From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6B1753DDAF1 for ; Mon, 27 Jul 2026 07:32:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.43 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785137543; cv=none; b=u0UQH1S/l/1U+AKOAlcb7yfb8OSBkWtPTYddFrreKiLeOq8NBrJ5iKvcz4BOepUMZ679e+m4f22p4mJPnEPTkSS2ry1up+G+KL8xBodkk7r3cgdawT0letfUhSjUj53QnMMnA3OOPpicnDOM2WOVmBD99eJcnQmaqhQ1/y8FdhA= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785137543; c=relaxed/simple; bh=AhaZ2ac8oEimySxpNjIfoYtWcC/kc92M7RxeTjSTuOs=; h=Date:From:To:Cc:Subject:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=HmY9Lwu+QN/Dbg0xia86QBhoYdHNNEK3em3Wkz1Zpic2UwFWfbzqwBzUD1hBXV1YOPKuLhqdd7/r+sDn/YK4yxnjPN6ejA/hymUKm9dwgSzyM4O3aYbpxsFOPtsu1zhXUwfmpk1IsnOAGi/6i4K3HSPcpBFgljanbESUx7Uqmk8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=PxQEIB1t; arc=none smtp.client-ip=209.85.128.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="PxQEIB1t" Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-49556f97a9dso15975425e9.1 for ; Mon, 27 Jul 2026 00:32:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785137540; x=1785742340; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=yOW/nYL4to09ZFRK9TrJFYsB5lOpHRRLHeRIsAezmMY=; b=PxQEIB1ty3ohoNsjZt8ZnEQQ2pvRUcfeNeq2GcoWWD7h0b8aSOgPITmiRtL/cQM+a4 2L+WrSX+V2jXcL2RrwlIr8EifJ+uC+qKpub1FmB3dWT0q3AL/MVdJFZqDtdblzdy4IHe fOj6SzTo4P1f4riMxWH96FL5otBDHpjS5MxDx1U+s3Xus5TAtDN9J7OWq1MecGlR/V/y majJLnbi+MJgXhHHufw/8+bYXay5rdBVxr8E/+PzjwQ+eM43ArypaP3BMT3cnLMspdrb NCJ2gAHegWr4SyNuveOMaOLYCZoUsCwbdRp4K+SNAH4G1s39rHPLmg3VIPz0OoM47dzA 74cg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785137540; x=1785742340; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=yOW/nYL4to09ZFRK9TrJFYsB5lOpHRRLHeRIsAezmMY=; b=qvU1e43qeG/1EmvqiwykxF/Tbb8CLg+pNDUwoNKcA1K0Ds95I1fMI8B+WKyWAZLvYr aZM1dq2CcCXqGwhpIh23OZzRMMgJw7Jy5uqXlBzHmifh0rVXpbiqKj4QI2dlwRJyteKu bfXAy+CYIWzYrZBcr9kzAUyC6ouX/zqQ4g3P++azWu4NtwtpAR4F+5zea7R7IWXcvG9J ap5goJ2j5wCeuvZARCIZcTfJvRaFhj9PkZMS/gPwZ3fBy4GH1D6pd38JyGva2LOtLzLn MwJgXdJwlmWS1Zzu6bmKo/EWhIOPkUYabj5zjtGDNgJQNcl2UpwPPsnJXytCd+h69iBx 7tyQ== X-Forwarded-Encrypted: i=1; AHgh+RodALPa75hEKV/18395Y9SZDLi7IhibfRmUOoeGAS8FEATWA0w4VAQj2vAVLnEBIwVch1kfpYbB7Ybn1kc=@vger.kernel.org X-Gm-Message-State: AOJu0YwVvid3SLeyaBrC179NnREk8FWUAbw3tt/CDWN+w+kjZZaV4QeH eaP3Ur/X4UWxyKBNTLf61J9Mop+40169TFLnmoFUNbNTUTIg8Xf7xiJn X-Gm-Gg: AR+sD11VUvO4hCObO6tw3DtjTA3db16HNpF/rHUnXXf2Ib6zPk5Qkp/Zuvy/lF8BaYp tr5zC9eobDinnVU5yWHcWQhvx11iOqLvYROktMcuBbCdnDuWLiYPQnqdSUwRR5ls1jGWHUue0Xa Hdu5mYK9UtVSU3ugyaK8IKtiDw2TwG2QJbqi6RMySrUxW+fSuAkJn6IZ7uPJoToxXwp/W8PKM+/ s984AgtU25Ng4ZWTlXUHM8mMDTMISx1ildCNFo5EFBB97A0PyrUnkwW1pYwypkhw1GqZ/5muEie 6ar1CVEgoLd56VdKEDLleXbwQv2FERtkLXlp3WvkzNQ821t+pNVz5OfnTxBW1hC0FD4ZOXxy44Y snJJMBSbTIZ7ddre6AS9BAf5BN0KqvH6xD9WfUk7rF4T4iulyGbjMetDyroFeenQh3BMrCH2+5W qYIlGX2XIfJs18s1OVv7QZqF9MIglqOcnECQfFv1c= X-Received: by 2002:a05:600c:3586:b0:496:bffb:fb7b with SMTP id 5b1f17b1804b1-496bffbfc25mr23100895e9.10.1785137539393; Mon, 27 Jul 2026 00:32:19 -0700 (PDT) Received: from pumpkin (82-69-66-36.dsl.in-addr.zen.co.uk. [82.69.66.36]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-496b4ee1d31sm219425825e9.5.2026.07.27.00.32.18 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 27 Jul 2026 00:32:18 -0700 (PDT) Date: Mon, 27 Jul 2026 08:32:12 +0100 From: David Laight To: Willy Tarreau Cc: Ammar Faizi , Thomas =?UTF-8?B?V2Vpw59zY2h1?= =?UTF-8?B?aA==?= , Linux Kernel Mailing List , Linux Kselftest Mailing List , LLVM Mailing List , Yichun Zhang , Alviro Iskandar Setiawan , Shuah Khan , Nathan Chancellor , Nick Desaulniers , Bill Wendling , Justin Stitt , gwml@gnuweeb.org Subject: Re: [PATCH 2/4] tools/nolibc: stdlib: avoid signed overflow in abs() and friends Message-ID: <20260727083212.223cb1ae@pumpkin> In-Reply-To: References: <20260726101306.3772237-1-ammarfaizi2@openresty.com> <20260726101306.3772237-3-ammarfaizi2@openresty.com> <20260726151334.4c1ec6f1@pumpkin> X-Mailer: Claws Mail 4.1.1 (GTK 3.24.38; arm-unknown-linux-gnueabihf) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit On Sun, 26 Jul 2026 18:01:11 +0200 Willy Tarreau wrote: > On Sun, Jul 26, 2026 at 03:13:34PM +0100, David Laight wrote: > > On Sun, 26 Jul 2026 17:13:03 +0700 > > Ammar Faizi wrote: > > > > > Negating the smallest negative value of a signed type overflows, which > > > is undefined behavior. The selftests are built with: > > > > > > -fsanitize=undefined -fsanitize-trap=all > > > > > > so a caller passing INT_MIN does not merely get an unspecified answer, > > > it dies (on both x86-64 and i386): > > > > > > A simple test program: > > > > > > printf("x = %d\n", abs(INT_MIN)); > > > > > > $ ./ab > > > Illegal instruction (core dumped) > > > > > > (gdb) bt > > > #0 0x0000000000401009 in main () > > > (gdb) x/6i main > > > 0x401000
: mov $0x80000000,%eax > > > 0x401005 : neg %eax > > > 0x401007 : jno 0x40100b > > > => 0x401009 : ud2 > > > 0x40100b : push %rax > > > 0x40100c : mov $0x80000000,%esi > > > > > > Negate in the corresponding unsigned type instead. The value still > > > cannot be represented in the result type, so the minimum is returned > > > unchanged. > > > > > > Cc: Yichun Zhang > > > Cc: Alviro Iskandar Setiawan > > > Fixes: bf5e8a78bede ("tools/nolibc: add abs() and friends") > > > Signed-off-by: Ammar Faizi > > > --- > > > tools/include/nolibc/stdlib.h | 12 +++++++++--- > > > 1 file changed, 9 insertions(+), 3 deletions(-) > > > > > > diff --git a/tools/include/nolibc/stdlib.h b/tools/include/nolibc/stdlib.h > > > index 1816c2368b68..8d86044f759f 100644 > > > --- a/tools/include/nolibc/stdlib.h > > > +++ b/tools/include/nolibc/stdlib.h > > > @@ -32,22 +32,28 @@ static __attribute__((unused)) char itoa_buffer[21]; > > > * As much as possible, please keep functions alphabetically sorted. > > > */ > > > > > > +/* > > > + * The absolute value of the smallest negative value is not representable in > > > + * the result type. Negate in the unsigned type so that the overflow is > > > + * defined and return it unchanged, like the other libcs do. > > > + */ > > > + > > > static __inline__ > > > int abs(int j) > > > { > > > - return j >= 0 ? j : -j; > > > + return j >= 0 ? j : (int)-(unsigned int)j; > > > > An alternative expression is -(j + 1) - 1 > > gcc (and I think clang) optimise it to just -j. > > This one would give -j -2, Gah, I meant -(j + 1) + 1 :-( > but ~(j - 1) would work, just like > (~j + 1). However here the benefit of the casts in Ammar's > version is that it's obvious that it's only playing with same > size casts with no extra operation. They only work for 2s compliment. While that is normal (and required for the next? C version) it isn't actually required by C. (Not that gcc supports '1s compliment' or 'sign overpunch'.) David > > Willy