|
Paolo Bonzini |
6ea72c |
From 07a446e7f869f79104bcc1d6accdc462e7bf7ba5 Mon Sep 17 00:00:00 2001
|
|
Paolo Bonzini |
6ea72c |
From: Laszlo Ersek <lersek@redhat.com>
|
|
Paolo Bonzini |
6ea72c |
Date: Fri, 2 Mar 2018 19:09:23 +0100
|
|
Paolo Bonzini |
6ea72c |
Subject: [PATCH 2/3] BaseTools/header.makefile: add "-Wno-restrict"
|
|
Paolo Bonzini |
6ea72c |
|
|
Paolo Bonzini |
6ea72c |
gcc-8 (which is part of Fedora 28) enables the new warning
|
|
Paolo Bonzini |
6ea72c |
"-Wrestrict" in "-Wall". This warning is documented in detail
|
|
Paolo Bonzini |
6ea72c |
at <https://gcc.gnu.org/onlinedocs/gcc/Warning-Options.html>; the
|
|
Paolo Bonzini |
6ea72c |
introduction says
|
|
Paolo Bonzini |
6ea72c |
|
|
Paolo Bonzini |
6ea72c |
> Warn when an object referenced by a restrict-qualified parameter (or, in
|
|
Paolo Bonzini |
6ea72c |
> C++, a __restrict-qualified parameter) is aliased by another argument,
|
|
Paolo Bonzini |
6ea72c |
> or when copies between such objects overlap.
|
|
Paolo Bonzini |
6ea72c |
|
|
Paolo Bonzini |
6ea72c |
It breaks the BaseTools build (in the Brotli compression library) with:
|
|
Paolo Bonzini |
6ea72c |
|
|
Paolo Bonzini |
6ea72c |
> In function 'ProcessCommandsInternal',
|
|
Paolo Bonzini |
6ea72c |
> inlined from 'ProcessCommands' at dec/decode.c:1828:10:
|
|
Paolo Bonzini |
6ea72c |
> dec/decode.c:1781:9: error: 'memcpy' accessing between 17 and 2147483631
|
|
Paolo Bonzini |
6ea72c |
> bytes at offsets 16 and 16 overlaps between 17 and 2147483631 bytes at
|
|
Paolo Bonzini |
6ea72c |
> offset 16 [-Werror=restrict]
|
|
Paolo Bonzini |
6ea72c |
> memcpy(copy_dst + 16, copy_src + 16, (size_t)(i - 16));
|
|
Paolo Bonzini |
6ea72c |
> ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
|
Paolo Bonzini |
6ea72c |
> In function 'ProcessCommandsInternal',
|
|
Paolo Bonzini |
6ea72c |
> inlined from 'SafeProcessCommands' at dec/decode.c:1833:10:
|
|
Paolo Bonzini |
6ea72c |
> dec/decode.c:1781:9: error: 'memcpy' accessing between 17 and 2147483631
|
|
Paolo Bonzini |
6ea72c |
> bytes at offsets 16 and 16 overlaps between 17 and 2147483631 bytes at
|
|
Paolo Bonzini |
6ea72c |
> offset 16 [-Werror=restrict]
|
|
Paolo Bonzini |
6ea72c |
> memcpy(copy_dst + 16, copy_src + 16, (size_t)(i - 16));
|
|
Paolo Bonzini |
6ea72c |
> ^~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
|
Paolo Bonzini |
6ea72c |
|
|
Paolo Bonzini |
6ea72c |
Paolo Bonzini <pbonzini@redhat.com> analyzed the Brotli source in detail,
|
|
Paolo Bonzini |
6ea72c |
and concluded that the warning is a false positive:
|
|
Paolo Bonzini |
6ea72c |
|
|
Paolo Bonzini |
6ea72c |
> This seems safe to me, because it's preceded by:
|
|
Paolo Bonzini |
6ea72c |
>
|
|
Paolo Bonzini |
6ea72c |
> uint8_t* copy_dst = &s->ringbuffer[pos];
|
|
Paolo Bonzini |
6ea72c |
> uint8_t* copy_src = &s->ringbuffer[src_start];
|
|
Paolo Bonzini |
6ea72c |
> int dst_end = pos + i;
|
|
Paolo Bonzini |
6ea72c |
> int src_end = src_start + i;
|
|
Paolo Bonzini |
6ea72c |
> if (src_end > pos && dst_end > src_start) {
|
|
Paolo Bonzini |
6ea72c |
> /* Regions intersect. */
|
|
Paolo Bonzini |
6ea72c |
> goto CommandPostWrapCopy;
|
|
Paolo Bonzini |
6ea72c |
> }
|
|
Paolo Bonzini |
6ea72c |
>
|
|
Paolo Bonzini |
6ea72c |
> If [src_start, src_start + i) and [pos, pos + i) don't intersect, then
|
|
Paolo Bonzini |
6ea72c |
> neither do [src_start + 16, src_start + i) and [pos + 16, pos + i).
|
|
Paolo Bonzini |
6ea72c |
>
|
|
Paolo Bonzini |
6ea72c |
> The if seems okay:
|
|
Paolo Bonzini |
6ea72c |
>
|
|
Paolo Bonzini |
6ea72c |
> (src_start + i > pos && pos + i > src_start)
|
|
Paolo Bonzini |
6ea72c |
>
|
|
Paolo Bonzini |
6ea72c |
> which can be rewritten to:
|
|
Paolo Bonzini |
6ea72c |
>
|
|
Paolo Bonzini |
6ea72c |
> (pos < src_start + i && src_start < pos + i)
|
|
Paolo Bonzini |
6ea72c |
>
|
|
Paolo Bonzini |
6ea72c |
> Then the numbers are in one of these two orders:
|
|
Paolo Bonzini |
6ea72c |
>
|
|
Paolo Bonzini |
6ea72c |
> pos <= src_start < pos + i <= src_start + i
|
|
Paolo Bonzini |
6ea72c |
> src_start <= pos < src_start + i <= pos + i
|
|
Paolo Bonzini |
6ea72c |
>
|
|
Paolo Bonzini |
6ea72c |
> These two would be allowed by the "if", but they can only happen if pos
|
|
Paolo Bonzini |
6ea72c |
> == src_start so they degenerate to the same two orders above:
|
|
Paolo Bonzini |
6ea72c |
>
|
|
Paolo Bonzini |
6ea72c |
> pos <= src_start < src_start + i <= pos + i
|
|
Paolo Bonzini |
6ea72c |
> src_start <= pos < pos + i <= src_start + i
|
|
Paolo Bonzini |
6ea72c |
>
|
|
Paolo Bonzini |
6ea72c |
> So it is a false positive in GCC.
|
|
Paolo Bonzini |
6ea72c |
|
|
Paolo Bonzini |
6ea72c |
Disable the warning for now.
|
|
Paolo Bonzini |
6ea72c |
|
|
Paolo Bonzini |
6ea72c |
Cc: Ard Biesheuvel <ard.biesheuvel@linaro.org>
|
|
Paolo Bonzini |
6ea72c |
Cc: Cole Robinson <crobinso@redhat.com>
|
|
Paolo Bonzini |
6ea72c |
Cc: Liming Gao <liming.gao@intel.com>
|
|
Paolo Bonzini |
6ea72c |
Cc: Paolo Bonzini <pbonzini@redhat.com>
|
|
Paolo Bonzini |
6ea72c |
Cc: Yonghong Zhu <yonghong.zhu@intel.com>
|
|
Paolo Bonzini |
6ea72c |
Reported-by: Cole Robinson <crobinso@redhat.com>
|
|
Paolo Bonzini |
6ea72c |
Contributed-under: TianoCore Contribution Agreement 1.1
|
|
Paolo Bonzini |
6ea72c |
Signed-off-by: Laszlo Ersek <lersek@redhat.com>
|
|
Paolo Bonzini |
6ea72c |
Message-Id: <20180302180924.4312-3-lersek@redhat.com>
|
|
Paolo Bonzini |
6ea72c |
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
|
|
Paolo Bonzini |
6ea72c |
---
|
|
Paolo Bonzini |
6ea72c |
BaseTools/Source/C/Makefiles/header.makefile | 4 ++--
|
|
Paolo Bonzini |
6ea72c |
1 file changed, 2 insertions(+), 2 deletions(-)
|
|
Paolo Bonzini |
6ea72c |
|
|
Paolo Bonzini |
6ea72c |
diff --git a/BaseTools/Source/C/Makefiles/header.makefile b/BaseTools/Source/C/Makefiles/header.makefile
|
|
Paolo Bonzini |
6ea72c |
index 6c3826aecb..3feae10095 100644
|
|
Paolo Bonzini |
6ea72c |
--- a/BaseTools/Source/C/Makefiles/header.makefile
|
|
Paolo Bonzini |
6ea72c |
+++ b/BaseTools/Source/C/Makefiles/header.makefile
|
|
Paolo Bonzini |
6ea72c |
@@ -47,9 +47,9 @@ INCLUDE = $(TOOL_INCLUDE) -I $(MAKEROOT) -I $(MAKEROOT)/Include/Common -I $(MAKE
|
|
Paolo Bonzini |
6ea72c |
BUILD_CPPFLAGS = $(INCLUDE) -O2
|
|
Paolo Bonzini |
6ea72c |
ifeq ($(DARWIN),Darwin)
|
|
Paolo Bonzini |
6ea72c |
# assume clang or clang compatible flags on OS X
|
|
Paolo Bonzini |
6ea72c |
-BUILD_CFLAGS = -MD -fshort-wchar -fno-strict-aliasing -Wall -Werror -Wno-deprecated-declarations -Wno-stringop-truncation -Wno-self-assign -Wno-unused-result -nostdlib -c -g
|
|
Paolo Bonzini |
6ea72c |
+BUILD_CFLAGS = -MD -fshort-wchar -fno-strict-aliasing -Wall -Werror -Wno-deprecated-declarations -Wno-stringop-truncation -Wno-restrict -Wno-self-assign -Wno-unused-result -nostdlib -c -g
|
|
Paolo Bonzini |
6ea72c |
else
|
|
Paolo Bonzini |
6ea72c |
-BUILD_CFLAGS = -MD -fshort-wchar -fno-strict-aliasing -Wall -Werror -Wno-deprecated-declarations -Wno-stringop-truncation -Wno-unused-result -nostdlib -c -g
|
|
Paolo Bonzini |
6ea72c |
+BUILD_CFLAGS = -MD -fshort-wchar -fno-strict-aliasing -Wall -Werror -Wno-deprecated-declarations -Wno-stringop-truncation -Wno-restrict -Wno-unused-result -nostdlib -c -g
|
|
Paolo Bonzini |
6ea72c |
endif
|
|
Paolo Bonzini |
6ea72c |
BUILD_LFLAGS =
|
|
Paolo Bonzini |
6ea72c |
BUILD_CXXFLAGS = -Wno-unused-result
|
|
Paolo Bonzini |
6ea72c |
--
|
|
Paolo Bonzini |
6ea72c |
2.14.3
|
|
Paolo Bonzini |
6ea72c |
|