Skip to content

fix(daemon): suppress GCC 16 -Warray-bounds false positive - #113

Merged
zccrs merged 1 commit into
linuxdeepin:masterfrom
deepin-wm:agent/developer/855b1f50db3b
Oct 10, 2026
Merged

zccrs merged 1 commit into
linuxdeepin:masterfrom
deepin-wm:agent/developer/855b1f50db3b

Conversation

@deepin-wm

@deepin-wm deepin-wm commented Oct 8, 2026 •

Copy link
Copy Markdown

背景

ddm 的 Build ddm on Arch Linux 工作流在 master 基线上因 -Werror=array-bounds 中断,导致所有 ddm PR 的该检查都是红的。触发 run:https://github.com/linuxdeepin/ddm/actions/runs/37735447997

src/daemon/DdeSeatdControl.cpp:391:15: error: array subscript 'unsigned int[0]' is partly outside array bounds of 'const char [1]' [-Werror=array-bounds=]
/usr/include/qt6/QtCore/qbytearray.h:65:23: note: object 'QByteArray::_empty' of size 1
cc1plus: all warnings being treated as errors

这是 archlinux:latest 滚动到 GCC 16 之后暴露的既有问题,与任何 PR 的改动都无关(最初触发它的 PR #112 只改了 2 个 workflow 文件的 on: 触发条件)。

根因

QByteArray::constData() 在空数据时可能返回 1 字节的静态 QByteArray::_empty(const char[1])。GCC 15/16 的 -Warray-bounds 无法把 size() 的返回值与 constData() 返回的指针关联起来,于是把「源码来自 1 字节静态对象」这条不可达路径当成可能路径,对 4 字节的 memcpy 报错。

原代码并没有越界:src/daemon/DdeSeatdControl.cpp:389 的循环条件已经是 while (m_eventBuffer.size() >= static_cast<int>(sizeof(ControlHeader))),进入循环体时缓冲区至少有 sizeof(ControlHeader) = 4 字节,第 391 行的 memcpy 是安全的。

改动内容

src/daemon/DdeSeatdControl.cpp 一处,1 文件 / +7 行:

  • 对该条 memcpy 局部使用 QT_WARNING_PUSH / QT_WARNING_DISABLE_GCC("-Warray-bounds") / QT_WARNING_POP,只关闭 GCC 的这一次误报;
  • 上方加注释说明「while 已保证长度」以及「GCC 15/16 对 QByteArray::constData() 的误报成因」,避免后来人误以为这里本来就可能越界。

为什么这么改

  • 抑制范围最小,只作用于这一条语句;没有重复添加长度判断,没有改变线格式、字节序或运行时行为。
  • QT_WARNING_DISABLE_GCC 只对 GCC 生效,不会掩盖 clang 的真实告警。
  • 没有改成逐字节拷贝之类的等价写法:原代码本身是正确的,改写反而会引入与线格式相关的风险。

验证

  • 在 archlinux:latest 容器(GCC 16.2.1 / Qt 6.12.0,编译参数与 workflow 完全一致 -DCMAKE_CXX_FLAGS="-Wall -Wextra -Werror")中先复现同一报错,应用本改动后完整构建 53/53 个 target 通过、链接产出 src/daemon/ddm、退出码 0。
  • 本 PR 上的 Arch Linux 工作流变绿即闭环。

关联

Summary by Sourcery

Prevent GCC 15/16 false-positive array-bounds warnings from failing daemon builds without changing runtime behavior.

Bug Fixes:

  • Suppress the GCC 15/16 false-positive -Warray-bounds diagnostic that breaks Arch Linux daemon builds.

Enhancements:

  • Document why the guarded event-buffer copy is safe and limit warning suppression to that specific operation.

1. Wrap the ControlHeader memcpy in DdeSeatdControl with a local GCC
   -Warray-bounds suppression and document why the copy is in bounds.
2. The while loop above already guarantees the buffer holds at least
   sizeof(ControlHeader) bytes, so the copy is in bounds. GCC 15/16
   cannot relate QByteArray::size() to the pointer returned by
   constData(), which may be the 1-byte static QByteArray::_empty.
3. No wire format, byte order or runtime behaviour change.

Log: No user-facing changes

Influence:
1. Build ddm on Arch Linux (GCC 16, -Werror) and confirm it passes.
2. Check that DdeSeatdControl.cpp:391 no longer emits array-bounds.
3. Verify dde-seatd control messages are still received correctly.

fix(daemon): 抑制 GCC 16 对 constData() 的 -Warray-bounds 误报

1. 在 DdeSeatdControl 中对 ControlHeader 的 memcpy 局部关闭 GCC
   的 -Warray-bounds 告警,并注明该拷贝在界内的原因。
2. 上方 while 循环已保证缓冲区长度不小于 sizeof(ControlHeader);
   GCC 15/16 无法把 QByteArray::size() 与 constData() 返回的指针
   关联,后者可能指向 1 字节静态 QByteArray::_empty,故为误报。
3. 不改变线格式、字节序与运行时行为。

Log: 无用户可见变化

Influence:
1. 在 Arch Linux(GCC 16、-Werror)下构建 ddm,确认通过。
2. 确认 DdeSeatdControl.cpp:391 不再报 array-bounds。
3. 验证 dde-seatd 控制消息仍能正常收发。

Multica Issue: WM-566
@deepin-ci-robot

Copy link
Copy Markdown

Skipping CI for Draft Pull Request.
If you want CI signal for your change, please convert it to an actual PR.
You can still manually trigger a test run with /test all

@sourcery-ai

sourcery-ai Bot commented Oct 8, 2026 •

Copy link
Copy Markdown
Reviewer's guide (collapsed on small PRs)

Reviewer's Guide

The PR fixes Arch/GCC 15–16 build failures by locally suppressing an array-bounds false positive caused by GCC’s inability to connect QByteArray::size() with constData(), while retaining the existing size guard and unchanged safe memcpy behavior.

Flow diagram for guarded event-buffer header copy

flowchart TD
    A[m_eventBuffer.append] --> B{m_eventBuffer.size >= sizeof ControlHeader}
    B -- No --> C[Exit loop]
    B -- Yes --> D[QT_WARNING_PUSH]
    D --> E[QT_WARNING_DISABLE_GCC -Warray-bounds]
    E --> F[memcpy from m_eventBuffer.constData to header]
    F --> G[QT_WARNING_POP]
    G --> H[Process ControlHeader]
    H --> B
Loading

File-Level Changes

Change Details Files
Narrowly suppress GCC’s false-positive array-bounds diagnostic for the validated event-header copy.
  • Document that the loop guard guarantees enough buffered bytes for the copy.
  • Wrap only the affected memcpy with QT_WARNING_PUSH, QT_WARNING_DISABLE_GCC("-Warray-bounds"), and QT_WARNING_POP.
  • Keep the suppression GCC-specific and preserve existing runtime behavior, protocol handling, and byte order.
src/daemon/DdeSeatdControl.cpp

Tips and commands

Interacting with Sourcery

  • Trigger a new review: Comment @sourcery-ai review on the pull request.
  • Continue discussions: Reply directly to Sourcery's review comments.
  • Generate a GitHub issue from a review comment: Ask Sourcery to create an
    issue from a review comment by replying to it. You can also reply to a
    review comment with @sourcery-ai issue to create an issue from it.
  • Generate a pull request title: Write @sourcery-ai anywhere in the pull
    request title to generate a title at any time. You can also comment
    @sourcery-ai title on the pull request to (re-)generate the title at any time.
  • Generate a pull request summary: Write @sourcery-ai summary anywhere in
    the pull request body to generate a PR summary at any time exactly where you
    want it. You can also comment @sourcery-ai summary on the pull request to
    (re-)generate the summary at any time.
  • Generate reviewer's guide: Comment @sourcery-ai guide on the pull
    request to (re-)generate the reviewer's guide at any time.
  • Resolve all Sourcery comments: Comment @sourcery-ai resolve on the
    pull request to resolve all Sourcery comments. Useful if you've already
    addressed all the comments and don't want to see them anymore.
  • Dismiss all Sourcery reviews: Comment @sourcery-ai dismiss on the pull
    request to dismiss all existing Sourcery reviews. Especially useful if you
    want to start fresh with a new review - don't forget to comment
    @sourcery-ai review to trigger a new review!

Customizing Your Experience

Access your dashboard to:

  • Enable or disable review features such as the Sourcery-generated pull request
    summary, the reviewer's guide, and others.
  • Change the review language.
  • Add, remove or edit custom review instructions.
  • Adjust other review settings.

Getting Help

@deepin-ci-robot

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by: deepin-wm, zccrs

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@zccrs
zccrs marked this pull request as ready for review October 10, 2026 02:36
@zccrs
zccrs merged commit f5681d4 into linuxdeepin:master Oct 10, 2026
6 of 7 checks passed

@sourcery-ai sourcery-ai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey - I've reviewed your changes and they look great!


Sourcery is free for open source - if you like our reviews please consider sharing them ✨

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants