From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wr1-f48.google.com (mail-wr1-f48.google.com [209.85.221.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9B5333BBFBF for ; Sun, 26 Jul 2026 14:13:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.48 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785075221; cv=none; b=mmcf0tf8sO12GzBX3LqH9W9jhK+x6rKuRmrhChH63ih4KJ5HQjzYun42MXEw08JsVgyjncE3C3JO7xHHODCMFYwCNs1UDgs+YcVKMVJaCr5iLKHdJ0J4gquQuuk3+vZ3+4nNW9GsNYU6KIzMPgKh7wArNjZ4byy3F8TZEuhiZus= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785075221; c=relaxed/simple; bh=5EVN9kcvU5gVRWVLO/DSXXNw7Y1dcHFYAtzffkegbYM=; h=Date:From:To:Cc:Subject:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=HPMGdR+JdFAAMC40ncwFCaI4k6Sclm8NYiRnCaloWm6MiIJsLRAU088Jua6gCGRGxAUuMguZBVnPK4Kh6yLWuz0UUO3YGN2s8T4Q7/NVCc6yvWncHUv9K8hBr/igURM6ujb3kZj5J2CI+4VsBYboHeBxzxoWA3U6gOzOAMF21MI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=f+Lo3fbk; arc=none smtp.client-ip=209.85.221.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="f+Lo3fbk" Received: by mail-wr1-f48.google.com with SMTP id ffacd0b85a97d-47f81a3ccf9so1169086f8f.0 for ; Sun, 26 Jul 2026 07:13:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785075216; x=1785680016; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=K4g2kK4jDWITUw2uejvAMiPY148LZbRyudfCDbQMRog=; b=f+Lo3fbkFWziCCFqgSZ7a3VVIyir8921yRM2wZPvoUKspT81feXkpn6GDJLvVUH4X0 WnXGo+lq0aEjXBr44a9z4QVBDnuFxeJJ576MO+4LS/3vTa15Dau6pdRmssNyn17C3eb1 mlt1GLa4aNnDxAN1ya8BTK6YV5YMoM/RgutOG2oKkwWe8FhAuNSXz+eRofSCi1GFDvRj Y56YZ6zIR15hV2ZKqoL5aFaR4Lxe6rgW+xs496tMwQJP/GPJgl2GPet7/JHJerV20qbr Q32p5qI95f48SHONq++dKQBj9c2YW2iuT8HI+dzs6bduDYc89ntYhOJFqG/s+1n+sWrl ZMJA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785075216; x=1785680016; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=K4g2kK4jDWITUw2uejvAMiPY148LZbRyudfCDbQMRog=; b=GpVncCUiBrkS3wpRbnvlApGUcTYWxjLlN/Bq5g/ATHnjhqDy6p/mTElBroYWYSImJD d2ZTN764SkFNN/GNS9nK1n9H8PKIq7Cu86BVsYzsLyojnV/cmNUS6zKVXZcv07gku2D8 TKO0fYeAO5YRn0ofLBhNCPX+vU1ZcXWN6PToeV+80KyjYjhaxlXN5imhIRzdGNuJMnsl whhjGkepyNtfKWKQwBheWusCe3JDphUEHWxDAP2qKkYzOtPSwwAr5wobcRRZhWDM23aX +2RapEzVFKUx0Q2OLR409fkYWaiNTi3Da+j78wIEA8LwXyUuoY2F2shAXqNHkt9G8hEC dhsg== X-Forwarded-Encrypted: i=1; AHgh+RpknQDKAg9ATCdIGQsuiLB7zYp21D3Ics3flTWRL/qpUgohhX0OrCQMzHofPktKQRw4mRSG0tBm2YfpAFE=@vger.kernel.org X-Gm-Message-State: AOJu0YwNktM+yeeHckIy9nSTcdHXUR1i3V0DJw60O5LgThZIrrFz5l6E jmfZfIUlRfJwyuA3lfGRPJ/2UMcDbrTF3qcULexmNX7nNttVoN0jHPPBr2smYKZBS68= X-Gm-Gg: AR+sD12Omt1cLva4upod1nCT8Z1czR8aRK82vbMTZTUZTlFHryS+C/aiK3c09Mpdnze WsK7b3ADrhcW8LiZ+Bo3ewjFneZRc4WqznbHeJqFed246bjllQKCOUGqpdCAbywLPf56nYFAYMY SOEG6i2KF27tkhb1rSGb5uNEC5wLCLfFCPEQ+O/u2uDZyT0NVJIiAzznSrW1PozqG5UYdWrh0kt wDu4rYdJd+IApeLIlPwujDMZaqAp84jCVdNUkR7Z+YcVXL0oRSB1F+1MZjzRGvoY6+MeZpoIKeH MZuTSs3nhUXi4QRuZTOcArqB+s43+knm/Xax8sz9IUU3z9cl3TE0y1pdgrrhlmrX8ZaPJIfknm8 RWRgMT8NEhwncJcgA7nV8CbwZ7tFNILriQMFpC/nrNsrZ0GbpJ5kTrKxNkJeBmLe3g01i33zT+G KPgr7kUNm6lWXxt9MLLgdkwC70Rcg+8nIwFMLf7B8= X-Received: by 2002:a05:6000:188e:b0:47f:921f:3a37 with SMTP id ffacd0b85a97d-47f9fea4346mr6495997f8f.35.1785075215987; Sun, 26 Jul 2026 07:13:35 -0700 (PDT) Received: from pumpkin (82-69-66-36.dsl.in-addr.zen.co.uk. [82.69.66.36]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47f85c6dc25sm39925390f8f.33.2026.07.26.07.13.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 26 Jul 2026 07:13:35 -0700 (PDT) Date: Sun, 26 Jul 2026 15:13:34 +0100 From: David Laight To: Ammar Faizi Cc: Willy Tarreau , Thomas =?UTF-8?B?V2Vpw59zY2h1aA==?= , Linux Kernel Mailing List , Linux Kselftest Mailing List , LLVM Mailing List , Yichun Zhang , Alviro Iskandar Setiawan , Shuah Khan , Nathan Chancellor , Nick Desaulniers , Bill Wendling , Justin Stitt , gwml@gnuweeb.org Subject: Re: [PATCH 2/4] tools/nolibc: stdlib: avoid signed overflow in abs() and friends Message-ID: <20260726151334.4c1ec6f1@pumpkin> In-Reply-To: <20260726101306.3772237-3-ammarfaizi2@openresty.com> References: <20260726101306.3772237-1-ammarfaizi2@openresty.com> <20260726101306.3772237-3-ammarfaizi2@openresty.com> X-Mailer: Claws Mail 4.1.1 (GTK 3.24.38; arm-unknown-linux-gnueabihf) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit On Sun, 26 Jul 2026 17:13:03 +0700 Ammar Faizi wrote: > Negating the smallest negative value of a signed type overflows, which > is undefined behavior. The selftests are built with: > > -fsanitize=undefined -fsanitize-trap=all > > so a caller passing INT_MIN does not merely get an unspecified answer, > it dies (on both x86-64 and i386): > > A simple test program: > > printf("x = %d\n", abs(INT_MIN)); > > $ ./ab > Illegal instruction (core dumped) > > (gdb) bt > #0 0x0000000000401009 in main () > (gdb) x/6i main > 0x401000
: mov $0x80000000,%eax > 0x401005 : neg %eax > 0x401007 : jno 0x40100b > => 0x401009 : ud2 > 0x40100b : push %rax > 0x40100c : mov $0x80000000,%esi > > Negate in the corresponding unsigned type instead. The value still > cannot be represented in the result type, so the minimum is returned > unchanged. > > Cc: Yichun Zhang > Cc: Alviro Iskandar Setiawan > Fixes: bf5e8a78bede ("tools/nolibc: add abs() and friends") > Signed-off-by: Ammar Faizi > --- > tools/include/nolibc/stdlib.h | 12 +++++++++--- > 1 file changed, 9 insertions(+), 3 deletions(-) > > diff --git a/tools/include/nolibc/stdlib.h b/tools/include/nolibc/stdlib.h > index 1816c2368b68..8d86044f759f 100644 > --- a/tools/include/nolibc/stdlib.h > +++ b/tools/include/nolibc/stdlib.h > @@ -32,22 +32,28 @@ static __attribute__((unused)) char itoa_buffer[21]; > * As much as possible, please keep functions alphabetically sorted. > */ > > +/* > + * The absolute value of the smallest negative value is not representable in > + * the result type. Negate in the unsigned type so that the overflow is > + * defined and return it unchanged, like the other libcs do. > + */ > + > static __inline__ > int abs(int j) > { > - return j >= 0 ? j : -j; > + return j >= 0 ? j : (int)-(unsigned int)j; An alternative expression is -(j + 1) - 1 gcc (and I think clang) optimise it to just -j. David > } > > static __inline__ > long labs(long j) > { > - return j >= 0 ? j : -j; > + return j >= 0 ? j : (long)-(unsigned long)j; > } > > static __inline__ > long long llabs(long long j) > { > - return j >= 0 ? j : -j; > + return j >= 0 ? j : (long long)-(unsigned long long)j; > } > > /* must be exported, as it's used by libgcc for various divide functions */