Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20170705000303.6936aefe@inria.fr>
Date: Wed, 5 Jul 2017 00:03:03 +0200
From: Jens Gustedt <jens.gustedt@...ia.fr>
To: musl@...ts.openwall.com
Subject: Re: more on missing volatile qualifications

Hello Rich,

On Tue, 4 Jul 2017 17:19:09 -0400 Rich Felker <dalias@...c.org> wrote:

> On Sun, Jun 25, 2017 at 01:06:29PM +0200, Jens Gustedt wrote:
> > There is a reading of the C standard that says that volatile only
> > has implications if an object itself is such qualified, having a
> > volatile qualified lvalue access isn't enough. I don't think that
> > any current compiler does such weird things, but who knows where
> > optimisers will go in the future.  
> 
> Indeed. GCC seems committed to treating "accesses through volatile
> lvalue" as volatile, but I'd rather not depend on it. Perhaps we
> should add a primitive to atomic.h for loading the value of atomics so
> that we never access them directly; then volatile would not matter.

While I agree for the principle, identifying all these places and
replace them with a primitive might not be so easy.

Luckily most of these variables a called "lock" :)

I'll look into it and see what I can do. But I will probably not be
able to come up with sensible platform specific choices for an
"a_load" primitive and set it to "a_cas(p, 0, 0)" or so, to have a
start.

> > AFAICS for the third finding in sigaction.c this would not be an
> > issue. Since in addition this is something dealing with signal
> > stuff, I still think that volatile would be in order, here.  
> 
> The line:
> 
> 	memcpy(set, handler_set, sizeof handler_set);
> 
> is not valid if handler_set is made volatile;

Yes, so said the compiler, too.

> we'd have to write out
> the code to copy it. Not a big deal though, and more correct anyway;
> using memcpy to copy something that's semantically atomic is sloppy.

Ok, so let's do this properly.

> Unfortunately since I don't want to encode knowledge of the naming of
> sigset_t internals here, we'd probably need a loop to copy to a
> non-volatile array the same as handler_set, then memcpy from there to
> set.

Yes, unfortunately. To do that we'd also need an "a_load_l" primitive,
or we'd have to change handler_set to an array of unsigned, which is
far more intrusive.

Jens

-- 
:: INRIA Nancy Grand Est ::: Camus ::::::: ICube/ICPS :::
:: ::::::::::::::: office Strasbourg : +33 368854536   ::
:: :::::::::::::::::::::: gsm France : +33 651400183   ::
:: ::::::::::::::: gsm international : +49 15737185122 ::
:: http://icube-icps.unistra.fr/index.php/Jens_Gustedt ::

Content of type "application/pgp-signature" skipped

Powered by blists - more mailing lists

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.