varbuf: add optional -fbounds-safety annotations for struct ap_varbuf - #754
LaptopsPlural wants to merge 3 commits into
Conversation
Introduce inert AP_SIZED_BY*_ macros (OFF by default) and annotate the ap_varbuf buf/avail pair. Capacity-first assign in large-grow/init/free. Default builds unchanged; ENABLE_FBOUNDS_SAFETY / --enable-fbounds-safety opt-in for experimental Clang toolchains.
|
Very nice! I think this would be better in |
Per notroj's review, place the inert AP_SIZED_BY* / AP_COUNTED_BY* macros next to the existing AP_FN_ATTR_* compiler attribute helpers in ap_config.h and drop the standalone ap_bounds_safety.h.
|
@notroj Thanks — moved the inert macros into |
|
Thanks! Not trying to be awkward here but it looks like that LLVM feature is still a WIP? I was looking to see if there is something similar for GCC and found https://gcc.gnu.org/onlinedocs/gcc/Common-Attributes.html#index-counted_005fby - it's implied this would be used/usable under a UBSAN build already? (I wonder if we could try to trip it, we have UBSAN in CI already) |
|
@notroj Good questions — you’re right on both counts. Yes: Clang GCC’s
So I don’t think we can honestly “trip it in UBSAN CI” with a one-line GCC swap on this struct as it stands. What this PR is aiming for is: inert by default, optional Clang path for people with that toolchain, and capacity-before-pointer assigns so the invariants are correct if/when bounds checking is on. Happy to trim the PR description so it doesn’t oversell the LLVM side, or adjust the macros/docs if you want the GCC/ |
Summary
Secure-by-design memory-safety hardening. Annotates
struct ap_varbuf.bufwith optional Clang-fbounds-safety/ sized-by macros tied toavail. Default builds unchanged (opt-in OFF).Contributor: Jeff Bindel via
LaptopsPlural. Not a vulnerability PoC.Test plan