public inbox for gcc-bugs@sourceware.org help / color / mirror / Atom feed
* [Bug sanitizer/115273] New: [12 Regression] passing zero to ctz() check missing @ 2024-05-29 10:37 bic60176 at gmail dot com 2024-05-29 10:38 ` [Bug sanitizer/115273] " bic60176 at gmail dot com ` (4 more replies) 0 siblings, 5 replies; 6+ messages in thread From: bic60176 at gmail dot com @ 2024-05-29 10:37 UTC (permalink / raw) To: gcc-bugs https://gcc.gnu.org/bugzilla/show_bug.cgi?id=115273 Bug ID: 115273 Summary: [12 Regression] passing zero to ctz() check missing Product: gcc Version: 12.3.0 Status: UNCONFIRMED Severity: normal Priority: P3 Component: sanitizer Assignee: unassigned at gcc dot gnu.org Reporter: bic60176 at gmail dot com CC: dodji at gcc dot gnu.org, dvyukov at gcc dot gnu.org, jakub at gcc dot gnu.org, kcc at gcc dot gnu.org Target Milestone: --- Created attachment 58305 --> https://gcc.gnu.org/bugzilla/attachment.cgi?id=58305&action=edit testcase OS: Ubuntu 22.04.3 LTS We found a case that UBSAN missed checking if zero is passed to __builtin_ctz() when compiling with gcc-12.3.0. When compiling with gcc-11.4.0, gcc-13.2.0, and gcc-14.1.0, UBSAN can detect the undefined behavior. $ ../compiler-builds/gcc-12.3.0_build/bin/gcc -fsanitize=undefined -g -lgcc_s -I/home/csmith/include/csmith-2.3.0 testcase.c -o exec $ timeout 1s ./exec 2>exec.err $ cat exec.err $ ../compiler-builds/gcc-11.4.0_build/bin/gcc -fsanitize=undefined -g -lgcc_s -I/home/csmith/include/csmith-2.3.0 testcase.c -o exec $ timeout 1s ./exec 2>exec.err testcase.c:957:44: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:997:25: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:957: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:997: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:957: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:997: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:957: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:997: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:957: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:997: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:957: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:997: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:957: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:997: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:957: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:997: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:957: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:997: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:957: runtime error: passing zero to ctz(), which is not a valid argument testcase.c:997: runtime error: passing zero to ctz(), which is not a valid argument ^ permalink raw reply [flat|nested] 6+ messages in thread
* [Bug sanitizer/115273] [12 Regression] passing zero to ctz() check missing 2024-05-29 10:37 [Bug sanitizer/115273] New: [12 Regression] passing zero to ctz() check missing bic60176 at gmail dot com @ 2024-05-29 10:38 ` bic60176 at gmail dot com 2024-05-29 11:20 ` rguenth at gcc dot gnu.org ` (3 subsequent siblings) 4 siblings, 0 replies; 6+ messages in thread From: bic60176 at gmail dot com @ 2024-05-29 10:38 UTC (permalink / raw) To: gcc-bugs https://gcc.gnu.org/bugzilla/show_bug.cgi?id=115273 --- Comment #1 from Bi6c <bic60176 at gmail dot com> --- Created attachment 58306 --> https://gcc.gnu.org/bugzilla/attachment.cgi?id=58306&action=edit preprocessed file ^ permalink raw reply [flat|nested] 6+ messages in thread
* [Bug sanitizer/115273] [12 Regression] passing zero to ctz() check missing 2024-05-29 10:37 [Bug sanitizer/115273] New: [12 Regression] passing zero to ctz() check missing bic60176 at gmail dot com 2024-05-29 10:38 ` [Bug sanitizer/115273] " bic60176 at gmail dot com @ 2024-05-29 11:20 ` rguenth at gcc dot gnu.org 2024-06-02 1:45 ` pinskia at gcc dot gnu.org ` (2 subsequent siblings) 4 siblings, 0 replies; 6+ messages in thread From: rguenth at gcc dot gnu.org @ 2024-05-29 11:20 UTC (permalink / raw) To: gcc-bugs https://gcc.gnu.org/bugzilla/show_bug.cgi?id=115273 Richard Biener <rguenth at gcc dot gnu.org> changed: What |Removed |Added ---------------------------------------------------------------------------- Target Milestone|--- |12.4 ^ permalink raw reply [flat|nested] 6+ messages in thread
* [Bug sanitizer/115273] [12 Regression] passing zero to ctz() check missing 2024-05-29 10:37 [Bug sanitizer/115273] New: [12 Regression] passing zero to ctz() check missing bic60176 at gmail dot com 2024-05-29 10:38 ` [Bug sanitizer/115273] " bic60176 at gmail dot com 2024-05-29 11:20 ` rguenth at gcc dot gnu.org @ 2024-06-02 1:45 ` pinskia at gcc dot gnu.org 2024-06-02 1:46 ` pinskia at gcc dot gnu.org 2024-06-02 1:51 ` pinskia at gcc dot gnu.org 4 siblings, 0 replies; 6+ messages in thread From: pinskia at gcc dot gnu.org @ 2024-06-02 1:45 UTC (permalink / raw) To: gcc-bugs https://gcc.gnu.org/bugzilla/show_bug.cgi?id=115273 --- Comment #2 from Andrew Pinski <pinskia at gcc dot gnu.org> --- Reduced testcase: ``` int f(int a) { return __builtin_ctz(a) == 0; } int main(void) { __builtin_printf("%d\n", f(0)); } ``` ^ permalink raw reply [flat|nested] 6+ messages in thread
* [Bug sanitizer/115273] [12 Regression] passing zero to ctz() check missing 2024-05-29 10:37 [Bug sanitizer/115273] New: [12 Regression] passing zero to ctz() check missing bic60176 at gmail dot com ` (2 preceding siblings ...) 2024-06-02 1:45 ` pinskia at gcc dot gnu.org @ 2024-06-02 1:46 ` pinskia at gcc dot gnu.org 2024-06-02 1:51 ` pinskia at gcc dot gnu.org 4 siblings, 0 replies; 6+ messages in thread From: pinskia at gcc dot gnu.org @ 2024-06-02 1:46 UTC (permalink / raw) To: gcc-bugs https://gcc.gnu.org/bugzilla/show_bug.cgi?id=115273 Andrew Pinski <pinskia at gcc dot gnu.org> changed: What |Removed |Added ---------------------------------------------------------------------------- Resolution|--- |DUPLICATE Status|UNCONFIRMED |RESOLVED --- Comment #3 from Andrew Pinski <pinskia at gcc dot gnu.org> --- Dup. *** This bug has been marked as a duplicate of bug 115127 *** ^ permalink raw reply [flat|nested] 6+ messages in thread
* [Bug sanitizer/115273] [12 Regression] passing zero to ctz() check missing 2024-05-29 10:37 [Bug sanitizer/115273] New: [12 Regression] passing zero to ctz() check missing bic60176 at gmail dot com ` (3 preceding siblings ...) 2024-06-02 1:46 ` pinskia at gcc dot gnu.org @ 2024-06-02 1:51 ` pinskia at gcc dot gnu.org 4 siblings, 0 replies; 6+ messages in thread From: pinskia at gcc dot gnu.org @ 2024-06-02 1:51 UTC (permalink / raw) To: gcc-bugs https://gcc.gnu.org/bugzilla/show_bug.cgi?id=115273 --- Comment #4 from Andrew Pinski <pinskia at gcc dot gnu.org> --- Note ubsan can detect (correctly) a different undefined behavior since GCC 13 (since r13-4988-g8692b15ae7c05e; aka PR108256) but the undefinedness of passing 0 to ctz is still not detected and that is a dup of bug 115127 . ^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2024-06-02 1:52 UTC | newest] Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed) -- links below jump to the message on this page -- 2024-05-29 10:37 [Bug sanitizer/115273] New: [12 Regression] passing zero to ctz() check missing bic60176 at gmail dot com 2024-05-29 10:38 ` [Bug sanitizer/115273] " bic60176 at gmail dot com 2024-05-29 11:20 ` rguenth at gcc dot gnu.org 2024-06-02 1:45 ` pinskia at gcc dot gnu.org 2024-06-02 1:46 ` pinskia at gcc dot gnu.org 2024-06-02 1:51 ` pinskia at gcc dot gnu.org
This is a public inbox, see mirroring instructions for how to clone and mirror all data and code used for this inbox; as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).