From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f53.google.com (mail-wm1-f53.google.com [209.85.128.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B86403FB7C1 for ; Tue, 28 Jul 2026 08:46:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.53 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785228393; cv=none; b=mTMrPI3XTE6dZKwvmeuCL7KwfDJ0wiI6VH/+tGp+Vo5HwWfy+W/VNMGEh5YShZOw71QnY3stFRmZyjyx8HH2t6hR9CJtoY+ATnUJnZ9XL9jLNQ3I3kQusmUHN36gZrLekPxFjEDlGO9W5Gl8YO4raPA/0o3QMAB/L/uMrAz6zpI= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785228393; c=relaxed/simple; bh=DLea7GDB+WBJ7RoAC77zyEKX0QnwByXNUQOxrZdvpNM=; h=Date:From:To:Cc:Subject:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=E6C1ei+A8VaW9vPdxlZPKeXUnalZPmKmhhcseGwcvnyWczTvpCjOa5S1AxW1WAaukmq3xwxKQw89yOusKCrAizeK0t0fi5iuWf849sC87STcCLk5Sa4j/i+SVarQYs1dwst+Mxx1TStnvHLzrUmmNZ3JjjdoDfYyKjCYBj3BkFo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=pdyzDaLq; arc=none smtp.client-ip=209.85.128.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="pdyzDaLq" Received: by mail-wm1-f53.google.com with SMTP id 5b1f17b1804b1-4957eefd361so26388145e9.1 for ; Tue, 28 Jul 2026 01:46:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785228388; x=1785833188; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:from:to:cc:subject :date:message-id:reply-to:content-type; bh=TY5i83xUXytTq3W3hDjBOHFIBU26TkcCDfOy7gh1KLI=; b=pdyzDaLqNNd7Xs/JYwRF0Mqn3R+HXD3Ec5us/7Vb8W81DDyWCDKu5bDkH7GALWFg52 VMVkU/sHu/BoXpTJqZ6ZvNIfmouSE75isrGyKfgY2nm7aUaoeoYSMb0dVwecuoaYJ4Oc DlYP5TUspsRf6Whep/Ki9+NGHuXxT5p1YoGjAbo7PwaiwWq7A0zG6SyYJWoQnRm3HWIg bHrL84ouUh5Fw5ZGrk5fo6tElEnNpG2lE+LnonZn9PVMLpbIRFnN+NWRYMT+x8VpG/d7 zeO2rc/Dd6rMXYJ7cSpexdQrCB5UVz4nXJvs0ju5EWKOfpXz7beAsSZjiTBW1AplvZg7 n+Ew== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785228388; x=1785833188; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:subject:cc:to:from:date:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=TY5i83xUXytTq3W3hDjBOHFIBU26TkcCDfOy7gh1KLI=; b=SpecP8oXw6KkYVtufd41b4mLK6fffm8mLLci4J0pvxIjUtJlzown25rqkRPWcULSwN yzWeNXtVdCfBo1llg9b2sb5E6CfzoVfqcswdL/piOC/JEeBvrOQZk/qCAweXbcCLbRPS dGcvOz+YKD/1AbIghAzE0GsYxuJewD8/AicKYx+SDUCIus27w4gQQfoQy+vjyefCMXrS 7FFDxEJHkO4m9LW9CyqLoyYnivyPPRz0etdsQKKtZ6cXA/pUdPARdsvT+nxUymLNiNXa oWBMI376wMQvrn0jz10w7siY8A6+c3HT+Zzzqe20/Q80dRQZHDbvyyvyKeMnRw8hQcEs MU1A== X-Forwarded-Encrypted: i=1; AHgh+Rrgme0hlPk3qPMQtsuey/sOGOHQv2DqMLNroaxpFAS/gvQmcDheC1aip1hiIcxBwKLtp/DrmaOBkESb+ZY=@vger.kernel.org X-Gm-Message-State: AOJu0YySsg9iW9OrjObIgwNUMmp/T6DKKrMtxStpScAh2qVg43yZC45Y Yz4b2uPcv8aYTj5fcrLZtI/2DD6lOK+y4gOMsj9w/WBpxyl/giRhtOJCB6yuJmfd5Y4= X-Gm-Gg: AR+sD109CMF+D5LQFUn91irogitaT1DShEIf4xXdKMzQI7Hg4iRVx0FjMhFBcE5Jql6 x7R+dxdI8bQskbSACTOsD2u0q+QV6Qwk7xjdSxRjsT3QpyyPmMTWIbvicf29lC8i9b80hf9Xtop 2bFEmeS0fevhOxHsK4/9bE+AuO2qUdZWItUXm6ecFkCeCRlhfZMrQglI+0xSeWx0+yebUCZLcOg ICOq609k9F+HP+DOzPNq7NcfgxjpUFulcIPAmJBmhsiCCT/a6CZBOwC4a/Zhx+ydrdKM7uBNoIK /itkxzAbE0HLSMAvYYVBjnu9BCLxH10tyItyeCXApwAm6lJqxk3YHPYmWFRphIip3VKAKteA5D2 XXfWGSEHhHzqR8ZrsrTbVuEFChwdqbhauvxZewLw/gjduT1InJzw5Gng9vG95TxR0mZrtwAx6No bY9FTKd4oA6D6LHiyu2ldG3Rv9fLlyLsuQOgrDP9qQzgKcNNJOuQ== X-Received: by 2002:a05:600c:3b13:b0:495:5890:8f6c with SMTP id 5b1f17b1804b1-496c653d3dcmr17415025e9.7.1785228387869; Tue, 28 Jul 2026 01:46:27 -0700 (PDT) Received: from pumpkin (82-69-66-36.dsl.in-addr.zen.co.uk. [82.69.66.36]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4957f9b8b67sm340321705e9.4.2026.07.28.01.46.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 01:46:27 -0700 (PDT) Date: Tue, 28 Jul 2026 09:46:25 +0100 From: David Laight To: Ammar Faizi Cc: Willy Tarreau , Thomas =?UTF-8?B?V2Vpw59zY2h1aA==?= , Linux Kernel Mailing List , Linux Kselftest Mailing List , LLVM Mailing List , Yichun Zhang , Alviro Iskandar Setiawan , Shuah Khan , Nathan Chancellor , Nick Desaulniers , Bill Wendling , Justin Stitt , gwml@gnuweeb.org Subject: Re: [PATCH 2/4] tools/nolibc: stdlib: avoid signed overflow in abs() and friends Message-ID: <20260728094626.0fb1a467@pumpkin> In-Reply-To: <20260726101306.3772237-3-ammarfaizi2@openresty.com> References: <20260726101306.3772237-1-ammarfaizi2@openresty.com> <20260726101306.3772237-3-ammarfaizi2@openresty.com> X-Mailer: Claws Mail 4.1.1 (GTK 3.24.38; arm-unknown-linux-gnueabihf) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit On Sun, 26 Jul 2026 17:13:03 +0700 Ammar Faizi wrote: > Negating the smallest negative value of a signed type overflows, which > is undefined behavior. The selftests are built with: > > -fsanitize=undefined -fsanitize-trap=all > > so a caller passing INT_MIN does not merely get an unspecified answer, > it dies (on both x86-64 and i386): Thinking more, that is probably the correct thing to do. 'Undefined behaviour' means exactly that. It tends to be used for things that might cause traps on some architectures. But I believe 'undefined behaviour' is exactly that, erasing your hard disk (or starting a nuclear war) are both valid. David > > A simple test program: > > printf("x = %d\n", abs(INT_MIN)); > > $ ./ab > Illegal instruction (core dumped) > > (gdb) bt > #0 0x0000000000401009 in main () > (gdb) x/6i main > 0x401000
: mov $0x80000000,%eax > 0x401005 : neg %eax > 0x401007 : jno 0x40100b > => 0x401009 : ud2 > 0x40100b : push %rax > 0x40100c : mov $0x80000000,%esi > > Negate in the corresponding unsigned type instead. The value still > cannot be represented in the result type, so the minimum is returned > unchanged. > > Cc: Yichun Zhang > Cc: Alviro Iskandar Setiawan > Fixes: bf5e8a78bede ("tools/nolibc: add abs() and friends") > Signed-off-by: Ammar Faizi > --- > tools/include/nolibc/stdlib.h | 12 +++++++++--- > 1 file changed, 9 insertions(+), 3 deletions(-) > > diff --git a/tools/include/nolibc/stdlib.h b/tools/include/nolibc/stdlib.h > index 1816c2368b68..8d86044f759f 100644 > --- a/tools/include/nolibc/stdlib.h > +++ b/tools/include/nolibc/stdlib.h > @@ -32,22 +32,28 @@ static __attribute__((unused)) char itoa_buffer[21]; > * As much as possible, please keep functions alphabetically sorted. > */ > > +/* > + * The absolute value of the smallest negative value is not representable in > + * the result type. Negate in the unsigned type so that the overflow is > + * defined and return it unchanged, like the other libcs do. > + */ > + > static __inline__ > int abs(int j) > { > - return j >= 0 ? j : -j; > + return j >= 0 ? j : (int)-(unsigned int)j; > } > > static __inline__ > long labs(long j) > { > - return j >= 0 ? j : -j; > + return j >= 0 ? j : (long)-(unsigned long)j; > } > > static __inline__ > long long llabs(long long j) > { > - return j >= 0 ? j : -j; > + return j >= 0 ? j : (long long)-(unsigned long long)j; > } > > /* must be exported, as it's used by libgcc for various divide functions */