Skip to content

Simplify byte extract: fix unconditional read from optional values #7376

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Nov 23, 2022

Conversation

tautschnig
Copy link
Collaborator

We did not take into account that pointer_offset_bits may have failed to produce an integer value. Observed on some SV-COMP benchmarks (busybox/od).

  • Each commit message has a non-empty body, explaining why the change was made.
  • n/a Methods or procedures I have added are documented, following the guidelines provided in CODING_STANDARD.md.
  • n/a The feature or user visible behaviour I have added or modified has been documented in the User Guide in doc/cprover-manual/
  • Regression or unit tests are included, or existing tests cover the modified code (in this case I have detailed which ones those are in the commit message).
  • n/a My commit message includes data points confirming performance improvements (if claimed).
  • My PR is restricted to a single feature or bugfix.
  • n/a White-space or formatting changes outside the feature-related changed lines are in commits of their own.

We did not take into account that pointer_offset_bits may have failed to
produce an integer value. Observed on some SV-COMP benchmarks
(busybox/od).
@codecov
Copy link

codecov bot commented Nov 23, 2022

Codecov Report

Base: 78.35% // Head: 78.35% // Decreases project coverage by -0.00% ⚠️

Coverage data is based on head (c7550b6) compared to base (28b76fa).
Patch coverage: 72.22% of modified lines in pull request are covered.

Additional details and impacted files
@@             Coverage Diff             @@
##           develop    #7376      +/-   ##
===========================================
- Coverage    78.35%   78.35%   -0.01%     
===========================================
  Files         1645     1645              
  Lines       190190   190182       -8     
===========================================
- Hits        149031   149015      -16     
- Misses       41159    41167       +8     
Impacted Files Coverage Δ
unit/solvers/sat/external_sat.cpp 100.00% <ø> (ø)
src/solvers/sat/external_sat.cpp 81.81% <28.57%> (-6.42%) ⬇️
src/ansi-c/c_typecheck_expr.cpp 75.34% <100.00%> (-0.02%) ⬇️
src/pointer-analysis/value_set.cpp 82.46% <100.00%> (-0.05%) ⬇️
src/util/simplify_expr.cpp 85.29% <100.00%> (+<0.01%) ⬆️
src/nonstd/optional.hpp 96.18% <0.00%> (-1.53%) ⬇️

Help us with your feedback. Take ten seconds to tell us how you rate us. Have a feature suggestion? Share it here.

☔ View full report at Codecov.
📢 Do you have feedback about the report comment? Let us know in this issue.

@@ -1680,15 +1680,19 @@ simplify_exprt::simplify_byte_extract(const byte_extract_exprt &expr)
{
return op_byte_update.value();
}
else if(
el_size.has_value() &&
*el_size <= pointer_offset_bits(op_byte_update.value().type(), ns))
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Huh.. wasn't there even a compiler warning on that?

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was invoking this piece of code:
https://github.com/diffblue/cbmc/blob/8848ad878da46bbcd0cedad634e235e6faf8cb17/src/nonstd/optional.hpp#L997..L1000
which will return false when the optionalt doesn't have a value.

@peterschrammel peterschrammel removed their assignment Nov 23, 2022
@tautschnig tautschnig merged commit e04d0eb into diffblue:develop Nov 23, 2022
@tautschnig tautschnig deleted the bugfixes/simp-byte-extract branch November 23, 2022 19:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants