Commit 83b0fc30 authored by Paul Eggert's avatar Paul Eggert
Browse files

Minor tweaks to recent UBSan-related fix

* src/alloc.c: No need to include stdalign.h; it’s pervasive.
(GC_STRING_OVERRUN_COOKIE_SIZE): Align to sdata’s alignment,
so that the code works even if alignof (sdata) exceeds 8.
Don’t require the cookie size to be 8, as this overly fattens
32-bit platforms and one DEADBEEF should be enough.
(GC_STRING_EXTRA): Omit now-unnecessary ‘verify’.
(allocate_string_data): Omit unnecessary cast.
parent 69947311
Pipeline #1462 failed with stage
in 70 minutes and 42 seconds
......@@ -21,7 +21,6 @@ along with GNU Emacs. If not, see <>. */
#include <config.h>
#include <errno.h>
#include <stdalign.h>
#include <stdint.h>
#include <stdio.h>
#include <stdlib.h>
......@@ -1576,16 +1575,15 @@ static struct Lisp_String *string_free_list;
/* We check for overrun in string data blocks by appending a small
/* Check for overrun in string data blocks by appending a small
"cookie" after each allocated string data block, and check for the
presence of this cookie during GC. */
# define GC_STRING_OVERRUN_COOKIE_SIZE ROUNDUP (4, alignof (sdata))
static char const string_overrun_cookie[GC_STRING_OVERRUN_COOKIE_SIZE] =
{ '\xde', '\xad', '\xbe', '\xef', '\xde', '\xad', '\xbe', '\xef' };
{ '\xde', '\xad', '\xbe', '\xef', /* Perhaps some zeros here. */ };
/* Value is the size of an sdata structure large enough to hold NBYTES
......@@ -1615,13 +1613,7 @@ static char const string_overrun_cookie[GC_STRING_OVERRUN_COOKIE_SIZE] =
#endif /* not GC_CHECK_STRING_BYTES */
/* Extra bytes to allocate for each string. */
/* Make sure that allocating the extra bytes doesn't misalign
`sdata'. */
verify (GC_STRING_EXTRA % alignof (sdata) == 0);
/* Exact bound on the number of bytes in a string, not counting the
terminating NUL. A string cannot contain more bytes than
......@@ -1882,7 +1874,7 @@ allocate_string_data (struct Lisp_String *s,
data->string = s;
b->next_free = (sdata *) ((char *) data + needed + GC_STRING_EXTRA);
eassert ((uintptr_t) (char *) b->next_free % alignof (sdata) == 0);
eassert ((uintptr_t) b->next_free % alignof (sdata) == 0);
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment