diff mbox

linux-user: fix undefined shift in copy_to_user_fdset

Message ID mvm38v02chh.fsf@hawking.suse.de
State New
Headers show

Commit Message

Andreas Schwab April 9, 2013, 11:02 a.m. UTC
If TARGET_ABI_BITS is bigger than 32 we shift by more than the size of int.

Signed-off-by: Andreas Schwab <schwab@suse.de>
---
 linux-user/syscall.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Comments

Peter Maydell April 9, 2013, 11:12 a.m. UTC | #1
On 9 April 2013 12:02, Andreas Schwab <schwab@suse.de> wrote:
> If TARGET_ABI_BITS is bigger than 32 we shift by more than the size of int.
>
> Signed-off-by: Andreas Schwab <schwab@suse.de>

Reviewed-by: Peter Maydell <peter.maydell@linaro.org>

-- PMM

> ---
>  linux-user/syscall.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/linux-user/syscall.c b/linux-user/syscall.c
> index fa3039f..5abc16f 100644
> --- a/linux-user/syscall.c
> +++ b/linux-user/syscall.c
> @@ -922,7 +922,7 @@ static inline abi_long copy_to_user_fdset(abi_ulong target_fds_addr,
>      for (i = 0; i < nw; i++) {
>          v = 0;
>          for (j = 0; j < TARGET_ABI_BITS; j++) {
> -            v |= ((FD_ISSET(k, fds) != 0) << j);
> +            v |= ((abi_ulong)(FD_ISSET(k, fds) != 0) << j);
>              k++;
>          }
>          __put_user(v, &target_fds[i]);
> --
> 1.8.2.1
>
> --
> Andreas Schwab, SUSE Labs, schwab@suse.de
> GPG Key fingerprint = 0196 BAD8 1CE9 1970 F4BE  1748 E4D4 88E3 0EEA B9D7
> "And now for something completely different."
>
diff mbox

Patch

diff --git a/linux-user/syscall.c b/linux-user/syscall.c
index fa3039f..5abc16f 100644
--- a/linux-user/syscall.c
+++ b/linux-user/syscall.c
@@ -922,7 +922,7 @@  static inline abi_long copy_to_user_fdset(abi_ulong target_fds_addr,
     for (i = 0; i < nw; i++) {
         v = 0;
         for (j = 0; j < TARGET_ABI_BITS; j++) {
-            v |= ((FD_ISSET(k, fds) != 0) << j);
+            v |= ((abi_ulong)(FD_ISSET(k, fds) != 0) << j);
             k++;
         }
         __put_user(v, &target_fds[i]);