No description
Find a file
sideshowbarker 028eb0a966 AK: Don’t let float precision sneak past is_within_range bounds
Problem: is_within_range<I>(F value) — where I is an integer and F is a
floating-point type — is unexpectedly too permissive in some cases:

a. Values that are 1 past the integer range unexpectedly pass; e.g.,
   is_within_range<int>(2147483648.0f) returns true — even though
   2147483648 is INT_MAX + 1.

b. Fractional values whose magnitude exceeds the destination max
   unexpectedly pass; e.g., is_within_range<unsigned>(4294967295.5)
   returns true — even though 4294967295.5 > UINT_MAX.

c. Fractional values within the destination’s numeric range unexpectedly
   pass (e.g., is_within_range<int>(2.5) returns true) — even though
   they aren’t exactly representable as the destination type.

Cause: TypeBoundsChecker integer-bounds specializations compare against
NumericLimits<Destination>::max() and ::min() directly. When a caller’s
value is a float, the integer max/min get implicitly converted to a
float for the comparison. For Destination/Source pairs with the integer
extreme not exactly representable in the float, that conversion rounds
up to the next power-of-two boundary — so “value <= F(max)” accepts
values that are actually out of range by one (case a). And the
comparison itself doesn’t reject fractional values (cases b and c).

Fix: When Source is a floating-point type:

1. First gate (case a) — Compare against 2^digits; exactly representable
   in any IEEE float, and equals max + 1 for unsigned / -min for two’s-
   complement signed integers.

2. Second gate (cases b and c) – Round-trip check: cast value to
   Destination, then cast back — and require equality. Only integer-
   valued floats whose truncation matches the original pass.

Fixes https://github.com/LadybirdBrowser/ladybird/issues/6212
2026-05-27 19:05:56 +02:00
.devcontainer Devcontainer: Fixes for fedora 2026-04-30 10:10:25 +02:00
.github CI: Switch GNU build from sanitizer to release 2026-05-24 10:13:23 +02:00
AK AK: Don’t let float precision sneak past is_within_range bounds 2026-05-27 19:05:56 +02:00
Base/res LibWebView: Use existing CSS rules for advanced setting inputs 2026-05-26 17:57:37 -04:00
Documentation LibWeb: Mark pseudo-elements as either synthetic or element-reference 2026-05-21 14:26:22 +01:00
Libraries DevTools: Allocate fresh highlighter actors for each request 2026-05-27 17:47:50 +01:00
Meta Meta: Mark generated CSS enum to_string() methods as WEB_API 2026-05-27 17:47:50 +01:00
Services DevTools: Include subframe grids in layout inspection 2026-05-27 17:47:50 +01:00
Tests AK: Don’t let float precision sneak past is_within_range bounds 2026-05-27 19:05:56 +02:00
UI UI: Update page visibility when switching tabs 2026-05-27 18:44:42 +02:00
Utilities Utilities/wasm: Stub non-function imports under --export-all-imports 2026-05-27 09:52:34 +02:00
.clang-format Meta: Enforce newlines around namespaces 2025-05-14 02:01:59 -06:00
.clang-tidy Meta: Disable clang-tidy's const correctness checks 2025-07-08 11:04:15 -04:00
.clangd Meta: Enable angled brackets in clangd 2026-03-20 19:32:14 +01:00
.editorconfig Meta: Add .editorconfig 2022-09-10 17:32:55 +01:00
.gitattributes LibGfx: Remove support for the various "portable" image formats 2024-06-17 21:57:35 +02:00
.gitignore Meta: Ignore log files 2026-04-23 13:50:01 -04:00
.mailmap Meta: Update my e-mail address everywhere 2024-10-04 13:19:50 +02:00
.pre-commit-config.yaml Meta: Replace deprecated pre-commit stage name 2024-10-18 09:40:59 +02:00
.prettierignore Tests: Exclude JS AST and bytecode tests from prettier checks 2026-02-19 02:45:37 +01:00
.prettierrc Meta: Increase the line length enforced by prettier to 120 2025-10-31 19:55:50 -04:00
.ycm_extra_conf.py Meta: Sort all python imports 2025-06-09 11:25:14 -04:00
Cargo.lock LibWeb: Add adblock-rust FFI hooks 2026-05-24 08:16:46 +02:00
Cargo.toml LibWeb: Add adblock-rust FFI hooks 2026-05-24 08:16:46 +02:00
CMakeLists.txt Meta: Remove a legacy NoCoverage target 2026-05-05 22:08:24 +02:00
CMakePresets.json CMake+CI: Use the same preset names on every platform 2026-01-17 12:18:46 -07:00
CODE_OF_CONDUCT.md Meta: Add code of conduct (from the Ruby community) 2024-10-02 09:49:52 +02:00
CONTRIBUTING.md Meta: Disallow PR descriptions entirely generated by AI 2026-04-05 16:17:29 +02:00
ISSUES.md Everywhere: Document use of ladybird.py over ladybird.sh 2025-05-29 16:24:17 -04:00
LICENSE Meta: Update license year 2025-02-10 11:40:57 +00:00
pyproject.toml Meta+CI: Add pyright type checking to lint_python.sh 2026-05-13 08:13:51 -05:00
README.md Libraries: Remove LibArchive 2024-11-25 13:37:45 +01:00
rust-toolchain.toml Meta: Pin Rust toolchain version 2026-04-16 23:42:22 +02:00
rustfmt.toml Rust: Add a config file for rustfmt 2026-04-18 08:05:47 -04:00
SECURITY.md Documentation: Make updates to align better with new issue template 2024-10-31 09:18:08 +01:00
vcpkg-configuration.json Meta: Add overlay port for vulkan-loader 2024-07-07 15:56:59 +02:00
vcpkg.json Meta: Ensure version overrides in vcpkg.json are consistent 2026-05-05 22:08:24 +02:00

Ladybird

Ladybird is a truly independent web browser, using a novel engine based on web standards.

Important

Ladybird is in a pre-alpha state, and only suitable for use by developers

Features

We aim to build a complete, usable browser for the modern web.

Ladybird uses a multi-process architecture with a main UI process, several WebContent renderer processes, an ImageDecoder process, and a RequestServer process.

Image decoding and network connections are done out of process to be more robust against malicious content. Each tab has its own renderer process, which is sandboxed from the rest of the system.

At the moment, many core library support components are inherited from SerenityOS:

  • LibWeb: Web rendering engine
  • LibJS: JavaScript engine
  • LibWasm: WebAssembly implementation
  • LibCrypto/LibTLS: Cryptography primitives and Transport Layer Security
  • LibHTTP: HTTP/1.1 client
  • LibGfx: 2D Graphics Library, Image Decoding and Rendering
  • LibUnicode: Unicode and locale support
  • LibMedia: Audio and video playback
  • LibCore: Event loop, OS abstraction layer
  • LibIPC: Inter-process communication

How do I build and run this?

See build instructions for information on how to build Ladybird.

Ladybird runs on Linux, macOS, Windows (with WSL2), and many other *Nixes.

How do I read the documentation?

Code-related documentation can be found in the documentation folder.

Get in touch and participate!

Join our Discord server to participate in development discussion.

Please read Getting started contributing if you plan to contribute to Ladybird for the first time.

Before opening an issue, please see the issue policy and the detailed issue-reporting guidelines.

The full contribution guidelines can be found in CONTRIBUTING.md.

License

Ladybird is licensed under a 2-clause BSD license.