From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from [87.239.111.99] (localhost [127.0.0.1]) by dev.tarantool.org (Postfix) with ESMTP id DB2036ECCD; Fri, 24 Jul 2026 15:42:25 +0300 (MSK) DKIM-Filter: OpenDKIM Filter v2.11.0 dev.tarantool.org DB2036ECCD DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tarantool.org; s=dev; t=1784896946; bh=r5d4ApCqz/3hmHLHM84oC3q0FPvkL9xNc+D5qXhe5jo=; h=To:Date:Subject:List-Id:List-Unsubscribe:List-Archive:List-Post: List-Help:List-Subscribe:From:Reply-To:From; b=qlvcrntD/Em3MXYtf4NDFW5U3VlLMzd/+f4OBF9eBhapzYnYT/WV53tiq0cn6EDUu PC03XguzbPMmkvwfUOYrKwj0XSa7SSfGI21WZ5nqk0sOtFSBiJ/ojgb4YaqueCUdyD 2xKtulll7pYdi3AdSWZcVJ6Z5d9pyg0p/wK7PoZ8= Received: from mail-lj1-f174.google.com (mail-lj1-f174.google.com [209.85.208.174]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by dev.tarantool.org (Postfix) with ESMTPS id 6AB1B6ECCD for ; Fri, 24 Jul 2026 15:42:25 +0300 (MSK) DKIM-Filter: OpenDKIM Filter v2.11.0 dev.tarantool.org 6AB1B6ECCD Received: by mail-lj1-f174.google.com with SMTP id 38308e7fff4ca-39c8e65e3f5so3109721fa.0 for ; Fri, 24 Jul 2026 05:42:25 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784896945; x=1785501745; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=oPyAEYLo0f/4hF2fOAhn/1MMskL/N4hDd5TfJR55tNI=; b=E2e69rGqciOaL0v5YEWIBERaao5ynJNZwazWGmfc7b1V5uGaflU7q4yGvg2TGrRPvg fataj9adIVbwjKFWZ2lCBxmKsyDy0JTPINpwe6pPLYZHUA5dPH1s9T//d1cT4nIYOAd+ nylzeU0sVJ63ZU4UPxd6h0GO+ZqaBTZk0iTVR1x8Ys0b1jWW/BGG6OrYZX6mF5kXZzko L83HUwZ084zqqEF+zS+8t7xeqXvu14HyISXYwKsKmO2rm77yjTQpnXaeAaVmhoNx89xT cYpc9tSoAth70x5A+cRIUb4Jwzv/Hq/c6sYZ9bH/RuUM7JP/gvjRZHAe0yUNyQNAT/P2 FQvA== X-Gm-Message-State: AOJu0Yz93i0sPqAMwbfkQiGEUI7OWPRX1ldtVb30w2wRGBRShdPo78fz Me01+RbTLUvos8hHWfkvIbNglbP4rWnGLwwG2HzsX9+wT5I0Fx6jnvMjSzi5tV18 X-Gm-Gg: AR+sD12ASEbaXwWvBsCSFp1xn0+GaOWDjfxsLiDmVf+Mu1xeQw75YVw+AWOckt3oOR4 4esz4Xuo/ZgH3spbv8TZrIqXtcXoAdnP34HfZVsLPapew0b8DYfegQNKf7wBMf7b5xp5LqZulAS 5wRYvieQL0jv8wC49TD9Nb44SDmjLYfNKAdkGZ/tARHI3GUE/aMGbTgv72bfqF3MDJNvSMGuAhf HdP0luVVNW3pOZLmJBL97r1rrhPHpIdDuyC+P9ud9OmDZnvhXgMmUG6BFMC9mKpj06mvRlCrhpY 2MhmSzu62qOWfFGuSXmxUKr3OO6eFPCEmU0idLd6r7SJw4kLQaEdxpPZmaylOC1fkptupKQsN/O l3tBZpnA+UPkspKE1sp0rxXZHViXUtaQVL2tFZGMhZj3n5GcAVTlMDxa1Jo5T+7/kdYRg8RNmR6 oj4Zxe0tphjWhelxgH X-Received: by 2002:a2e:a9a3:0:b0:39f:1a11:7c78 with SMTP id 38308e7fff4ca-39f1a117ee6mr6315911fa.41.1784896944479; Fri, 24 Jul 2026 05:42:24 -0700 (PDT) Received: from localhost ([2a06:a780:1000:2::f288:7708]) by smtp.gmail.com with ESMTPSA id 38308e7fff4ca-39ef6c4274bsm13304141fa.24.2026.07.24.05.42.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 24 Jul 2026 05:42:23 -0700 (PDT) X-Google-Original-From: Sergey Bronnikov To: tarantool-patches@dev.tarantool.org, Sergey Kaplun , e.temirgaleev@tarantool.org Date: Fri, 24 Jul 2026 15:42:16 +0300 Message-ID: <7266d024dc58e71ec74929a2f2973c4454161c59.1784895433.git.sergeyb@tarantool.org> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Subject: [Tarantool-patches] [PATCH luajit] FFI: Prevent sanitizer warning in carith_ptr(). X-BeenThere: tarantool-patches@dev.tarantool.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: Tarantool development patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , From: Sergey Bronnikov via Tarantool-patches Reply-To: Sergey Bronnikov Errors-To: tarantool-patches-bounces@dev.tarantool.org Sender: "Tarantool-patches" From: Mike Pall Reported by Sergey Bronnikov. (cherry picked from commit c3b379bf50c8819c61daa3afd9f21d9ec5708bd5) The Undefined Behaviour Sanitizer [1] produce a warning about signed integer overflow in the function carith_ptr(), when idx equals INT_MIN in the expression idx = -idx. In practice, negating -2147483648 wraps back to itself instead of producing the correct positive value, leading to incorrect pointer arithmetic in carith_ptr() for MM_sub (pointer subtraction). The patch fixes that by converting idx to unsigned (uintptr_t), computes two's complement negation via bitwise negation + 1 (safe from overflow in unsigned arithmetic), and casts back to ptrdiff_t. This avoids signed overflow entirely and correctly negates even the INT_MIN edge case. [1]: https://clang.llvm.org/docs/UndefinedBehaviorSanitizer.html Sergey Bronnikov: * added the description and the test for the problem Part of tarantool/tarantool#12480 --- Branch: https://github.com/tarantool/luajit/tree/ligurio/lj-1459-ub-carith_ptr Related issues: - https://github.com/LuaJIT/LuaJIT/issues/1459 - https://github.com/tarantool/tarantool/issues/12880 src/lj_carith.c | 2 +- .../lj-1459-subtraction-carith.test.lua | 16 ++++++++++++++++ 2 files changed, 17 insertions(+), 1 deletion(-) create mode 100644 test/tarantool-tests/lj-1459-subtraction-carith.test.lua diff --git a/src/lj_carith.c b/src/lj_carith.c index eb56d552..e971bfc2 100644 --- a/src/lj_carith.c +++ b/src/lj_carith.c @@ -135,7 +135,7 @@ static int carith_ptr(lua_State *L, CTState *cts, CDArith *ca, MMS mm) return 0; lj_cconv_ct_ct(cts, ctype_get(cts, CTID_INT_PSZ), ca->ct[1], (uint8_t *)&idx, ca->p[1], 0); - if (mm == MM_sub) idx = -idx; + if (mm == MM_sub) idx = (ptrdiff_t)(~(uintptr_t)idx+1u); } else if (mm == MM_add && ctype_isnum(ctp->info) && (ctype_isptr(ca->ct[1]->info) || ctype_isrefarray(ca->ct[1]->info))) { /* Swap pointer and index. */ diff --git a/test/tarantool-tests/lj-1459-subtraction-carith.test.lua b/test/tarantool-tests/lj-1459-subtraction-carith.test.lua new file mode 100644 index 00000000..df401a56 --- /dev/null +++ b/test/tarantool-tests/lj-1459-subtraction-carith.test.lua @@ -0,0 +1,16 @@ +local tap = require('tap') + +-- The test file to demonstrate UBSan warning in carith_ptr(). +-- See also: https://github.com/LuaJIT/LuaJIT/issues/1459. +local test = tap.test('lj-1459-subtraction-carith') + +test:plan(2) + +local func = load('_ = nil - 0LL%0') +local res, err = pcall(func) + +test:is(res, false, 'correct result') +local error_msg = "attempt to perform arithmetic on 'nil' and 'int64_t'" +test:ok(err:match(error_msg), 'error on subtraction') + +test:done(true) -- 2.43.0