Skip to content

Commit 1335da3

Browse files
committed
BUILD: add detection of missing important CFLAGS
Modern compilers love to break existing code, and some options detected at build time (such as -fwrapv) are absolutely critical otherwise some bad code can be generated. Given that some users rely on packages that force CFLAGS without being aware of this and can be hit by runtime bugs, we have to help packagers figure that they need to be careful about their build options. The test here consists in detecting correct wrapping of signed integers. Some of the old code relies on it, and modern compilers recently decided to break it. It's normally addressed using -fwrapv which users will rarely enforce in their own flags. Thus it is a good indicator of missing critical CFLAGS, and it happens to be very easy to detect at run time. Note that the test uses argc in order to have a variable. While gcc ignores wrapping even for constants, clang only ignores it for variables. The way the code is constructed doesn't result in code being emitted for optimized builds thanks to value range propagation. This should address GitHub issue #1315, and should be backported to all stable versions. It may result in instantly breaking binaries that seemed to work fine (typically the ones suddenly showing a busy loop after a few weeks of uptime), and require packagers to fix their flags. The vast majority of distro packages are fine and will not be affected though.
1 parent 0498fa4 commit 1335da3

1 file changed

Lines changed: 32 additions & 0 deletions

File tree

‎src/haproxy.c‎

Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2842,6 +2842,38 @@ int main(int argc, char **argv)
28422842
int err, retry;
28432843
struct rlimit limit;
28442844
int pidfd = -1;
2845+
int intovf = (unsigned char)argc + 1; /* let the compiler know it's strictly positive */
2846+
2847+
/* Catch forced CFLAGS that miss 2-complement integer overflow */
2848+
if (intovf + 0x7FFFFFFF >= intovf) {
2849+
fprintf(stderr,
2850+
"FATAL ERROR: invalid code detected -- cannot go further, please recompile!\n"
2851+
"The source code was miscompiled by the compiler, which usually indicates that\n"
2852+
"some of the CFLAGS needed to work around overzealous compiler optimizations\n"
2853+
"were overwritten at build time. Please do not force CFLAGS, and read Makefile\n"
2854+
"and INSTALL files to decide on the best way to pass your local build options.\n"
2855+
"\nBuild options :"
2856+
#ifdef BUILD_TARGET
2857+
"\n TARGET = " BUILD_TARGET
2858+
#endif
2859+
#ifdef BUILD_CPU
2860+
"\n CPU = " BUILD_CPU
2861+
#endif
2862+
#ifdef BUILD_CC
2863+
"\n CC = " BUILD_CC
2864+
#endif
2865+
#ifdef BUILD_CFLAGS
2866+
"\n CFLAGS = " BUILD_CFLAGS
2867+
#endif
2868+
#ifdef BUILD_OPTIONS
2869+
"\n OPTIONS = " BUILD_OPTIONS
2870+
#endif
2871+
#ifdef BUILD_DEBUG
2872+
"\n DEBUG = " BUILD_DEBUG
2873+
#endif
2874+
"\n\n");
2875+
return 1;
2876+
}
28452877

28462878
setvbuf(stdout, NULL, _IONBF, 0);
28472879

0 commit comments

Comments
 (0)