| Age | Commit message (Collapse) | Author | Lines |
|
the category values from the old locale were only being used for a
non-null base; for null ((locale_t)0) base, a lookup for "" was
wrongly being performed rather than using the C locale values.
this caused, for example, newlocale(LC_CTYPE_MASK,"",0) to produce a
locale_t matching newlocale(LC_ALL_MASK,"",0) rather than one that
only reflects LC_CTYPE.
|
|
these ranges are special-cased because they lie near the top of the
encoding space far above where the bit tables currently end, and they
are unlikely to change often. the last character in each of these
ranges failed to get reported as having width 0.
|
|
the code to implement a modular postincrement was too clever, and
essentially did it as a reducing version of (z+=1)-1, but only applied
the redution after the addition not the subtraction. as a result, it
evaluated to -1 when wrapping, causing a fixed value of zero to be
stored out of bounds below the buffer.
whether this condition is triggered depends on where the mantissa bits
end up in the circular buffer after processing.
for archs with 80-bit extended long double or IEEE quad long double,
the input "710542735760100185871124267578125e-33" was reported to and
has been confirmed to trigger it.
|
|
the new condition also allows forward progress into ordinary matching
if the pattern begins with a backslash. this is fine independent of
FNM_NOESCAPE and independent of what follows the backslash; if
FNM_NOESCAPE is active, the backslash is literal and will not match.
if FNM_NOESCAPE is not active, the pattern beginning with a backslash
ensures that the first character is literal.
|
|
previously, the malloc-failure error path cleared it, but other
failures from vsnprintf such as EILSEQ or EOVERFLOW left the original
contents of the result object in place.
leaving any old value in place is allowed, and would be required if
the specification did not explicitly permit clobbering it on failure,
but it does.
by overwriting any old value there with a null pointer, we harden
callers that might have failed to check the return value for errors
against accessing and possibly exposing unrelated data; instead they
will fault on dereference.
|
|
in this case, negation produces integer overflow. since a field width
of the faithfully negated value would necessarily overflow INT_MAX,
just detect this case and immediately treat it as an output overflow
error.
|
|
this magic number 4 is what ensures the next wctomb won't overflow the
allocated buffer, but its purpose wasn't clear.
|
|
Allocated narrow %c conversions initially reserve only width+1 bytes.
For the default width this is two bytes, but in a UTF-8 locale wctomb
can write up to MB_LEN_MAX bytes into the buffer before the
post-conversion growth check, overflowing the two-byte allocation for
a three- or four-byte input character.
Ensure every allocated narrow buffer starts at no less than
MB_LEN_MAX bytes. The existing geometric growth then keeps at least
MB_LEN_MAX spare bytes available after each conversion.
|
|
on archs with 32-bit size_t, multiplying the caller-provided signed
int field width by sizeof(wchar_t) can overflow.
we could explicitly error out, but just replacing the requested size
to let malloc fail avoids the need to poke at errno, and the rest of
the function here is already using guaranteed-fail in the geometric
buffer growth path to avoid explicit size checks.
|
|
added 'set --' so $@, $*, $#, $1, $2 are cleared
(does not seem to be in the spec, but cleaner)
wordexp("$*", p, 0)
was "$*","2>/dev/stderr", now empty list.
|
|
stderr redirection to /dev/null didn't work, can be done in the
command, but would not redirect errors printed during sh startup.
wordexp(")", p, 0)
clobbered stderr, now silent.
|
|
On an unsuccessful search, the backwards loop decrements the pointer
past the beginning of the string and then compares that invalid pointer
with the string pointer.
Check for the beginning of the string before decrementing instead. This
preserves the existing results without forming a pointer outside the
array.
|
|
The continue for lines longer than INT_MAX reaches the do-while
condition without initializing n. On the first such line, the condition
reads indeterminate values. After an earlier line, it reuses stale
offsets from that line.
Jump directly to the start of the loop instead. This is the minimal form
requested in the previous review and preserves the intended behavior of
skipping an overlong line.
|
|
the new code uses that for all real |x| in [0x1p-999,0x1p999]
y = (float)x
is the same as
r = (double)x
t = x - r
if (t!=0 && r.bits%2==0)
r.bits += (r<0)==(t<0) ? 1 : -1
y = (float)r
in all rounding modes, with the same fenv effects.
this can be interpreted as a round to odd adjustment[1].
in fmaf t is computed with a fast2sum variant.
- optimized common case.
- implicit uflow handling instead of fenv calls.
- no fegetround check.
- no api calls on hf targets.
- fixed missed uflow on targets that signal it before rounding:
fmaf(-0x1p-100f, 0x1p-100f, 0x1p-126f)
- removed freebsd code references and comments.
- fmaf.o code size vs before the halfway subnormal fix:
x86_64: 514 -> 210
armhf: 304 -> 156 (v7 thumb, no vfma op)
arm: 400 -> 348 (soft float, no fenv)
round to odd paper (suggested by Sergey Davidoff):
[1] S. Boldo et al., Emulation of a FMA and correctly-rounded sums:
proved algorithms using rounding to odd, 2008
|
|
inexact halfway cases were not handled correctly for subnormals
fmaf(0x20201p-92f, 0x1fe01p-92f, 0x1p-130f)
= (float)(0x1p-130 + 0x1.000000004p-150)
was rounded to 0x1.00001p-130 first in double precision, then to
0x1p-130 in the float subnormal range instead of 0x1.00002p-130.
this is a minimal fix of the halfway check.
Reported-by: Sergey Davidoff <shnatsel@gmail.com>
|
|
TZif v1 encodes its version as NUL, but do_tzset treats only the byte
'1' as v1. It consequently reads a valid v1 file as if it contained a
second header.
Use zero and nonzero version bytes to distinguish v1 from later files.
|
|
stddef.h is unused, commit da88b16a221c9d327e1bfa61dd6f4f08dacce57a
removed the use of offsetof().
|
|
calling qsort() with a pointer to a function whose type is not
compatible with int(const void *, const void *) results in UB because
qsort() would call this function with an incompatible type.
avoid this by using qsort_r(). this is similar to how qsort() is
implemented on top of qsort_r().
the types of the pointers passed to wrapper_cmp() are
struct dirent *const * but the caller's comparison function expects
const struct dirent **. copy the pointer values into local variables
and pass their addresses to the caller's comparison function to get
the right type and avoid aliasing violations.
this is only necessary because the pointer to the comparison function
for scandir() was (incorrectly) specified as
int (*)(const struct dirent **, const struct dirent **) rather than
int (*)(struct dirent *const *, struct dirent *const *).
|
|
if the loop is exited because len * sizeof *names does not fit into
size_t, errno should be explicitly set to ENOMEM. previously, the
behavior differed depending on which value errno happened to have at
this point.
if cnt reached a value > INT_MAX, scandir() returned an incorrect
value. EOVERFLOW should be reported instead.
it's unlikely that these errors can actually occur. it may not even
be possible to have directories with that many entries, and even then
malloc() or realloc() will probably fail long before len or cnt reach
those large values.
|
|
opendir() or closedir() might act upon a cancellation request. because
scandir() did not disable cancellation or install a cancellation
cleanup handler, this could lead to memory and file descriptor leaks.
|
|
when closedir() set errno, scandir() misinterpreted this as a failure.
this was wrong for two reasons:
* if closedir() succeeds, errno could still have been set, e.g. by
__aio_close().
* even if closedir() "fails", it always closes the file descriptor and
frees memory, so there is no reason to free all directory entries
and return from scandir() with a failure.
|
|
POSIX.1-2024 requires that standard functions don't set errno to 0.
commit dae17a1aaf25d8333e729173d86659066607d87d ensured that cmp() and
the caller of scandir() cannot observe that errno is set to 0
internally. however, this was not yet the case for the sel() callback.
|
|
the standard allows but does not require detecting bad catalog
descriptors and reporting the as EBADF. detection is only possible in
the general case if nl_catd is its own resource identifier namespace
not shaed with address space or file descriptors or anything else;
however, (nl_catd)-1 is always detectable since it's reserved as an
error value, and reportedly all other implementations detect this
condition and just return the untranslated string. users of catgets,
including tcsh, rely on this.
|
|
(v)sprint() is supposed to return the number of bytes written to s,
excluding the terminating null byte. however, when these functions
return INT_MAX, only INT_MAX - 1 bytes (excluding the terminating null
byte) are written.
this is caused by the way vsprintf() is implemented: calling
vsnprintf() with n = INT_MAX. vsnprintf() returns the number of bytes
that would be written to s had n been sufficiently large excluding the
terminating null byte. output bytes beyond the n-1st are discarded.
to accommodate the largest strings (v)sprintf() can produce (length
INT_MAX, the return value is of type int), vsnprintf() has to be
called with n >= INT_MAX + 1.
calling vsnprintf() with n > INT_MAX is possible since commit
11fb383275d20f5f94c00425bd888a02ecbd218e.
|
|
expl asm special cased |x|>=16384 and used 2^trunc(x) then,
but this was wrong for x<=-16384 when 2^trunc(x) doesn't
underflow to 0. fixed by bumping the threshold up to 32768.
Reported-by: Paul Zimmermann <Paul.Zimmermann@inria.fr>
|
|
when x<0 and y is an odd int then powl is computed for -x first
then negated at the end. some overflow cases missed the negation:
powl(-1.5, 50001)
powl(-0.5, 50001)
powl(-0x1p-16444L, -1)
returned inf, 0 and inf instead of the negated values.
Reported-by: Paul Zimmermann <Paul.Zimmermann@inria.fr>
|
|
getword allocates the next expanded word before the result vector is
grown. If realloc fails, that word has not been stored in the vector and
cannot be reached by wordfree, so returning WRDE_NOSPACE leaks it.
Free the exclusively owned word before leaving the loop. Existing
partial results and the returned error are unchanged.
|
|
The ABI requires a stack frame to, at minimum, consist of the backchain slot and
the LR save slot at sp+0 and sp+4 respectively. The old code spilled r30/r31
into those slots, meaning that a backchain-based unwinder would see a nonsense
value as the backchain pointer and go on a wild goose chase.
It's admittedly a very small window where this is possible -- a thread that's
stopped in the middle of the clone() parent body -- but fixing it just requires
shifting the r30/r31 spill slots down by 8 bytes and storing the old sp in the
backchain slot, so seems reasonable to do.
|
|
As usual, clearing fp helps simple/generic frame-pointer-based unwinders.
Clearing ra unbreaks DWARF unwinders because ra would otherwise contain garbage
from _start all the way through to libc_start_main_stage2. The CFI for
libc_start_main_stage2 would then incorrectly claim that ra contains a perfectly
valid return address that the unwinder should proceed through. If that return
address just so happened to land inside a real function somewhere, the unwinder
would then happily proceed to run that function's CFI on a completely unrelated
register context, unsurprisingly leading to weird crashes.
As an aside: Some ports don't clear their ra equivalent in _start, but they do
use a linked branch to _start_c. That works out too because the unwinder then
actually reaches _start which intentionally has no CFI, so it stops there.
Between these approaches, clearing ra and using an unlinked branch tends to lead
to slightly nicer stack traces for users because there won't be an unwind error
printed for the _start frame (due to missing CFI).
|
|
It's a 32-bit pointer and passed on the stack; the upper 32 bits of the stack
slot are garbage. This works out fine if we're lucky and those bits happen to be
zeroed, but if they're not, we ask the kernel to write to some random 64-bit
location, which it will just silently fail to do (the process is in x32 mode;
nothing can be mapped up there), and consequently, we never learn the new
thread's tid.
|
|
or1k uses an unusual variant of the TLS_ABOVE_TP layout:
powerpc, mips, m68k:
pthread | tls
+----------+-----------------+--
| |< tpoff >|
self a = e = m tp
arm, aarch64, sh:
pthread < gap >| tls
+----------+-------------+------
| | |
self a = e = tp m
or1k:
pthread < gap >| tls
+----------+-------------+------
| |< tpoff >|
self a = e m = tp
tp: thread pointer
a: address aligned to tls_align
e: end of the libc internal pthread self struct
m: min user tls address
the layout variant only matters for local-exec tls access, but then
ld and libc have to match how tp-relative tls addresses are computed.
or1k is tpoff=gap=16 in bfd ld, but it was gap=tpoff=0 in musl. this
works if tls_align <= 16, but an exe with larger tls_align fails.
TP_OFFSET (tpoff) and GAP_ABOVE_TP (gap) are now defined as
tpoff: tp - a
gap: m - a (so it is not really "gap above tp")
TPOFF_K = -tpoff is needed for relocs as the tls_module->offset is
internally computed relative to a, not tp.
this changes tp - e on or1k which in general may affect internal abi
(e.g. tlsdesc asm uses self->dtv) or toolchain abi (the layout below
m is not visible to the elf abi, but e.g. ssp uses self->canary on
some targets with fixed tp offset), but or1k seems unaffected. it is
possible to place the pthread struct such that tp = m = e on or1k,
to aviod this abi change, but that looks uglier (e.g. a != e then).
found and tested on user qemu-or1k.
|
|
at least gai_strerror() and regerror() are specified to accept any int
value. if the value was close to INT_MAX (for gai_strerror()) or
INT_MIN (for hstrerror() and regerror()) a signed integer overflow
would occur.
fix this by converting the int argument to unsigned before doing
arithmetic.
|
|
Add explicit padding between struct fields with alignment attributes.
This ensures that the struct layout is the same with and without the
attribute.
|
|
DNS query retry interval is calculated through timeout / attempts in
__res_msend_rc(), both are loaded from resolv.conf in
__get_resolv_conf(), while value of attempts isn't checked. This would
trigger an undefined behavior if attempts is set to zero in
configuration, causing misfunction or termination with SIGFPE.
Gracefully handle it by returning early.
|
|
POSIX.1-2024 requires both dirent.h and sys/types.h to define this
type.
|
|
the documented type is int. on 64-bit archs, callers which truncate
the result from the raw bitmask to int will not see any bits above 31
as being set.
|
|
This matches what is done for the x32 port. As far as I can tell based on kernel
and glibc sources, this is the expected kABI for mipsn32 since the syscall path
uses the n32 calling convention, i.e. full 64-bit registers. Before this patch,
you would get compiler warnings about truncation of off_t values in various
syscall wrappers.
As for x32, I left the return type (and r2 register variable type) as long since
lseek() remains the only syscall with a 64-bit return type on ILP32 targets.
This change has been tested by running Zig's module tests for
mips64-linux-muslabin32 and mips64el-linux-muslabin32 with no regressions.
|
|
commit cb0cdc2e88c652af225d2fc31c1dec99b9880d39 broke this as part of
future proofing.
|
|
this fixes a build regression for riscv32 introduced in commit
b306b16af15c89a04d8e0c55cac2dadbeb39c083. prior to that, the riscv32
bits/syscall.h.in defined a macro for the nanosleep syscall, despite
the kernel on time64-native archs having no such syscall.
our clock_nanosleep uses the old nanosleep syscall when possible as
part of minimal compatibility with pre-2.6 kernels. using a
non-functional syscall number didn't have any ill effect on riscv32 or
future time64-native archs, since the affected code is unreachable in
that case, but removing the wrongly defined macro broke the build.
this change fixes it.
in order not to need to fix this again if future 64-bit archs also
drop the old nanosleep syscall factor out the conditional use of
SYS_nanosleep and use the same approach in the preprocessor else block
for them.
|
|
ftello adds pending buffered output to the position reported by the
underlying seek operation. Near LLONG_MAX, the addition can overflow
signed off_t and return an apparently successful negative position.
Check that the buffered-byte count fits before adding it. Fail with
EOVERFLOW when the logical position cannot be represented.
|
|
For SEEK_CUR, fseeko subtracts the unread input-buffer length from the
caller's offset before invoking the underlying seek operation. A valid
LLONG_MIN offset therefore overflows before the seek can reject the
unrepresentable logical result.
Detect the underflow and fail with EOVERFLOW without flushing or
discarding the stream's buffers.
|
|
mktime is required to accept and normalize out-of-range members of
struct tm. When tm_mday is INT_MIN, subtracting one from it overflows
before the existing long long multiplication takes effect.
Perform the subtraction in long long so the complete int range can be
normalized as intended.
|
|
Fresh writable streams use null wpos and wend pointers until output is
initialized. The non-ASCII path adds MB_LEN_MAX to wpos before comparing
it with wend, which is invalid for a null pointer. The addition can also
form a pointer beyond one past the buffer when little space remains.
First require an active output buffer. Then compare the defined
difference between its pointers. Preserve the existing strict capacity
test and use the normal write fallback otherwise.
|
|
|
|
acosh(-0x1.8p15) returned -3.7534177368329567 instead of nan.
the same issue got fixed for acoshf and acoshl in commits
c4c38e6364323b6d83ba3428464e19987b981d7a and
6d10102709df4bc966d2846c1c45cd667e5048e5 here we follow the latter.
reported by Paul Zimmermann.
|
|
since commit e1a51185ceb4386481491e11f6dd39569b9e54f7, popen obeys an
obscure historical requirement to implement a sort of pseudo-cloexec
behavior for other pipe streams obtained by popen. but since popen
uses posix_spawn (and thereby posix_spawn file actions) internally,
the time of check for other pipe streams is separated from the time of
closure.
this was intended to be addressed by popen holding the open file list
lock across posix_spawn, but pclose (via fclose) closes the file
descriptor before taking the open file list lock, only using the lock
for updating the linked list pointers. this is to avoid serializing
fclose operations across the entire process, since in general close
may be a blocking operation.
multiple solutions to this problem were considered, but the simplest
and least invasive is conditionally taking the open file list lock
early for popen streams -- that is, for FILE streams where the
pipe_pid member is nonzero. since the file descriptor refers to a
pipe, closing it is a simple, nonblocking operation, and the only cost
is the time spent entering and leaving kernelspace while the lock is
held.
since individual FILE locks cannot be held while taking the open file
list lock (this would violate lock order protocol and produce
deadlocks), the FILE lock must be released after fflush but before the
ofl lock is taken. there is no point in retaking the lock afterwards,
since the FILE pointer is no longer valid and any further use by the
application would be undefined. so, simply let fflush do the locking.
note that the early return path (F_PERM) is not reachable for popen
streams, only for stdin/stdout/stderr, which are always normal FILEs.
thus, it does not provide a code path to return with the ofl lock
still held.
|
|
nanosleep is a time32 syscall which riscv32 lacks by being natively
time64. the erroneous macro being present did not break anything libc
internal, because SYS_nanosleep is never used in the natively-time64
path, but i could in theory cause applications to wrongly attempt to
use it if they do their own syscalls. it has wrongly been there since
the riscv32 port was added.
close_range and quotactl_fd were somehow omitted in commit
8432d16a4664433b2f9a263aee0d7d829129a7bc.
|
|
the namespace-safety remappings in glue.h handled mmap, madvise, and
mremap correctly but somehow overlooked munmap and mprotect.
|
|
LDBL_* macros were not defined in logbl.
the code happens to be correct without them, but when the long double
format matches double the intention was to tail call logb.
|
|
the expression LDBL_MANT_DIG/4+1 was intended to represent the number
of hex digits which can be significant, after which all that matters
to the result, regardless of rounding mode, is whether any part of the
tail is nonzero.
however, the expression LDBL_MANT_DIG/4 is only exact for ld80 archs.
for ld64 and ld128, the truncation of the remainder caused one too few
digits to be processed, producing incorrect rounding.
for ld128 archs, only strtold and scanf's %La conversion specifier
were affected; doubles and floats still had plenty of trailing digits
to yield a correct final rounding. but for ld64 archs, the number of
digits processed were insufficient for double, and could affect any
code using strtod or scanf's %a.
for ld64 archs, 0x1.111111111111281 produces an incorrect rounding
down, and 0x1.11111111111111 produces an incorrect rounding up.
for ld128 archs, the inputs 0x1.111111111111111111111111111281 and
0x1.11111111111111111111111111111 behave respectively.
rounding up in the expression for the number of hex digits needed
produces correct results.
|