Skip to content

[java] Fix BufferOverrun FP on String.split with non-positive limit - #2094

Merged
dulmarod merged 2 commits into
facebook:mainfrom
tanvir-ux:fix/java-string-split-limit
Aug 25, 2026
Merged

dulmarod merged 2 commits into
facebook:mainfrom
tanvir-ux:fix/java-string-split-limit

Conversation

@tanvir-ux

Copy link
Copy Markdown
Contributor

String.split(regex, limit) was modeled by treating limit as the malloc size of the result array. For s.split(",", -1) that produces INFERBO_ALLOC_MAY_BE_NEGATIVE with length [-1, 1], even though the result length is never negative.

Size the result from the receiver (same idea as the one-arg overload). A positive limit is only used as an upper bound.

Fixes #1971

The two-arg model used the limit as the result array's malloc size, so split(",", -1) was reported as a possibly negative allocation.
@meta-cla meta-cla Bot added the CLA Signed label Aug 22, 2026
@dulmarod

Copy link
Copy Markdown
Contributor

ERROR 'Running test: direct java performance test'

…odel

The two-arg String.split model now sizes the result from the receiver string, so the loop cost tracks s.length rather than limit.
@tanvir-ux

Copy link
Copy Markdown
Contributor Author

ERROR 'Running test: direct java performance test'

Fixed

@dulmarod
dulmarod merged commit d135005 into facebook:main Aug 25, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

FP in Java's BufferOverrun analysis with String.split(String, int) with non-positive limit

2 participants