Skip to content

Close out #33: reduce_one() sanitizer crash, UBSan function-type reports, R-hub workflow - #34

Merged
mattfidler merged 2 commits into
mainfrom
issue-33
Oct 5, 2026
Merged

mattfidler merged 2 commits into
mainfrom
issue-33

Conversation

@mattfidler

Copy link
Copy Markdown
Member

Closes #33.

Is #33 fixed?

Yes, by #32 (the first reduction path moved off a process-wide static onto reduce_one()'s stack). Verified locally with clang ASan+UBSan:

1.3.1-13 (CRAN) 1.3.1-14 (dev)
concurrent dparse() test, 16 threads parse.c:1397:57 … 0xbebebebebebebebe then SEGV (the issue's signature) clean
rxode2 5.1.8 parallel CSE (.rxOptExprC, 1–8 threads) same crash clean

Only clang builds ever used the shared vector. In vec_add(paths, new_VecZNode(paths, ...)) the n++ and the call were unsequenced, and gcc took a fresh malloc()ed path. That is why only R-hub's clang containers crashed.

Changes

  • src/parse.c: build_paths() calls new_VecZNode() before vec_add(), so every compiler takes the same path. With only this change applied to the old static-path1 code, the existing concurrent test now crashes it under gcc too.
  • src/lex.c, src/write_tables.c: the hash/cmp callbacks take void * to match hash_fn_t/cmp_fn_t exactly. Clang's -fsanitize=function reported "call to function through pointer to incorrect function type" from mkdparse(), which would fail R-hub's UBSan step.
  • .github/workflows/rhub.yaml (new, based on the r-hub v1 template):
    • sets NOT_CRAN=true so the concurrent test runs (it skips on CRAN);
    • after the check, installs this checkout's dparser plus nlmixr2/rxode2 and runs .github/rhub/rxode2-parallel-cse.R, failing on any sanitizer report;
    • the extra step can be turned off with the downstream input.
  • NEWS.md entries.

Testing

  • Full test suite under gcc ASan/UBSan and clang ASan/UBSan: 690 expectations, 0 failures, no sanitizer reports.
  • The workflow can only be dispatched once it is on main; after merging, run rhub::rhub_check(platforms = c("clang-asan", "clang-ubsan")).

… workflow

The reduce_one() crash R-hub's clang-asan/clang-ubsan checks hit in
babelmixr2 (#33) is the shared first-path race fixed in #32; reproduced on
1.3.1-13 and clean on 1.3.1-14 under clang ASan/UBSan, both with the
concurrent test and with rxode2's parallel CSE.

- build_paths(): call new_VecZNode() before vec_add(); the n++ and the call
  were unsequenced, so gcc never used path1 and the concurrent test could
  only catch the race on clang.
- lex.c/write_tables.c: hash/cmp callbacks take void* to match
  hash_fn_t/cmp_fn_t, silencing clang -fsanitize=function in mkdparse().
- .github/workflows/rhub.yaml: R-hub workflow with NOT_CRAN=true and a
  downstream rxode2 parallel CSE smoke test (.github/rhub/).
Clears the 4 CodeFactor undesirable-operator issues on #34.
@mattfidler
mattfidler merged commit 91cf41b into main Oct 5, 2026
9 checks passed
@mattfidler
mattfidler deleted the issue-33 branch October 5, 2026 17:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

AddressSanitizer global-buffer-overflow / UBSan SEGV in reduce_one (parse.c:1396-1397) under rxode2's parallel CSE

1 participant