT's incorrect behaviour of the
+-- `#pragma` pack directive for bitfields in structures.
+-- See also: https://github.com/LuaJIT/LuaJIT/issues/1451.
+
+local test = tap.test('lj-1451-ffi-packed-bitfield')
+
+local ffi = require('ffi')
+
+ffi.cdef[[
+#pragma pack(push, 2)
+typedef struct {
+  unsigned int bitfield:1;
+} packed_struct;
+#pragma pack(pop)
+]]
+
+test:plan(2)
+
+local packed = ffi.new('packed_struct')
+
+test:is(packed.bitfield, 0, 'correct 0-initialization')
+
+packed.bitfield = 1
+test:is(packed.bitfield, 1, 'bitfield set correctly')
+
+test:done(true)
--------------r2eJzFheGRAollR8iBJumDXb--