Skip to content

Macro census and every-definition self-sized destinations - #187

Merged
prabhu merged 1 commit into
feat/memsafe-part1from
feat/memsafe-part13
Sep 28, 2026
Merged

prabhu merged 1 commit into
feat/memsafe-part1from
feat/memsafe-part13

Conversation

@prabhu

@prabhu prabhu commented Sep 27, 2026

Copy link
Copy Markdown
Contributor

Consolidates feat/memsafe-part13-selfsized and feat/macro-census, with fixes from an adversarial review of both.

MS-BOUND-002 self-sized destinations. The rule now stays silent only when every value the destination can hold is safe: an allocation sized from the copy length, or a fixed array that an enclosing if bounds by its own sizeof. The check also:

  • follows only plain, non-static locals, matched by declaration so a shadowing inner variable doesn't count;
  • treats a pointer as unknown if its address is taken or a reference is bound to it, and stops at +=, ++ and similar;
  • requires the length in a guard like need = n + 8 to be unsigned and summed in a wider type, so it can't wrap;
  • requires copies at an offset to have that offset as an addend of the size;
  • excludes strndup, strncat, and calloc with a variable count;
  • recovers provable FFmpeg shapes: packet copies after the header, append after av_grow_packet, and *len -= k in-place strips.

Macro census. Opt-in --macro-census <file> and --auto-defines find build-config macros that hide #if code, and define the ones with strong evidence (template-declared switches, CONFIG_*/ENABLE_*). Compared with the earlier branch, it:

  • understands string literals, C23 #elifdef, and comments inside directives;
  • counts lines the way the parser would see them, including nested blocks and include guards;
  • treats a name as defined only if a header the tree actually includes defines it;
  • never overrides a name set in --macro-files or --include-files, and skips its own report;
  • skips unreadable directories and applies the usual file excludes.

A bare --define X now means X=1, as with gcc. The AST cache key now includes the contents of macro and include files.

Results:

  • chen: full test suite passes.
  • Corpus: unchanged (medium 62.77%/98.33%, low 75.53%/95.95%, 0 negative controls).
  • FFmpeg CVE set: 5/13 medium and 7/13 low; 6/13 and 8/13 with --auto-defines. No fixed-tree hits.
  • abseil: identical sites.
  • New false positives: one on leveldb (dbformat.cc:129, needs a helper-return summary) and one per FFmpeg tree (rtpdec_h264.c:282, needs correlated conditions).

Known limits:

  • Field lengths are never treated as untrusted by BOUND-002.
  • Pointer values in loops aren't path-sensitive.
  • GuardPass.holdsAt gets the condition backwards after an if whose else exits. The guard check here avoids it by requiring the assignment inside the if.

…destination to be sized, and resolve header members, constants and qualified class names
@prabhu
prabhu force-pushed the feat/memsafe-part13 branch from a167a78 to a06ab01 Compare September 28, 2026 02:49
@prabhu
prabhu merged commit a06ab01 into feat/memsafe-part1 Sep 28, 2026
@prabhu
prabhu deleted the feat/memsafe-part13 branch September 28, 2026 02:49
@prabhu prabhu added the ai-auto label Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant