git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH 0/3] Fix uninitialised reads found with MSAN

From
Jeff King <peff@peff.net>
Date
Jun 11, 2021, 17:11 UTC
Message-ID
<YMOZNyzWZbDvtFkD@coredump.intra.peff.net>
In-Reply-To
<pull.1033.git.git.1623343712.gitgitgadget@gmail.com>
On Thu, Jun 10, 2021 at 04:48:29PM +0000, Andrzej Hunt via GitGitGadget wrote:
Show 13 quoted lines
> As to the tricky part: MSAN tries to detect reads from uninitialised memory
> at runtime. However you need to ensure that all code performing
> initialisation is built with the right instrumentation (i.e.
> -fsanitize=memory). So you'll immediately run into issues if you link
> against libraries provided by your system (with the exception of libc, as
> MSAN provides some default interceptors for most of libc). In theory you
> should rebuild all dependencies with -fsanitize=memory, although I
> discovered that it's sufficient to recompile only zlib + link git against
> that copy of zlib (which not a very tricky thing to do). Doing this will
> uncover one intentional read from uninitialised memory inside zlib itself.
> This can be worked around with an annotation in zlib (which I'm trying to
> submit upstream at [1]) - but it's also possible to define an override list
> at compile time - I've detailed this in my recipe below).

I played with MSAN a while ago, and yeah, the trickiest part is dealing with libraries. I came up with this patch for handling zlib from within Git itself:

  https://lore.kernel.org/git/20171004101932.pai6wzcv2eohsicr@sigill.intra.peff.net/

It's entirely possible that it papers over actual bugs (perhaps even the one your first patch is addressing). But I wonder if it's easier to convince people to try the tool if there's an easy way to do it without recompiling dependencies (I also hit issues with pcre and the libc regex; that was a few years ago, though, so I would not be at all surprised if they know intercept the system regex routines, at least).

-Peff
Previous: Andrzej Hunt via GitGitGadgetNext: Andrzej Hunt via GitGitGadget
Message 9 of 15 in “Fix uninitialised reads found with MSAN”
  1. 0/3 Fix uninitialised reads found with MSANAndrzej Hunt via GitGitGadget, Jun 10, 2021
  2. 2/3 split-index: use oideq instead of memcmp to compare object_id'sAndrzej Hunt via GitGitGadget, Jun 10, 2021
  3. 3/3 builtin/checkout--worker: memset struct to avoid MSAN complaintsAndrzej Hunt via GitGitGadget, Jun 10, 2021
  4. Chris TorekJun 11, 2021
  5. Junio C HamanoJun 11, 2021
  6. Andrzej HuntJun 11, 2021
  7. Junio C HamanoJun 14, 2021
  8. 1/3 bulk-checkin: make buffer reuse more obvious and saferAndrzej Hunt via GitGitGadget, Jun 10, 2021
  9. Jeff KingJun 11, 2021
  10. 0/3 Fix uninitialised reads found with MSANAndrzej Hunt via GitGitGadget, Jun 14, 2021
  11. 1/3 bulk-checkin: make buffer reuse more obvious and saferAndrzej Hunt via GitGitGadget, Jun 14, 2021
  12. 2/3 split-index: use oideq instead of memcmp to compare object_id'sAndrzej Hunt via GitGitGadget, Jun 14, 2021
  13. 3/3 builtin/checkout--worker: zero-initialise struct to avoid MSAN complaintsAndrzej Hunt via GitGitGadget, Jun 14, 2021
  14. Philip OakleyJun 17, 2021
  15. Andrzej HuntJun 20, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.