glibc/malloc
Adhemerval Zanella 9bf8e29ca1 malloc: make malloc fail with requests larger than PTRDIFF_MAX (BZ#23741)
As discussed previously on libc-alpha [1], this patch follows up the idea
and add both the __attribute_alloc_size__ on malloc functions (malloc,
calloc, realloc, reallocarray, valloc, pvalloc, and memalign) and limit
maximum requested allocation size to up PTRDIFF_MAX (taking into
consideration internal padding and alignment).

This aligns glibc with gcc expected size defined by default warning
-Walloc-size-larger-than value which warns for allocation larger than
PTRDIFF_MAX.  It also aligns with gcc expectation regarding libc and
expected size, such as described in PR#67999 [2] and previously discussed
ISO C11 issues [3] on libc-alpha.

From the RFC thread [4] and previous discussion, it seems that consensus
is only to limit such requested size for malloc functions, not the system
allocation one (mmap, sbrk, etc.).

The implementation changes checked_request2size to check for both overflow
and maximum object size up to PTRDIFF_MAX. No additional checks are done
on sysmalloc, so it can still issue mmap with values larger than
PTRDIFF_T depending on the requested size.

The __attribute_alloc_size__ is for functions that return a pointer only,
which means it cannot be applied to posix_memalign (see remarks in GCC
PR#87683 [5]). The runtimes checks to limit maximum requested allocation
size does applies to posix_memalign.

Checked on x86_64-linux-gnu and i686-linux-gnu.

[1] https://sourceware.org/ml/libc-alpha/2018-11/msg00223.html
[2] https://gcc.gnu.org/bugzilla//show_bug.cgi?id=67999
[3] https://sourceware.org/ml/libc-alpha/2011-12/msg00066.html
[4] https://sourceware.org/ml/libc-alpha/2018-11/msg00224.html
[5] https://gcc.gnu.org/bugzilla/show_bug.cgi?id=87683

	[BZ #23741]
	* malloc/hooks.c (malloc_check, realloc_check): Use
	__builtin_add_overflow on overflow check and adapt to
	checked_request2size change.
	* malloc/malloc.c (__libc_malloc, __libc_realloc, _mid_memalign,
	__libc_pvalloc, __libc_calloc, _int_memalign): Limit maximum
	allocation size to PTRDIFF_MAX.
	(REQUEST_OUT_OF_RANGE): Remove macro.
	(checked_request2size): Change to inline function and limit maximum
	requested size to PTRDIFF_MAX.
	(__libc_malloc, __libc_realloc, _int_malloc, _int_memalign): Limit
	maximum allocation size to PTRDIFF_MAX.
	(_mid_memalign): Use _int_memalign call for overflow check.
	(__libc_pvalloc): Use __builtin_add_overflow on overflow check.
	(__libc_calloc): Use __builtin_mul_overflow for overflow check and
	limit maximum requested size to PTRDIFF_MAX.
	* malloc/malloc.h (malloc, calloc, realloc, reallocarray, memalign,
	valloc, pvalloc): Add __attribute_alloc_size__.
	* stdlib/stdlib.h (malloc, realloc, reallocarray, valloc): Likewise.
	* malloc/tst-malloc-too-large.c (do_test): Add check for allocation
	larger than PTRDIFF_MAX.
	* malloc/tst-memalign.c (do_test): Disable -Walloc-size-larger-than=
	around tests of malloc with negative sizes.
	* malloc/tst-posix_memalign.c (do_test): Likewise.
	* malloc/tst-pvalloc.c (do_test): Likewise.
	* malloc/tst-valloc.c (do_test): Likewise.
	* malloc/tst-reallocarray.c (do_test): Replace call to reallocarray
	with resulting size allocation larger than PTRDIFF_MAX with
	reallocarray_nowarn.
	(reallocarray_nowarn): New function.
	* NEWS: Mention the malloc function semantic change.
2019-04-18 17:30:06 -03:00
..
alloc_buffer_alloc_array.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
alloc_buffer_allocate.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
alloc_buffer_copy_bytes.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
alloc_buffer_copy_string.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
alloc_buffer_create_failure.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
arena.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
Depend Update. 1999-10-04 22:59:43 +00:00
dynarray_at_failure.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
dynarray_emplace_enlarge.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
dynarray_finalize.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
dynarray_resize_clear.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
dynarray_resize.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
dynarray-skeleton.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
dynarray.h Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
hooks.c malloc: make malloc fail with requests larger than PTRDIFF_MAX (BZ#23741) 2019-04-18 17:30:06 -03:00
Makefile Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
malloc-hooks.h Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
malloc-internal.h Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
malloc.c malloc: make malloc fail with requests larger than PTRDIFF_MAX (BZ#23741) 2019-04-18 17:30:06 -03:00
malloc.h malloc: make malloc fail with requests larger than PTRDIFF_MAX (BZ#23741) 2019-04-18 17:30:06 -03:00
mallocbug.c Reformat malloc to gnu style. 2014-01-02 09:40:10 +01:00
mcheck-init.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
mcheck.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
mcheck.h Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
memusage.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
memusage.sh Update copyright dates not handled by scripts/update-copyrights. 2019-01-01 00:15:13 +00:00
memusagestat.c Break more lines before not after operators. 2019-02-25 13:19:19 +00:00
morecore.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
mtrace.c malloc: Set and reset all hooks for tracing (Bug 16573) 2019-04-09 10:56:51 -04:00
mtrace.pl Update copyright dates not handled by scripts/update-copyrights. 2019-01-01 00:15:13 +00:00
obstack.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
obstack.h Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
reallocarray.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
scratch_buffer_grow_preserve.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
scratch_buffer_grow.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
scratch_buffer_set_array_size.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
set-freeres.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
thread-freeres.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-alloc_buffer.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-calloc.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-dynarray-at-fail.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-dynarray-fail.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-dynarray-shared.h Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-dynarray.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-interpose-aux-nothread.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-interpose-aux-thread.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-interpose-aux.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-interpose-aux.h Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-interpose-nothread.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-interpose-skeleton.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-interpose-static-nothread.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-interpose-static-thread.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-interpose-thread.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-malloc_info.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-malloc-backtrace.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-malloc-fork-deadlock.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-malloc-stats-cancellation.c [BZ #22830] malloc_stats: restore cancellation for stderr correctly. 2018-02-10 16:24:17 -05:00
tst-malloc-tcache-leak.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-malloc-thread-exit.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-malloc-thread-fail.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-malloc-too-large.c malloc: make malloc fail with requests larger than PTRDIFF_MAX (BZ#23741) 2019-04-18 17:30:06 -03:00
tst-malloc-usable-static-tunables.c Initialize tunable list with the GLIBC_TUNABLES environment variable 2016-12-31 23:49:24 +05:30
tst-malloc-usable-static.c Add framework for tunables 2016-12-31 23:49:24 +05:30
tst-malloc-usable-tunables.c Initialize tunable list with the GLIBC_TUNABLES environment variable 2016-12-31 23:49:24 +05:30
tst-malloc-usable.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-malloc.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-mallocfork2.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-mallocfork.c Prefer https for Sourceware links 2017-11-16 11:49:26 +05:30
tst-mallocstate.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-mallopt.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-mcheck.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-memalign.c malloc: make malloc fail with requests larger than PTRDIFF_MAX (BZ#23741) 2019-04-18 17:30:06 -03:00
tst-mtrace.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-mtrace.sh Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-obstack.c Modify several tests to use test-skeleton.c 2014-11-05 15:24:08 +05:30
tst-posix_memalign.c malloc: make malloc fail with requests larger than PTRDIFF_MAX (BZ#23741) 2019-04-18 17:30:06 -03:00
tst-pvalloc.c malloc: make malloc fail with requests larger than PTRDIFF_MAX (BZ#23741) 2019-04-18 17:30:06 -03:00
tst-realloc.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-reallocarray.c malloc: make malloc fail with requests larger than PTRDIFF_MAX (BZ#23741) 2019-04-18 17:30:06 -03:00
tst-scratch_buffer.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-tcfree1.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-tcfree2.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-tcfree3.c Update copyright dates with scripts/update-copyrights. 2019-01-01 00:11:28 +00:00
tst-trim1.c * malloc/tst-trim1.c: New file. 2007-12-16 22:57:57 +00:00
tst-valloc.c malloc: make malloc fail with requests larger than PTRDIFF_MAX (BZ#23741) 2019-04-18 17:30:06 -03:00
Versions Implement allocation buffers for internal use 2017-06-21 22:43:57 +02:00