4 ms·
One case in which I couldn't get UBSan (nor MemSan) to report issues was with the usage of unitialized values, which may constitute undefined behavior. UBSan d
by dhekir 9y ago
One case in which I couldn't get UBSan (nor MemSan) to report issues was with the usage of unitialized values, which may constitute undefined behavior.
UBSan does not deal with uninitialized reads, but Memory Sanitizer does ("MemorySanitizer is a detector of uninitialized reads"). However, unless it changed, it only detects them when they are used in conditional branches. So in the following code, for instance, I couldn't get UBSan/MemSan to tell me the printf will read some uninitialized value.
#include <stdio.h>
int main() {
int uninit;
printf("%d", uninit);
return 0;
}
tis-interpreter (and Frama-C/EVA, which is related) will report the uninitialized read.
Note that both tools are very different in nature and usage, since tis-interpreter is a sound static analyzer (for all entry values), while UBSan is a runtime monitoring tool (Frama-C also has E-ACSL, its own runtime monitoring tool). The former provides stronger guarantees, especially when the set of inputs can be large, while the latter will surely be more efficient when doing bug detection work, since there won't be any false positives.
Overall, I'd say, use UBSan/MemSan/etc. for the majority of the code, and focus on sound analysis for critical components or libraries, where mistakes can be expensive.
- krasin 9y agoThis (printf of an undefined value) is a good example. Thank you! Most of the time, MemorySanitizer is used with instrumented libc++ and sometimes even libc, which allows to catch most of the cases (including printf), as the data ends up in conditional branches. Still, your point is very valid.
- MaxBarraclough 9y ago> tis-interpreter is a sound static analyzer (for all entry values), while UBSan is a runtime monitoring tool Isn't it a dynamic analysis tool, i.e. a C interpreter that keeps an eye out for UB? From the GitHub README.md: > tis-interpreter works by interpreting C programs statement by statement from beginning to end, verifying at each statement whether the program can invoke undefined behavior. This makes it comparable to Valgrind and C compiler sanitizers (UBSan, ASan, …)
- dhekir 9y ago> Isn't it a dynamic analysis tool, i.e. a C interpreter that keeps an eye out for UB? Indeed, I'm sorry, I had tis-analyzer in mind. tis-interpreter is indeed closer to Valgrind. It interprets the C code according to its semantics, without going down to assembly level nor executing the code.