zeromem: Do not call memset when there is nothing to zero - #1750
Open
yumasansansan wants to merge 1 commit into
Open
yumasansansan wants to merge 1 commit into
yumasansansan wants to merge 1 commit into
Conversation
zeromem() passes what it is given straight to memset(), whose declaration forbids a null pointer however many bytes it is asked to fill -- nought included. A buffer of no samples holds no address, so clearing one is a call that UndefinedBehaviorSanitizer stops the program at: modules/juce_core/memory/juce_Memory.h:40:79: runtime error: null pointer passed as argument 1, which is declared to never be null AudioBuffer::clear() is one way there: AudioProcessor::processBlockBypassed() clears the channels it has no input for, and a host that asks a plug-in for no samples at all may hand over a buffer whose channels are nowhere. Nothing is written either way, so only the call goes away. This is the shape of the fix for MemoryBlock::matches(), where memcmp() was given the null pointer of an empty block. A fuzz target of ADLplug-Next found it, one that gives the plug-in the blocks a host asks for, of the sizes and the channel counts a host chooses.
This was referenced Sep 20, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
zeromem()passes what it is given straight tomemset(), whose declaration forbids a null pointer however many bytes it is asked to fill -- nought included. A buffer of no samples holds no address, so clearing one is a call that UndefinedBehaviorSanitizer stops the program at:AudioBuffer::clear()is one way there.AudioProcessor::processBlockBypassed()clears the channels the plug-in has no input for, and a host that asks a plug-in for no samples at all may hand over a buffer whose channels are nowhere;FloatVectorOperations::clear()then reacheszeromem()with that pointer and no bytes. Nothing is written either way, so only the call goes away.This is the shape of #1749's second commit, where
MemoryBlock::matches()was given the null pointer of an empty block formemcmp().A fuzz target of ADLplug-Next found it: it gives an
AudioProcessorthe blocks a host asks for, of the sizes and the channel counts a host chooses, including none of either.It is in 9.0.2 and in
developas it stands, and it is independent of the commits of ours that are already open.