From: Sergey Bronnikov via Tarantool-patches <tarantool-patches@dev.tarantool.org>
To: tarantool-patches@dev.tarantool.org,
Sergey Kaplun <skaplun@tarantool.org>,
e.temirgaleev@tarantool.org
Subject: [Tarantool-patches] [PATCH luajit] Prevent sanitizer warnings for lj_tab_new*() and table.new().
Date: Tue, 9 Jun 2026 13:55:53 +0300 [thread overview]
Message-ID: <a809bec02e4feb0a1d5215146c2262926b9094d6.1781002531.git.sergeyb@tarantool.org> (raw)
From: Mike Pall <mike>
Reported by Sergey Bronnikov.
(cherry picked from commit 8f421c81ec6aaae0bcd80e01f4353de200afbbc5)
The Undefined Behaviour Sanitizer [1] produce a warning because
the function `lua_createtable()` takes signed integer arguments,
but the `lj_tab_new_ah()` was not properly validating or converting
these signed values before using them in unsigned arithmetic.
The fix changes the signature of `lj_tab_new_ah()` to accept
uint32_t directly, and adjusts `lua_createtable()` to cast the
incoming signed int values to uint32_t before passing them.
[1]: https://clang.llvm.org/docs/UndefinedBehaviorSanitizer.html
Sergey Bronnikov:
* added the description and the test for the problem
Part of tarantool/tarantool#12480
---
Branch: https://github.com/tarantool/luajit/tree/ligurio/lj-1458-ub-lj_tab_new
Related issues:
- https://github.com/tarantool/tarantool/issues/12480
- https://github.com/LuaJIT/LuaJIT/issues/1458
src/lj_api.c | 2 +-
src/lj_tab.c | 4 +--
src/lj_tab.h | 2 +-
.../lj-1458-ub-table.new.test.lua | 30 +++++++++++++++++++
4 files changed, 34 insertions(+), 4 deletions(-)
create mode 100644 test/tarantool-tests/lj-1458-ub-table.new.test.lua
diff --git a/src/lj_api.c b/src/lj_api.c
index 16a1da0e..fc7a589f 100644
--- a/src/lj_api.c
+++ b/src/lj_api.c
@@ -746,7 +746,7 @@ LUA_API void lua_pushlightuserdata(lua_State *L, void *p)
LUA_API void lua_createtable(lua_State *L, int narray, int nrec)
{
lj_gc_check(L);
- settabV(L, L->top, lj_tab_new_ah(L, narray, nrec));
+ settabV(L, L->top, lj_tab_new_ah(L, (uint32_t)narray, (uint32_t)nrec));
incr_top(L);
}
diff --git a/src/lj_tab.c b/src/lj_tab.c
index 1d6a4b7f..9e253d03 100644
--- a/src/lj_tab.c
+++ b/src/lj_tab.c
@@ -165,9 +165,9 @@ GCtab *lj_tab_new(lua_State *L, uint32_t asize, uint32_t hbits)
}
/* The API of this function conforms to lua_createtable(). */
-GCtab *lj_tab_new_ah(lua_State *L, int32_t a, int32_t h)
+GCtab *lj_tab_new_ah(lua_State *L, uint32_t a, uint32_t h)
{
- return lj_tab_new(L, (uint32_t)(a > 0 ? a+1 : 0), hsize2hbits(h));
+ return lj_tab_new(L, a ? a+1 : 0, hsize2hbits(h));
}
#if LJ_HASJIT
diff --git a/src/lj_tab.h b/src/lj_tab.h
index 71e34945..77b08678 100644
--- a/src/lj_tab.h
+++ b/src/lj_tab.h
@@ -34,7 +34,7 @@ static LJ_AINLINE uint32_t hashrot(uint32_t lo, uint32_t hi)
#define hsize2hbits(s) ((s) ? ((s)==1 ? 1 : 1+lj_fls((uint32_t)((s)-1))) : 0)
LJ_FUNCA GCtab *lj_tab_new(lua_State *L, uint32_t asize, uint32_t hbits);
-LJ_FUNC GCtab *lj_tab_new_ah(lua_State *L, int32_t a, int32_t h);
+LJ_FUNC GCtab *lj_tab_new_ah(lua_State *L, uint32_t a, uint32_t h);
#if LJ_HASJIT
LJ_FUNC GCtab * LJ_FASTCALL lj_tab_new1(lua_State *L, uint32_t ahsize);
#endif
diff --git a/test/tarantool-tests/lj-1458-ub-table.new.test.lua b/test/tarantool-tests/lj-1458-ub-table.new.test.lua
new file mode 100644
index 00000000..d0cf6ff5
--- /dev/null
+++ b/test/tarantool-tests/lj-1458-ub-table.new.test.lua
@@ -0,0 +1,30 @@
+local tap = require('tap')
+
+-- The test file to demonstrate UBSan warning for `table.new()`
+-- with a minimal and maximum array and hash parts values.
+-- See also: https://github.com/LuaJIT/LuaJIT/issues/1458.
+local test = tap.test('lj-1458-ub-table-new')
+
+test:plan(8)
+
+local table_new = require('table.new')
+
+local INT_MAX = 2 ^ 31 - 1
+local INT_MIN = -2 ^ 31
+
+local table_sizes = {
+ { 0, INT_MIN },
+ { 0, INT_MAX },
+ { INT_MIN, 0 },
+ { INT_MAX, 0 },
+}
+
+for _, case in ipairs(table_sizes) do
+ local apart, hpart = unpack(case)
+ local ok, err = pcall(table_new, apart, hpart)
+ local message = ('table.new(%d, %d)'):format(apart, hpart)
+ test:is(ok, false, message .. ' is failed')
+ test:ok(err:match('table overflow'), message .. ' correct error message')
+end
+
+test:done(true)
--
2.43.0
next reply other threads:[~2026-06-09 11:35 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-09 10:55 Sergey Bronnikov via Tarantool-patches [this message]
2026-06-09 12:03 ` Sergey Kaplun via Tarantool-patches
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a809bec02e4feb0a1d5215146c2262926b9094d6.1781002531.git.sergeyb@tarantool.org \
--to=tarantool-patches@dev.tarantool.org \
--cc=e.temirgaleev@tarantool.org \
--cc=estetus@gmail.com \
--cc=skaplun@tarantool.org \
--subject='Re: [Tarantool-patches] [PATCH luajit] Prevent sanitizer warnings for lj_tab_new*() and table.new().' \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox