Skip to content

Commit 0bbb936

Browse files
ldionnetru
authored andcommitted
[libc++] Fix broken precondition of __bit_log2 (#155476)
In #135303, we started using `__bit_log2` instead of `__log2i` inside `std::sort`. However, `__bit_log2` has a precondition that `__log2i` didn't have, which is that the input is non-zero. While it technically makes no sense to request the logarithm of 0, `__log2i` handled that case and returned 0 without issues. After switching to `__bit_log2`, passing 0 as an input results in an unsigned integer overflow which can trigger `-fsanitize=unsigned-integer-overflow`. While not technically UB in itself, it's clearly not intended either. To fix this, we add an internal assertion to `__bit_log2` which catches the issue in our test suite, and we make sure not to violate `__bit_log2`'s preconditions before we call it from `std::sort`. (cherry picked from commit 2ae4b92)
1 parent 677a8a2 commit 0bbb936

File tree

3 files changed

+8
-0
lines changed

3 files changed

+8
-0
lines changed

libcxx/include/__algorithm/sort.h

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -860,6 +860,9 @@ __sort<__less<long double>&, long double*>(long double*, long double*, __less<lo
860860
template <class _AlgPolicy, class _RandomAccessIterator, class _Comp>
861861
_LIBCPP_HIDE_FROM_ABI _LIBCPP_CONSTEXPR_SINCE_CXX20 void
862862
__sort_dispatch(_RandomAccessIterator __first, _RandomAccessIterator __last, _Comp& __comp) {
863+
if (__first == __last) // log(0) is undefined, so don't try computing the depth
864+
return;
865+
863866
typedef typename iterator_traits<_RandomAccessIterator>::difference_type difference_type;
864867
difference_type __depth_limit = 2 * std::__bit_log2(std::__to_unsigned_like(__last - __first));
865868

libcxx/include/__bit/bit_log2.h

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,7 @@
99
#ifndef _LIBCPP___BIT_BIT_LOG2_H
1010
#define _LIBCPP___BIT_BIT_LOG2_H
1111

12+
#include <__assert>
1213
#include <__bit/countl.h>
1314
#include <__config>
1415
#include <__type_traits/integer_traits.h>
@@ -23,6 +24,7 @@ _LIBCPP_BEGIN_NAMESPACE_STD
2324
template <class _Tp>
2425
_LIBCPP_HIDE_FROM_ABI _LIBCPP_CONSTEXPR_SINCE_CXX14 _Tp __bit_log2(_Tp __t) _NOEXCEPT {
2526
static_assert(__is_unsigned_integer_v<_Tp>, "__bit_log2 requires an unsigned integer type");
27+
_LIBCPP_ASSERT_INTERNAL(__t != 0, "logarithm of 0 is undefined");
2628
return numeric_limits<_Tp>::digits - 1 - std::__countl_zero(__t);
2729
}
2830

libcxx/src/algorithm.cpp

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,9 @@ _LIBCPP_BEGIN_NAMESPACE_STD
1313

1414
template <class Comp, class RandomAccessIterator>
1515
void __sort(RandomAccessIterator first, RandomAccessIterator last, Comp comp) {
16+
if (first == last) // log(0) is undefined, so don't try computing the depth
17+
return;
18+
1619
auto depth_limit = 2 * std::__bit_log2(static_cast<size_t>(last - first));
1720

1821
// Only use bitset partitioning for arithmetic types. We should also check

0 commit comments

Comments
 (0)