IsoAlloc: Detecting Uninitialized Reads with Userfaultfd
struct.github.io
struct.github.io
For example highly vectorized loops that process a big buffer of data, but might read a bit out of bounds at the start or end of the buffer. The algorithm as a whole is guaranteed not to depend on the outcomes of those out of bounds reads, so as long as they can be guaranteed not to segfault, they should be safe.
Not allowing this usually results in either slower code (can't vectorize as much) or bigger code (need to have a special case codepath for the first/last items to be processed). The bigger code is often slower too due to worse branch prediction, more cache pressure, etc.
> need to have a special case codepath for the first/last items to be processed
Suppose you want to allocate 24 bytes and process them using SIMD instructions.
You call `aligned_alloc(24, 16)` to get a 24 byte allocation allocated to a 16 byte boundary.
Since the OS doesn't give the allocator 24 bytes, but whole memory pages, _it is valid_ for your program to read 32 bytes starting at the pointer returned, since that will never read out of the memory page in which this allocation resides.
This means that you can actually read the 24 bytes using 1 AVX instruction to read 32 bytes at once into a SIMD register, and do stuff with it (masking the uninitialized memory, etc.).
From those 32 bytes that you read, only the first 24 bytes might have been touched. That's a perfectly normal thing (e.g. you ask the allocator for 24 bytes, and it gives you a pointer to a 32 byte allocation, such that the last 8 bytes will never be touched by anyone).
That is, if a program writes only to the 0th byte of a page, this tool won't warn on it reading from the 42nd byte ?