• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

vbpf / prevail
87%

Build:
DEFAULT BRANCH: main
Repo Added 03 Apr 2025 12:08AM UTC
Token ENVZUPw7kXSVTNwI0SnEWS5mIrwoBd6UH regen
Build 945 Last
Files 79
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

LAST BUILD ON BRANCH main
branch: SELECT
CHANGE BRANCH
x
Sync Branches
  • No branch selected
  • 1103-test-only-string-parsing
  • CMP0167-NEW
  • add-ifndefs
  • analysis-engine
  • arith
  • array-map-through-context
  • better-error-handling
  • better-print
  • boost-headers-setup
  • btf_cycles
  • bulk-rename-callee-saved
  • bump-catch2-to-3.9.1
  • bump-ebpf-samples
  • c++23
  • cache-ci
  • call-builtins
  • catch2-3.10.0
  • catch2-3.11.0
  • catch2-3.12.0
  • catch2-3.8.2
  • catch2-3.9.0
  • cfg-dir
  • chore/bump-catch2-3.15.2
  • claude/fix-close-after-widen-bug-Un4eW
  • cli11-v2.5.0
  • cli11-v2.6.1
  • cmake-explicit-sources-144
  • co-re
  • coderabbitai/docstrings/aacd752
  • codex/add-catch2-test-suite-for-ebpfdomain
  • codex/add-catch2-test-suite-for-ebpftransformer
  • codex/create-agents.md-file
  • codex/fix-negative-sdiv-singleton
  • codex/fix-zero-shift-finite-domain
  • codex/handle-out-of-window-numbytes
  • codex/optimize-test-execution-speed
  • codex/reject-misaligned-relocations
  • codex/reject-out-of-range-section-table
  • codex/reject-oversized-map-access-width
  • compute-slice-from-label
  • coverage-exclude-test-344
  • coverage-repository
  • dependabot/github_actions/actions/cache-5
  • dependabot/github_actions/actions/cache-6
  • dependabot/github_actions/actions/checkout-5
  • dependabot/github_actions/actions/checkout-6
  • dependabot/github_actions/actions/checkout-7
  • dependabot/github_actions/actions/upload-artifact-7
  • dependabot/github_actions/github/codeql-action-4
  • dependabot/github_actions/softprops/action-gh-release-3
  • dependabot/submodules/ebpf-samples-058b5c0
  • dependabot/submodules/ebpf-samples-65b12c6
  • dependabot/submodules/ebpf-samples-6a81f8e
  • dependabot/submodules/ebpf-samples-c504fda
  • dependabot/submodules/external/bpf_conformance-057d705
  • dependabot/submodules/external/bpf_conformance-13029d4
  • dependabot/submodules/external/bpf_conformance-151bcd7
  • dependabot/submodules/external/bpf_conformance-15e0553
  • dependabot/submodules/external/bpf_conformance-3203c1f
  • dependabot/submodules/external/bpf_conformance-35b1eb1
  • dependabot/submodules/external/bpf_conformance-394a188
  • dependabot/submodules/external/bpf_conformance-4334864
  • dependabot/submodules/external/bpf_conformance-498ee85
  • dependabot/submodules/external/bpf_conformance-5d1c9f5
  • dependabot/submodules/external/bpf_conformance-5df55bc
  • dependabot/submodules/external/bpf_conformance-5fbe1c3
  • dependabot/submodules/external/bpf_conformance-6e648f2
  • dependabot/submodules/external/bpf_conformance-6fa6a20
  • dependabot/submodules/external/bpf_conformance-8670f73
  • dependabot/submodules/external/bpf_conformance-8b5330d
  • dependabot/submodules/external/bpf_conformance-8e6ed4a
  • dependabot/submodules/external/bpf_conformance-8f3c2fe
  • dependabot/submodules/external/bpf_conformance-93549c2
  • dependabot/submodules/external/bpf_conformance-d280fcd
  • dependabot/submodules/external/bpf_conformance-e208f52
  • dependabot/submodules/external/bpf_conformance-e2318cb
  • dependabot/submodules/external/bpf_conformance-f16282e
  • dependabot/submodules/external/bpf_conformance-f558566
  • dependabot/submodules/external/libbtf-04281ee
  • dependabot/submodules/external/libbtf-0570bf0
  • dependabot/submodules/external/libbtf-11e41e2
  • dependabot/submodules/external/libbtf-1362c17
  • dependabot/submodules/external/libbtf-3115538
  • dependabot/submodules/external/libbtf-35e6a53
  • dependabot/submodules/external/libbtf-55c22b7
  • dependabot/submodules/external/libbtf-5efd6a0
  • dependabot/submodules/external/libbtf-643757e
  • dependabot/submodules/external/libbtf-6a09e51
  • dependabot/submodules/external/libbtf-846bf15
  • dependabot/submodules/external/libbtf-8588c66
  • dependabot/submodules/external/libbtf-9224231
  • dependabot/submodules/external/libbtf-ba5ab5e
  • dependabot/submodules/external/libbtf-cdf441a
  • dependabot/submodules/external/libbtf-e1e4e01
  • dependabot/submodules/external/libbtf-e3a95e2
  • dependabot/submodules/external/libbtf-f3864e6
  • dependabot/submodules/external/libbtf-f96afc3
  • detach-type-domain
  • docs
  • docs/helper-output-initialization-contract
  • dynamic-packet
  • dynamic-stack
  • elazarg-patch-1
  • expected
  • explicit-context
  • extrapolator-api
  • failure-slice
  • fast-slow-tests
  • fast-yaml
  • feat/linear-relation-domain
  • feature/abi-classes
  • feature/call-model
  • feature/callbacks
  • feature/conformance-direct-parse
  • feature/human-friendly-cli
  • feature/kfunc
  • feature/map-by-index-pseudos
  • feature/platform-tables
  • feature/pointer-types
  • feature/runtime-config
  • feature/safety-parity
  • fix-c26817-range-for-copy
  • fix-ci-apt-update
  • fix-cmake-git-hooks
  • fix-ebpf-domain-to-set-bottom
  • fix-issue-626-validmapkeyvalue-print
  • fix-reallocate-packet
  • fix-stacksize
  • fix-ub-radix-substr
  • fix-unaligned-func-symbol-overflow
  • fix/1071-widen-bottom-short-circuit
  • fix/1098-thread-callbtf-module
  • fix/1201-select-potentials-spurious-bottom
  • fix/1202-stale-stack-cell-havoc
  • fix/1203-inlined-callee-backedge
  • fix/absdiv-infinite-sign
  • fix/adapt-sgraph-defects
  • fix/array-domain-weak-havoc-width
  • fix/assume-type-mismatch
  • fix/boolean-and-null-precision
  • fix/btf-map-fallback
  • fix/cfg-builder-seen-labels
  • fix/conformance-group-selection
  • fix/dev-script-bugs
  • fix/dockerfile-cmake-version
  • fix/docs-sync-with-code
  • fix/elf-subprogram-reloc-identity
  • fix/exit-optional-deref
  • fix/finite-domain-32bit
  • fix/ghsa-2qc8-nonsingleton-add
  • fix/ghsa-65fp-alu32-ptr
  • fix/ghsa-65rv-ctx-write
  • fix/hide-boost-public-abi
  • fix/install-ci
  • fix/issue-1099-validmapkeyvalue-packet-size
  • fix/load-narrow-and-ptr-sum-bounds
  • fix/narrow-sign-extending-loads
  • fix/packaging-ci-gaps
  • fix/pentest-soundness-bugs
  • fix/phase6-helper-abi
  • fix/ptr-sum-bound-checks
  • fix/shouldfail-infra-precondition
  • fix/signed-division-soundness
  • fix/socket-direct-access
  • fix/stack-numeric-imprecise-store
  • fix/stack-offset-narrow-crash
  • fix/stale-svalue-copy
  • fix/store-immediate-sign-extension
  • fix/svalue-type-kind-strong-updates
  • fix/test-gen-inventory-gaps
  • fix/tracing-context-descriptor
  • fix/type-subsumed-equality
  • fix/update-expectations-unknown-fail
  • fix/widening-termination
  • fix/windows-ci-vs2026
  • fix/writable-mem-stack-havoc
  • fix/wto-iterative-consumers
  • fix/yaml-diff-bottom-invariant
  • fix_cmake_issue
  • fix_fuzzer_debug
  • fix_prevail_cmake
  • folder-structure
  • get-local-storage-flags
  • get_helper_prototype_use_fix
  • global-var
  • gsl-narrow-heap
  • hard-assert
  • int128
  • inventory-reject-1043
  • issue-728-observation-check
  • lazy-allocator-constant-limits
  • lazy-allocator-constant-limits-dco
  • lib
  • llm-context-doc
  • load-elf-fix
  • long-test-names
  • loop-mask-constraints
  • main
  • maintain_enum_order
  • map-count-fix
  • map-func-compat
  • may_have_type
  • milestones
  • minmax
  • modernize-graph-iterators
  • more-proto
  • mov-imm-fix
  • msvc-debug-assert-handler
  • namespace
  • no-patricia
  • opt
  • passes
  • prevail-mcp
  • prevail-namespace
  • principled-context-cleanup
  • prog-env
  • project-name
  • proposal/diagnostic-reporting
  • readme-compiler-630
  • refactor/call-resolver-kfunc
  • refactor/data-driven-verify-tests
  • remove-thread-local-options
  • remove-thresholds
  • rename-classes
  • rename-library
  • resolve_by_name
  • review-fixes
  • sleepable-might-sleep
  • split-call
  • svalue-num-specific
  • test-join
  • test/rfc9669-llm-conformance
  • tidy
  • type-domain-rcu
  • unreachable
  • update_assertion_creation
  • update_cfg_computation
  • update_read_elf
  • user/anusa/add_inner_map_template
  • user/anusa/array_opt
  • user/anusa/asan_fix
  • user/anusa/verification_issue
  • user/khorton/StringInvariant_to_use_moves
  • v0.2.0
  • verification-context
  • verify-all-conformance
  • version-flag-1108
  • yaml-dynamic

24 Jul 2026 01:28PM UTC coverage: 86.762%. Remained the same
30096987245

push

github

web-flow
Handle out-of-bounds negative stack offset without crashing (fixes #1211) (#1212)

A stack access at a negative constant offset (a stack pointer walked below its
frame) crashed the verifier with an uncaught InternalError instead of rejecting
the out-of-bounds access:

    CRAB ERROR: Number -8 does not fit into m; function narrow, line 208

The strong-update path narrows the byte offset to the unsigned cell-offset type
Index (uint64_t): `n->narrow<Index>()` in both `kill_and_find_var` (used by
havoc/havoc_type/store/store_type) and `split_number_var`. A negative singleton
offset does not fit an unsigned type, so narrow throws and aborts the whole
analysis -- a robustness/DoS hole on adversarial input.

Guard the constant-offset path with `n->fits<Index>()`, exactly the condition
under which the narrow is safe. A negative offset has no corresponding stack
cell, so the cell bookkeeping is skipped and the out-of-bounds access is left
for the assertion checker to reject. Verified end-to-end that the crash becomes
a clean rejection ("Lower bound must be at least
r10.stack_offset - subprogram_stack_size") rather than a silent accept.

Regression test in test_array_domain.cpp drives store_type/havoc_type/havoc/
store with a negative singleton offset and asserts no throw and that the
in-bounds cell is untouched; it throws the InternalError without the fix.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QRunjNUunuZjp6KiBSZXzt
Signed-off-by: Elazar Gershuni <elazarg@gmail.com>

* Don't route negative constant stack offsets through symbolic kill (

Addresses review feedback. The guard only prevented the narrow
crash: a negative singleton offset left `res` empty and fell through to the
symbolic kill path, which builds the inclusive range `ii | (ii + elem_size)`
(e.g. [-8, 0]). That range overlaps the tracked cell [0, 8) at the shared
endpoint 0, so a havoc/store at a negative offset erased th... (continued)

9326 of 10749 relevant lines covered (86.76%)

6319078.39 hits per line

Relevant lines Covered
Build:
Build:
10749 RELEVANT LINES 9326 COVERED LINES
6319078.39 HITS PER LINE
Source Files on main
  • Tree
  • List 79
  • Changed 1
  • Source Changed 1
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line

Recent builds

Builds Branch Commit Type Ran Committer Via Coverage
30096987245 main Handle out-of-bounds negative stack offset without crashing (fixes #1211) (#1212) A stack access at a negative constant offset (a stack pointer walked below its frame) crashed the verifier with an uncaught InternalError instead of rejecting the o... push 24 Jul 2026 01:38PM UTC web-flow github
86.76
30049892521 feat/linear-relation-domain Merge 31c474d22 into 07558f088 Pull #1213 23 Jul 2026 10:36PM UTC GitHub github
87.1
29851398100 main Reconstruct inlined callee's internal edges in a second pass (fixes #1203) (#1209) * Reconstruct inlined callee's internal edges in a second pass (fixes #1203) When a bpf-to-bpf local function is inlined, `add_cfg_nodes` reconstructed the clone'... push 21 Jul 2026 05:15PM UTC web-flow github
86.76
29851285864 main Reset per-SCC vertex marks in select_potentials (fixes #1201) (#1210) `select_potentials` runs Bellman-Ford per SCC to assign valid potentials during meet, using `vert_marks` to track which vertices belong to the SCC currently being processed (BF... push 21 Jul 2026 05:13PM UTC web-flow github
86.76
29850994034 fix/stack-offset-narrow-crash Merge e705f9c07 into b8dd92616 Pull #1212 21 Jul 2026 05:09PM UTC web-flow github
86.76
29784313676 fix/stack-offset-narrow-crash Merge 9b3da880a into b8dd92616 Pull #1212 20 Jul 2026 10:43PM UTC web-flow github
86.76
29783290643 fix/stack-offset-narrow-crash Merge 994a9dd86 into b8dd92616 Pull #1212 20 Jul 2026 10:33PM UTC web-flow github
86.76
29781093587 fix/1203-inlined-callee-backedge Merge 86e0bf212 into b8dd92616 Pull #1209 20 Jul 2026 09:55PM UTC web-flow github
86.76
29779616095 fix/1201-select-potentials-spurious-bottom Merge 32baba502 into b8dd92616 Pull #1210 20 Jul 2026 09:27PM UTC web-flow github
86.76
29778242089 main Havoc exact-match stack cell on kill (fixes #1202) `get_overlap_cells` deliberately excludes the exact-match cell (o, size) because loads handle it separately via `get_cell`. But `kill_and_find_var` reuses `get_overlap_cells` for the havoc path, ... push 20 Jul 2026 09:07PM UTC elazarg github
86.76
See All Builds (923)

Badge your Repo: prevail

We detected this repo isn’t badged! Grab the embed code to the right, add it to your repo to show off your code coverage, and when the badge is live hit the refresh button to remove this message.

Could not find badge in README.

Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

Refresh
  • Settings
  • Repo on GitHub
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc