Add a CI job that builds and tests under UBSan - #89
Merged
Merged
Conversation
Four of the five commits before the post-1.4 review were undefined
behaviour findings, every one of them found by hand. This is the job
that finds the next one without anybody looking.
Ubuntu, autotools, --enable-debug so assertions are compiled in.
-fno-sanitize-recover=all is the flag that matters: without it the
sanitizer prints a diagnostic and the run still exits 0, so the job
would pass while reporting undefined behaviour.
Alignment is excluded, and only because of the packaged dependencies.
mathic's KDEntryArray places entries wanting 8-byte alignment on 4-byte
boundaries in memtailor Arena memory, which is 325 reports across 113
sites -- every one of them that single cause, none of them any other
class of undefined behaviour. It is already fixed in mathic's git but
not in libmathic-dev 1.0~git20230916-1, which is what CI installs. The
comment in the job says to drop -fno-sanitize=alignment once the package
catches up, and to re-check our own sites then, since they share the
cause and should go with it.
So the job gates every other class from day one: integer overflow, bad
shifts, null dereferences, out-of-bounds, vptr errors. It gates nothing
today, because there is nothing else to find.
VERBOSE=1 because automake prints only a summary on failure; it makes
the harness cat the test log, which is where the diagnostics and stack
traces are. --enable-debug adds only -DMATHICGB_DEBUG, so passing
CXXFLAGS drops configure's default -g -O2 and builds at -O0, which is
slower but gives better traces -- the right trade for this job.
Verified locally against the same environment the job runs in: Ubuntu
24.04, GCC 13.3, libmathic-dev and libmemtailor-dev 1.0~git20230916-1.
with the job's flags 253/253, 0 reports, exit 0
alignment re-enabled 325 reports, 113 distinct sites
The second line is the point. It reproduces the review's 2026-09-01
measurement exactly, breakdown included -- 117 reference binding, 98
member access, 73 member call, 25 load, 12 constructor call -- which is
how we know the job is green because the exclusion is doing its work
rather than because the sanitizer is inert.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Four of the five commits before the post-1.4 review were undefined behaviour
findings, every one found by hand. This adds the job that finds the next one
without anybody looking.
One job, not a seventeenth matrix cell — Ubuntu, autotools,
--enable-debug,and
make checkunder-fsanitize=undefined.The flag that matters
-fno-sanitize-recover=all. Without it the sanitizer prints a diagnostic andthe process still exits 0, so the job would pass while reporting undefined
behaviour. With it, the first report kills the run and fails the PR.
Why alignment is excluded
Because of the packaged dependencies, and nothing else.
mathic's
KDEntryArrayplaces entries that want 8-byte alignment on 4-byteboundaries in memtailor
Arenamemory. That is 325 reports across 113distinct sites — and every one of them is that single cause:
Not one integer overflow, shift, null dereference, bounds or vptr error in the
whole run. It is already fixed in mathic's git, but not in
libmathic-dev 1.0~git20230916-1, which is what this job installs.The job's comment records when to remove the exclusion: once the package
catches up. Our own sites share the root cause and should go with it, so they
want re-checking at the same time.
So what does it gate?
Nothing today — it is green, because alignment is the only class this codebase
currently has. What it buys is that from now on, any new integer overflow,
bad shift, null dereference, out-of-bounds access or vptr error on a path the
suite reaches fails the PR that introduces it.
Verification
Run locally against the same environment the job runs in — Ubuntu 24.04,
GCC 13.3,
libmathic-devandlibmemtailor-dev1.0~git20230916-1:The second row is the important one. It reproduces the review's 2026-09-01
measurement exactly, breakdown included, which is how we know the job is green
because the exclusion is doing its work — not because the sanitizer is inert.
Also checked: YAML parses,
bash -nclean on the run script, the quotedCXXFLAGScontinuation expands to a single argument (verified withset -x),and no tabs or trailing whitespace, so the existing
editorconfig-checkerjobstays happy.
Two small notes
VERBOSE: 1is set because automake prints only a summary on failure; it makesthe harness
catthe test log, which is where the sanitizer's diagnostics andstack traces live.
--enable-debugcontributes only-DMATHICGB_DEBUG, so passingCXXFLAGSoverrides configure's default
-g -O2and the job builds at-O0. Slower, butbetter stack traces, which is the right trade here.
🤖 Generated with Claude Code