Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1698859 > unrolled thread

[PATCH net] tcp: avoid bogus gcc-7 array-bounds warning

Started byArnd Bergmann <arnd@arndb.de>
First post2017-07-28 16:50 +0200
Last post2017-07-30 08:30 +0200
Articles 3 — 3 participants

Back to article view | Back to linux.kernel


Contents

  [PATCH net] tcp: avoid bogus gcc-7 array-bounds warning Arnd Bergmann <arnd@arndb.de> - 2017-07-28 16:50 +0200
    RE: [PATCH net] tcp: avoid bogus gcc-7 array-bounds warning David Laight <David.Laight@ACULAB.COM> - 2017-07-28 17:50 +0200
    Re: [PATCH net] tcp: avoid bogus gcc-7 array-bounds warning David Miller <davem@davemloft.net> - 2017-07-30 08:30 +0200

#1698859 — [PATCH net] tcp: avoid bogus gcc-7 array-bounds warning

FromArnd Bergmann <arnd@arndb.de>
Date2017-07-28 16:50 +0200
Subject[PATCH net] tcp: avoid bogus gcc-7 array-bounds warning
Message-ID<u8eKv-4ZB-29@gated-at.bofh.it>
When using CONFIG_UBSAN_SANITIZE_ALL, the TCP code produces a
false-positive warning:

net/ipv4/tcp_output.c: In function 'tcp_connect':
net/ipv4/tcp_output.c:2207:40: error: array subscript is below array bounds [-Werror=array-bounds]
   tp->chrono_stat[tp->chrono_type - 1] += now - tp->chrono_start;
                                        ^~
net/ipv4/tcp_output.c:2207:40: error: array subscript is below array bounds [-Werror=array-bounds]
   tp->chrono_stat[tp->chrono_type - 1] += now - tp->chrono_start;
   ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^~~~~~~~~~~~~~~~~~~~~~~~~

I have opened a gcc bug for this, but distros have already shipped
compilers with this problem, and it's not clear yet whether there is
a way for gcc to avoid the warning. As the problem is related to the
bitfield access, this introduces a temporary variable to store the old
enum value.

I did not notice this warning earlier, since UBSAN is disabled when
building with COMPILE_TEST, and that was always turned on in both
allmodconfig and randconfig tests.

Link: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=81601
Signed-off-by: Arnd Bergmann <arnd@arndb.de>
---
 net/ipv4/tcp_output.c | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/net/ipv4/tcp_output.c b/net/ipv4/tcp_output.c
index 886d874775df..bb901297a369 100644
--- a/net/ipv4/tcp_output.c
+++ b/net/ipv4/tcp_output.c
@@ -2202,9 +2202,10 @@ static bool tcp_small_queue_check(struct sock *sk, const struct sk_buff *skb,
 static void tcp_chrono_set(struct tcp_sock *tp, const enum tcp_chrono new)
 {
 	const u32 now = tcp_jiffies32;
+	enum tcp_chrono old = tp->chrono_type;
 
-	if (tp->chrono_type > TCP_CHRONO_UNSPEC)
-		tp->chrono_stat[tp->chrono_type - 1] += now - tp->chrono_start;
+	if (old > TCP_CHRONO_UNSPEC)
+		tp->chrono_stat[old - 1] += now - tp->chrono_start;
 	tp->chrono_start = now;
 	tp->chrono_type = new;
 }
-- 
2.9.0

[toc] | [next] | [standalone]


#1698911

FromDavid Laight <David.Laight@ACULAB.COM>
Date2017-07-28 17:50 +0200
Message-ID<u8fGx-5Cs-5@gated-at.bofh.it>
In reply to#1698859
From: Arnd Bergmann
> Sent: 28 July 2017 15:42
...
> --- a/net/ipv4/tcp_output.c
> +++ b/net/ipv4/tcp_output.c
> @@ -2202,9 +2202,10 @@ static bool tcp_small_queue_check(struct sock *sk, const struct sk_buff *skb,
>  static void tcp_chrono_set(struct tcp_sock *tp, const enum tcp_chrono new)
>  {
>  	const u32 now = tcp_jiffies32;
> +	enum tcp_chrono old = tp->chrono_type;
> 
> -	if (tp->chrono_type > TCP_CHRONO_UNSPEC)
> -		tp->chrono_stat[tp->chrono_type - 1] += now - tp->chrono_start;
> +	if (old > TCP_CHRONO_UNSPEC)
> +		tp->chrono_stat[old - 1] += now - tp->chrono_start;
>  	tp->chrono_start = now;
>  	tp->chrono_type = new;

What a horrid combination of enum and integers.
Also have u32 chrono_stat[3]; - should probably be [__TCP_CHRONO_MAX - 1]
(or - CHRONO_FIRST which is defined to be 1).

Checking if (old != 0) would make the code more readable.

	David

[toc] | [prev] | [next] | [standalone]


#1699423

FromDavid Miller <davem@davemloft.net>
Date2017-07-30 08:30 +0200
Message-ID<u8PTH-563-3@gated-at.bofh.it>
In reply to#1698859
From: Arnd Bergmann <arnd@arndb.de>
Date: Fri, 28 Jul 2017 16:41:37 +0200

> When using CONFIG_UBSAN_SANITIZE_ALL, the TCP code produces a
> false-positive warning:
> 
> net/ipv4/tcp_output.c: In function 'tcp_connect':
> net/ipv4/tcp_output.c:2207:40: error: array subscript is below array bounds [-Werror=array-bounds]
>    tp->chrono_stat[tp->chrono_type - 1] += now - tp->chrono_start;
>                                         ^~
> net/ipv4/tcp_output.c:2207:40: error: array subscript is below array bounds [-Werror=array-bounds]
>    tp->chrono_stat[tp->chrono_type - 1] += now - tp->chrono_start;
>    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~^~~~~~~~~~~~~~~~~~~~~~~~~
> 
> I have opened a gcc bug for this, but distros have already shipped
> compilers with this problem, and it's not clear yet whether there is
> a way for gcc to avoid the warning. As the problem is related to the
> bitfield access, this introduces a temporary variable to store the old
> enum value.
> 
> I did not notice this warning earlier, since UBSAN is disabled when
> building with COMPILE_TEST, and that was always turned on in both
> allmodconfig and randconfig tests.
> 
> Link: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=81601
> Signed-off-by: Arnd Bergmann <arnd@arndb.de>

Applied, thanks Arnd.

[toc] | [prev] | [standalone]


Back to top | Article view | linux.kernel


csiph-web