| From: | Peter Eisentraut <peter(at)eisentraut(dot)org> |
|---|---|
| To: | pgsql-hackers <pgsql-hackers(at)postgresql(dot)org> |
| Subject: | Silence -fsanitize=function where we cast function pointers on purpose |
| Date: | 2026-09-29 05:47:22 |
| Message-ID: | 2db401d9-ef16-430e-a42c-34477006a49f@eisentraut.org |
| Views: | Whole Thread | Raw Message | Download mbox | Resend email |
| Thread: | |
| Lists: | pgsql-hackers |
In clang, -fsanitize=undefined includes -fsanitize=function, which
reports every call made through a function pointer whose type does not
exactly match the called function, so it fires all over the place on
expression tree walkers and mutators, as well as a few other places. So
-fsanitize=undefined hasn't been working cleanly under clang for a
while. (Before clang 17, it only applied to C++.)
This is the same issue that caused us to use
-Wno-cast-function-type-strict with clang. That warning applies at the
place where the mismatching function pointer is passed, so there are
potentially hundreds of sites. Therefore, a global disabling is
appropriate. The sanitizer, on the other hand, triggers where the
function is called, which are only about two dozen places, so it seems
possible to silence these checks individually and still main the check
for accidental violations elsewhere.
I propose to add pg_attribute_no_sanitize_function() and place it on the
functions that make such calls. This is similar to some existing
pg_attribute_no_sanitize_xxx attributes.
| Attachment | Content-Type | Size |
|---|---|---|
| 0001-Silence-fsanitize-function-where-we-cast-function-po.patch | text/plain | 10.5 KB |
| From | Date | Subject | |
|---|---|---|---|
| Next Message | Peter Eisentraut | 2026-09-29 05:50:15 | Re: Fix out-of-bounds array indexing in JsonValueList |
| Previous Message | Bertrand Drouvot | 2026-09-29 05:46:16 | Re: Add pg_stat_log_messages: cumulative statistics about server log messages (was: Add contrib module pg_stat_log: cumulative statistics about server log messages) |