NetBSD-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

PR/60839 CVS commit: src/external/cddl/osnet/dist/uts/common/dtrace



The following reply was made to PR kern/60839; it has been noted by GNATS.

From: "Taylor R Campbell" <riastradh%netbsd.org@localhost>
To: gnats-bugs%gnats.NetBSD.org@localhost
Cc: 
Subject: PR/60839 CVS commit: src/external/cddl/osnet/dist/uts/common/dtrace
Date: Fri, 2 Oct 2026 21:13:05 +0000

 Module Name:	src
 Committed By:	riastradh
 Date:		Fri Oct  2 21:13:05 UTC 2026
 
 Modified Files:
 	src/external/cddl/osnet/dist/uts/common/dtrace: dtrace.c
 
 Log Message:
 dtrace: Avoid uninitialized stack garbage.
 
 Found by:
 
 PR kern/60839: use -ftrivial-auto-var-init
 
 This applies the code change of the following FreeBSD commit, but I
 didn't understand the comment so I rewrote it:
 
 commit f222a6b88614db13ae83c8110281e690d1381a4c
 Author: Bryan Drewery <bdrewery%FreeBSD.org@localhost>
 Date:   Fri Dec 18 09:58:03 2020 -0800
 
     dtrace: Fix /"string" == NULL/ comparisons using an uninitialized value.
 
     A test of this is funcs/tst.strtok.d which has this filter:
 
         BEGIN
         /(this->field = strtok(this->str, ",")) == NULL/
         {
                 exit(1);
         }
     The test will randomly fail with exit status of 1 indicating that this->field
     was NULL even though printing it out shows it is not.
 
     This is compiled to the DTrace instruction set:
         // Pushed arguments not shown here
         // call strtok() and set result into %r1
         07: 2f001f01    call DIF_SUBR(31), %r1          ! strtok
         // set thread local scalar this->field from %r1
         08: 39050101    stls %r1, DT_VAR(1281)          ! DT_VAR(1281) = "field"
         // Prepare for the == comparison
         // Set right side of %r2 to NULL
         09: 25000102    setx DT_INTEGER[1], %r2         ! 0x0
         // string compare %r1 (strtok result) to %r2
         10: 27010200    scmp %r1, %r2
 
     In this case only %r1 is loaded with a string limit set to lim1.  %r2 being
     NULL does not get loaded and does not set lim2.  Then we call dtrace_strncmp()
     with MIN(lim1, lim2) resulting in passing 0 and comparing neither side.
     dtrace_strncmp() handles this case fine and it already has been while
     being lucky with what lim2 was [un]initialized as.
 
     Reviewed by:    markj, Don Morris <dgmorris AT earthlink.net>
     Sponsored by:   Dell EMC
     Differential Revision:  https://reviews.freebsd.org/D27671
 
 
 To generate a diff of this commit:
 cvs rdiff -u -r1.42 -r1.43 \
     src/external/cddl/osnet/dist/uts/common/dtrace/dtrace.c
 
 Please note that diffs are not public domain; they are subject to the
 copyright notices on the relevant files.
 



Home | Main Index | Thread Index | Old Index