Skip to content

Add a CI job that builds and tests under UBSan - #89

Merged
d-torrance merged 1 commit into
Macaulay2:masterfrom
d-torrance:ubsan-ci
Sep 19, 2026
Merged

d-torrance merged 1 commit into
Macaulay2:masterfrom
d-torrance:ubsan-ci

Conversation

@d-torrance

Copy link
Copy Markdown
Member

Four of the five commits before the post-1.4 review were undefined behaviour
findings, every one found by hand. This adds the job that finds the next one
without anybody looking.

One job, not a seventeenth matrix cell — Ubuntu, autotools, --enable-debug,
and make check under -fsanitize=undefined.

The flag that matters

-fno-sanitize-recover=all. Without it the sanitizer prints a diagnostic and
the process still exits 0, so the job would pass while reporting undefined
behaviour
. With it, the first report kills the run and fails the PR.

Why alignment is excluded

Because of the packaged dependencies, and nothing else.

mathic's KDEntryArray places entries that want 8-byte alignment on 4-byte
boundaries in memtailor Arena memory. That is 325 reports across 113
distinct sites
— and every one of them is that single cause:

117  reference binding to misaligned address
 98  member access within misaligned address
 73  member call on misaligned address
 25  load of misaligned address
 12  constructor call on misaligned address

Not one integer overflow, shift, null dereference, bounds or vptr error in the
whole run. It is already fixed in mathic's git, but not in
libmathic-dev 1.0~git20230916-1, which is what this job installs.

The job's comment records when to remove the exclusion: once the package
catches up. Our own sites share the root cause and should go with it, so they
want re-checking at the same time.

So what does it gate?

Nothing today — it is green, because alignment is the only class this codebase
currently has. What it buys is that from now on, any new integer overflow,
bad shift, null dereference, out-of-bounds access or vptr error on a path the
suite reaches fails the PR that introduces it.

Verification

Run locally against the same environment the job runs in — Ubuntu 24.04,
GCC 13.3, libmathic-dev and libmemtailor-dev 1.0~git20230916-1:

result
with the job's flags 253/253, 0 reports, exit 0 (49.8 s)
same flags, alignment re-enabled 325 reports, 113 sites

The second row is the important one. It reproduces the review's 2026-09-01
measurement exactly, breakdown included, which is how we know the job is green
because the exclusion is doing its work — not because the sanitizer is inert.

Also checked: YAML parses, bash -n clean on the run script, the quoted
CXXFLAGS continuation expands to a single argument (verified with set -x),
and no tabs or trailing whitespace, so the existing editorconfig-checker job
stays happy.

Two small notes

VERBOSE: 1 is set because automake prints only a summary on failure; it makes
the harness cat the test log, which is where the sanitizer's diagnostics and
stack traces live.

--enable-debug contributes only -DMATHICGB_DEBUG, so passing CXXFLAGS
overrides configure's default -g -O2 and the job builds at -O0. Slower, but
better stack traces, which is the right trade here.

🤖 Generated with Claude Code

Four of the five commits before the post-1.4 review were undefined
behaviour findings, every one of them found by hand. This is the job
that finds the next one without anybody looking.

Ubuntu, autotools, --enable-debug so assertions are compiled in.
-fno-sanitize-recover=all is the flag that matters: without it the
sanitizer prints a diagnostic and the run still exits 0, so the job
would pass while reporting undefined behaviour.

Alignment is excluded, and only because of the packaged dependencies.
mathic's KDEntryArray places entries wanting 8-byte alignment on 4-byte
boundaries in memtailor Arena memory, which is 325 reports across 113
sites -- every one of them that single cause, none of them any other
class of undefined behaviour. It is already fixed in mathic's git but
not in libmathic-dev 1.0~git20230916-1, which is what CI installs. The
comment in the job says to drop -fno-sanitize=alignment once the package
catches up, and to re-check our own sites then, since they share the
cause and should go with it.

So the job gates every other class from day one: integer overflow, bad
shifts, null dereferences, out-of-bounds, vptr errors. It gates nothing
today, because there is nothing else to find.

VERBOSE=1 because automake prints only a summary on failure; it makes
the harness cat the test log, which is where the diagnostics and stack
traces are. --enable-debug adds only -DMATHICGB_DEBUG, so passing
CXXFLAGS drops configure's default -g -O2 and builds at -O0, which is
slower but gives better traces -- the right trade for this job.

Verified locally against the same environment the job runs in: Ubuntu
24.04, GCC 13.3, libmathic-dev and libmemtailor-dev 1.0~git20230916-1.

    with the job's flags        253/253, 0 reports, exit 0
    alignment re-enabled        325 reports, 113 distinct sites

The second line is the point. It reproduces the review's 2026-09-01
measurement exactly, breakdown included -- 117 reference binding, 98
member access, 73 member call, 25 load, 12 constructor call -- which is
how we know the job is green because the exclusion is doing its work
rather than because the sanitizer is inert.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@d-torrance
d-torrance merged commit 35112b1 into Macaulay2:master Sep 19, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant