cpukit/libmisc: Remove the dead range checks

The string to integer template checked the range of the value in
every instantiation.  Six of the seven integer instantiations use a
conversion method whose type is not wider than the type of the value.
For those the two comparisons were constant and the code behind them
was dead.  Coverity reported this as CID 1700407 to CID 1700418.

Emit the range check only where the type of the conversion method is
wider than the type of the value.  Every instantiation which sets
STRING_TO_RESULT_TYPE gives the maximum of that type in
STRING_TO_RESULT_MAX.  The template compares the two maxima.  An
undefined macro drops the check without a diagnostic, so a missing
STRING_TO_RESULT_MAX is an error.

Behaviour is unchanged.  Where the two types have the same width, the
conversion method sets ERANGE.  The template already turns ERANGE into
RTEMS_INVALID_NUMBER.

Update #5708.

Assisted-by: Claude:claude-opus-5 claude-code
Signed-off-by: Sebastian Huber <sebastian.huber@embedded-brains.de>
This commit is contained in:
Sebastian Huber
2026-08-20 03:21:55 +02:00
parent 3a1f6f9f60
commit 6dca13d962
4 changed files with 11 additions and 2 deletions
+8 -2
View File
@@ -66,6 +66,10 @@
#error "STRING_TO_MAX not defined"
#endif
#if defined( STRING_TO_RESULT_TYPE ) && !defined( STRING_TO_RESULT_MAX )
#error "STRING_TO_RESULT_MAX not defined"
#endif
#undef ZERO
#ifdef STRING_TO_FLOAT
#define ZERO 0.0
@@ -128,9 +132,10 @@ rtems_status_code STRING_TO_NAME(
return RTEMS_INVALID_NUMBER;
}
#if defined( STRING_TO_RESULT_TYPE ) && STRING_TO_RESULT_MAX > STRING_TO_MAX
/*
* The conversion method returns a type which can be wider than the type of
* the value, so the range of the value has to be checked.
* The conversion method returns a type which is wider than the type of the
* value, so the range of the value has to be checked.
*/
if ( result > STRING_TO_MAX ) {
errno = ERANGE;
@@ -143,6 +148,7 @@ rtems_status_code STRING_TO_NAME(
return RTEMS_INVALID_NUMBER;
}
#endif
#endif
#else
#ifdef STRING_TO_MAX
/* there was an overflow */
+1
View File
@@ -45,4 +45,5 @@
#define STRING_TO_MAX INT_MAX
#define STRING_TO_MIN INT_MIN
#define STRING_TO_RESULT_TYPE long
#define STRING_TO_RESULT_MAX LONG_MAX
#include "stringto_template.h"
@@ -44,4 +44,5 @@
#define STRING_TO_METHOD strtoul
#define STRING_TO_MAX UCHAR_MAX
#define STRING_TO_RESULT_TYPE unsigned long
#define STRING_TO_RESULT_MAX ULONG_MAX
#include "stringto_template.h"
@@ -44,4 +44,5 @@
#define STRING_TO_METHOD strtoul
#define STRING_TO_MAX UINT_MAX
#define STRING_TO_RESULT_TYPE unsigned long
#define STRING_TO_RESULT_MAX ULONG_MAX
#include "stringto_template.h"