diff --git a/Makefile b/Makefile index 3c596660..1b38350f 100644 --- a/Makefile +++ b/Makefile @@ -249,6 +249,7 @@ TESTS = $(BIN)/test_smoke $(BIN)/test_lex $(BIN)/test_parse $(BIN)/test_check \ $(BIN)/test_tagged_subset_reject \ $(BIN)/test_callarg_typecheck \ $(BIN)/test_catA_f2_reject \ + $(BIN)/test_intoverflow_reject \ $(BIN)/test_idxarg_run \ $(BIN)/test_chainidx_run \ $(BIN)/test_tupfieldsize_run \ @@ -685,6 +686,17 @@ $(BIN)/test_catA_f2_reject: test/wcc/989_catA_f2_reject.c \ $(LIB)/libwwrt.a | $(BIN) $(CC) $(CFLAGS) -o $@ $< +# 989_intoverflow_reject (F14 #53): an integer literal that overflows u64 +# must FAIL to build on BOTH driver twins (wwstage parseint dropped the C +# twin's overflow guard). Needs the full cstage + wwstage tool sets plus +# libwwrt for the control links. +$(BIN)/test_intoverflow_reject: test/wcc/989_intoverflow_reject.c \ + $(BIN)/ww $(BIN)/ww_ww \ + $(BIN)/w6c $(BIN)/w6a $(BIN)/w6l \ + $(BIN)/w6c_ww $(BIN)/w6a_ww $(BIN)/w6l_ww \ + $(LIB)/libwwrt.a | $(BIN) + $(CC) $(CFLAGS) -o $@ $< + # 989_idxarg_run (F7-c2, #45/#46): an indexed slice/str element passed as # a call arg must push its full multi-word header. Builds+runs each fixture # on BOTH the cstage `ww` and wwstage `ww_ww` drivers (rule-10), so it needs diff --git a/lib/ww/lex/lex.ww b/lib/ww/lex/lex.ww index 48dc59b5..f71dc29b 100644 --- a/lib/ww/lex/lex.ww +++ b/lib/ww/lex/lex.ww @@ -210,6 +210,7 @@ fn parseint(p: *u8, n: u64, base: i32, ok: *bool) u64 = { }; if (d < 0) { *ok = false; return 0u64; }; if (d >= base) { *ok = false; return 0u64; }; + if (v > ~0u64 / (base: u64)) { *ok = false; return 0u64; }; v = v * (base: u64) + (d: u64); got = true; i += 1u64; diff --git a/selfhost/cmd/w6c/main.combined.ww b/selfhost/cmd/w6c/main.combined.ww index 225db528..79da7177 100644 --- a/selfhost/cmd/w6c/main.combined.ww +++ b/selfhost/cmd/w6c/main.combined.ww @@ -6985,6 +6985,7 @@ fn parseint(p: *u8, n: u64, base: i32, ok: *bool) u64 = { }; if (d < 0) { *ok = false; return 0u64; }; if (d >= base) { *ok = false; return 0u64; }; + if (v > ~0u64 / (base: u64)) { *ok = false; return 0u64; }; v = v * (base: u64) + (d: u64); got = true; i += 1u64; diff --git a/selfhost/cmd/wwdump/main.combined.ww b/selfhost/cmd/wwdump/main.combined.ww index c0bd0a35..c9b3aeed 100644 --- a/selfhost/cmd/wwdump/main.combined.ww +++ b/selfhost/cmd/wwdump/main.combined.ww @@ -6985,6 +6985,7 @@ fn parseint(p: *u8, n: u64, base: i32, ok: *bool) u64 = { }; if (d < 0) { *ok = false; return 0u64; }; if (d >= base) { *ok = false; return 0u64; }; + if (v > ~0u64 / (base: u64)) { *ok = false; return 0u64; }; v = v * (base: u64) + (d: u64); got = true; i += 1u64; diff --git a/test/wcc/989_intoverflow_reject.c b/test/wcc/989_intoverflow_reject.c new file mode 100644 index 00000000..b6d724ed --- /dev/null +++ b/test/wcc/989_intoverflow_reject.c @@ -0,0 +1,215 @@ +/* + * 989_intoverflow_reject — F14 #53: wwstage parseint dropped the u64 + * overflow guard the C twin carries (cmd/wcc/lex.c:156 + * `if (v > (u64)~0ULL / (u64)base)`), so any integer literal that + * overflows u64 was silently accepted mod 2^64 by wwstage while cstage + * loudly rejected with "bad integer literal". The fix ports the + * pre-multiply guard into lib/ww/lex/lex.ww parseint, aligning wwstage + * UP to cstage. + * + * Each REJECT row is a literal that exceeds u64 and must FAIL to build + * on BOTH driver twins; each control fits in u64 and must build+run. + * Edge rows: U64_MAX decimal and hex (the largest accepted), a 65-bit + * hex (smallest-bit overflow), a 21-digit decimal, and a 2^128-1 + * decimal. The exact-2^64 boundary family is NOT a row here: cstage's + * own cheap-check leaks it (report-item #54, a separate both-stages + * item), so both stages accept it identically — outside #53's scope. + * + * Rule-10: every row runs on cstage `ww` and wwstage `ww_ww`; both must + * agree. wwstage rows are gated on out/bin/ww_ww. + */ +#include +#include +#include +#include +#include +#include + +static int +runwait(const char *cmd) +{ + int rc = system(cmd); + if (rc == -1) return -1; + if (WIFEXITED(rc)) return WEXITSTATUS(rc); + return -1; +} + +struct row { + const char *label; + const char *src; + int expect_build; /* 1 = build+run to want_exit; 0 = must FAIL */ + int want_exit; +}; + +static const struct row rows[] = { + /* REJECT — 21-digit decimal, well over u64. */ + { "dec_overflow", + "package main;\n" + "export fn main() i32 = {\n" + " let x: u64 = 99999999999999999999u64;\n" + " return x: i32;\n" + "};\n", + 0, 0 }, + + /* REJECT — 65-bit hex (smallest overflow above U64_MAX). */ + { "hex_overflow", + "package main;\n" + "export fn main() i32 = {\n" + " let x: u64 = 0x1ffffffffffffffffu64;\n" + " return x: i32;\n" + "};\n", + 0, 0 }, + + /* REJECT — 2^128-1 decimal, far over u64. */ + { "dec_huge", + "package main;\n" + "export fn main() i32 = {\n" + " let x: u64 = 340282366920938463463374607431768211455u64;\n" + " return x: i32;\n" + "};\n", + 0, 0 }, + + /* control — U64_MAX decimal is the largest accepted literal. */ + { "u64max_dec_ok", + "package main;\n" + "export fn main() i32 = {\n" + " let x: u64 = 18446744073709551615u64;\n" + " if (x == 18446744073709551615u64) { return 7; };\n" + " return 0;\n" + "};\n", + 1, 7 }, + + /* control — U64_MAX hex, same value via the base-16 path. */ + { "u64max_hex_ok", + "package main;\n" + "export fn main() i32 = {\n" + " let x: u64 = 0xffffffffffffffffu64;\n" + " if (x == 18446744073709551615u64) { return 9; };\n" + " return 0;\n" + "};\n", + 1, 9 }, +}; + +static int +run_build(const char *driver, const struct row *r, int i) +{ + char src[64], tmpdir[64], cmd[1024]; + snprintf(src, sizeof src, "/tmp/iov_%d_%d.ww", getpid(), i); + snprintf(tmpdir, sizeof tmpdir, "/tmp/iov_%d_d_%d", getpid(), i); + + FILE *f = fopen(src, "wb"); + if (!f) return -2; + fputs(r->src, f); + fclose(f); + + mkdir(tmpdir, 0755); + snprintf(cmd, sizeof cmd, "cd %s && %s build %s 2>/dev/null", + tmpdir, driver, src); + int brc = runwait(cmd); + + const char *base = strrchr(src, '/'); + base = base ? base + 1 : src; + char outbin[128]; + snprintf(outbin, sizeof outbin, "%s/%s", tmpdir, base); + char *dot = strrchr(outbin, '.'); + if (dot && strcmp(dot, ".ww") == 0) *dot = '\0'; + + int got = -1; + if (brc == 0) got = runwait(outbin); + + unlink(src); unlink(outbin); rmdir(tmpdir); + return brc == 0 ? got : -1; +} + +static int +build_should_fail(const char *driver, const char *src, int i) +{ + char s[64], tmpdir[64], cmd[1024]; + snprintf(s, sizeof s, "/tmp/iovn_%d_%d.ww", getpid(), i); + snprintf(tmpdir, sizeof tmpdir, "/tmp/iovn_%d_d_%d", getpid(), i); + + FILE *f = fopen(s, "wb"); + if (!f) return -1; + fputs(src, f); + fclose(f); + + mkdir(tmpdir, 0755); + snprintf(cmd, sizeof cmd, "cd %s && %s build %s 2>/dev/null", + tmpdir, driver, s); + int rc = runwait(cmd); + + unlink(s); + const char *base = strrchr(s, '/'); + base = base ? base + 1 : s; + char outbin[128]; + snprintf(outbin, sizeof outbin, "%s/%s", tmpdir, base); + char *dot = strrchr(outbin, '.'); + if (dot && strcmp(dot, ".ww") == 0) *dot = '\0'; + unlink(outbin); + rmdir(tmpdir); + return rc == 0 ? -1 : 0; /* build must NOT succeed */ +} + +int +main(void) +{ + const char *bin = getenv("BIN"); + if (!bin) bin = "out/bin"; + char absbin[1024]; + if (bin[0] != '/') { + char cwd[1024]; + if (getcwd(cwd, sizeof cwd) == NULL) return 1; + snprintf(absbin, sizeof absbin, "%s/%s", cwd, bin); + bin = absbin; + } + + char cdrv[1024], wdrv[1024]; + snprintf(cdrv, sizeof cdrv, "%s/ww", bin); + snprintf(wdrv, sizeof wdrv, "%s/ww_ww", bin); + + struct { const char *name; const char *drv; int gated; } + drivers[] = { + { "cstage", cdrv, 0 }, + { "wwstage", wdrv, 1 }, + { NULL, NULL, 0 }, + }; + + int n = (int)(sizeof rows / sizeof rows[0]); + int total = 0, fail = 0; + + for (int d = 0; drivers[d].name; d++) { + if (drivers[d].gated && access(drivers[d].drv, X_OK) != 0) { + fprintf(stderr, "intoverflow_reject: skip %s (no %s)\n", + drivers[d].name, drivers[d].drv); + continue; + } + for (int i = 0; i < n; i++) { + total++; + if (rows[i].expect_build) { + int got = run_build(drivers[d].drv, &rows[i], i); + if (got != rows[i].want_exit) { + fprintf(stderr, "intoverflow_reject[%s][%s]: " + "exit=%d want=%d\n", drivers[d].name, + rows[i].label, got, rows[i].want_exit); + fail++; + } + } else { + if (build_should_fail(drivers[d].drv, rows[i].src, + 100 + i) != 0) { + fprintf(stderr, "intoverflow_reject[%s][%s]: " + "built ok, expected a loud reject\n", + drivers[d].name, rows[i].label); + fail++; + } + } + } + } + + if (fail) { + fprintf(stderr, "intoverflow_reject: %d/%d fixtures failed\n", + fail, total); + return 1; + } + printf("intoverflow_reject: %d/%d ok\n", total, total); + return 0; +}