From: Brian Cain <brian.cain@oss.qualcomm.com>
To: qemu-devel@nongnu.org
Cc: "Pierrick Bouvier" <pierrick.bouvier@oss.qualcomm.com>,
"Alex Bennée" <alex.bennee@linaro.org>,
"Brian Cain" <brian.cain@oss.qualcomm.com>,
sid.manning@oss.qualcomm.com
Subject: [PATCH 03/17] tests/tcg/hexagon: fix undefined signed integer overflow in hvx_misc
Date: Sat, 5 Sep 2026 11:09:35 -0700 [thread overview]
Message-ID: <20260905180949.1852673-4-brian.cain@oss.qualcomm.com> (raw)
In-Reply-To: <20260905180949.1852673-1-brian.cain@oss.qualcomm.com>
Use unsigned (.uw) instead of signed (.w) array members for
vector addition and subtraction reference calculations to avoid
signed integer overflow. Wrapping arithmetic is well-defined for
unsigned types. Add CHECK_OUTPUT_FUNC(uw, 4) to support unsigned
word comparisons in the TEST_VEC_OP2 macro.
Found with UBSan.
Signed-off-by: Brian Cain <brian.cain@oss.qualcomm.com>
---
tests/tcg/hexagon/hvx_misc.h | 1 +
tests/tcg/hexagon/hvx_misc.c | 18 +++++++++---------
2 files changed, 10 insertions(+), 9 deletions(-)
diff --git a/tests/tcg/hexagon/hvx_misc.h b/tests/tcg/hexagon/hvx_misc.h
index c21ea975c16..e32715ed11d 100644
--- a/tests/tcg/hexagon/hvx_misc.h
+++ b/tests/tcg/hexagon/hvx_misc.h
@@ -69,6 +69,7 @@ static inline void check_output_##FIELD(int line, size_t num_vectors) \
CHECK_OUTPUT_FUNC(d, 8)
CHECK_OUTPUT_FUNC(w, 4)
CHECK_OUTPUT_FUNC(sf, 4)
+CHECK_OUTPUT_FUNC(uw, 4)
CHECK_OUTPUT_FUNC(h, 2)
CHECK_OUTPUT_FUNC(uh, 2)
CHECK_OUTPUT_FUNC(hf, 2)
diff --git a/tests/tcg/hexagon/hvx_misc.c b/tests/tcg/hexagon/hvx_misc.c
index 32a3661a86f..f20afc8e670 100644
--- a/tests/tcg/hexagon/hvx_misc.c
+++ b/tests/tcg/hexagon/hvx_misc.c
@@ -55,7 +55,7 @@ static void test_load_tmp(void)
pout += sizeof(MMVector);
for (int j = 0; j < MAX_VEC_SIZE_BYTES / 4; j++) {
- expect[i].w[j] = buffer0[i].w[j] + buffer1[i].w[j] + 1;
+ expect[i].uw[j] = buffer0[i].uw[j] + buffer1[i].uw[j] + 1;
}
}
@@ -285,8 +285,8 @@ static void test_max_temps()
/* The first two vectors come from the vadd-pair instruction */
for (int i = 0; i < MAX_VEC_SIZE_BYTES / 4; i++) {
- expect[0].w[i] = buffer0[0].w[i] + buffer0[2].w[i];
- expect[1].w[i] = buffer0[1].w[i] + buffer0[3].w[i];
+ expect[0].uw[i] = buffer0[0].uw[i] + buffer0[2].uw[i];
+ expect[1].uw[i] = buffer0[1].uw[i] + buffer0[3].uw[i];
}
/* The third vector comes from the vshuffe instruction */
for (int i = 0; i < MAX_VEC_SIZE_BYTES / 2; i++) {
@@ -295,7 +295,7 @@ static void test_max_temps()
}
/* The fourth vector comes from the vadd-single instruction */
for (int i = 0; i < MAX_VEC_SIZE_BYTES / 4; i++) {
- expect[3].w[i] = buffer0[1].w[i] + buffer0[5].w[i];
+ expect[3].uw[i] = buffer0[1].uw[i] + buffer0[5].uw[i];
}
/*
* The fifth vector comes from the load to v4
@@ -306,10 +306,10 @@ static void test_max_temps()
check_output_b(__LINE__, 5);
}
-TEST_VEC_OP2(vadd_w, vadd, .w, w, 4, +)
+TEST_VEC_OP2(vadd_w, vadd, .w, uw, 4, +)
TEST_VEC_OP2(vadd_h, vadd, .h, h, 2, +)
TEST_VEC_OP2(vadd_b, vadd, .b, b, 1, +)
-TEST_VEC_OP2(vsub_w, vsub, .w, w, 4, -)
+TEST_VEC_OP2(vsub_w, vsub, .w, uw, 4, -)
TEST_VEC_OP2(vsub_h, vsub, .h, h, 2, -)
TEST_VEC_OP2(vsub_b, vsub, .b, b, 1, -)
TEST_VEC_OP2(vxor, vxor, , d, 8, ^)
@@ -489,9 +489,9 @@ static void test_load_tmp_predicated(void)
pout += sizeof(MMVector);
for (int j = 0; j < MAX_VEC_SIZE_BYTES / 4; j++) {
- expect[i].w[j] =
- pred ? buffer0[i].w[j] + buffer1[i].w[j] + 1
- : buffer0[i].w[j] + 2;
+ expect[i].uw[j] =
+ pred ? buffer0[i].uw[j] + buffer1[i].uw[j] + 1
+ : buffer0[i].uw[j] + 2;
}
pred = !pred;
}
--
2.34.1
next prev parent reply other threads:[~2026-09-05 18:12 UTC|newest]
Thread overview: 35+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-05 18:09 [PATCH 00/17] hexagon: TCG test coverage + ubsan fixes Brian Cain
2026-09-05 18:09 ` [PATCH 01/17] tests/tcg/hexagon: fix undefined signed left shift in circ.c Brian Cain
2026-09-08 15:54 ` Sid Manning
2026-09-05 18:09 ` [PATCH 02/17] tests/tcg/hexagon: fix undefined signed left shift in brev.c Brian Cain
2026-09-09 14:43 ` Sid Manning
2026-09-05 18:09 ` Brian Cain [this message]
2026-09-09 14:50 ` [PATCH 03/17] tests/tcg/hexagon: fix undefined signed integer overflow in hvx_misc Sid Manning
2026-09-05 18:09 ` [PATCH 04/17] tests/tcg/hexagon: fix undefined integer overflow in v69_hvx.c Brian Cain
2026-09-09 14:51 ` Sid Manning
2026-09-05 18:09 ` [PATCH 05/17] tests/tcg/multiarch: suppress UBSan for float-to-int conversions Brian Cain
2026-09-14 19:43 ` Pierrick Bouvier
2026-09-05 18:09 ` [PATCH 06/17] tests/tcg/hexagon: add FP classification, conversion, and fixup tests Brian Cain
2026-09-14 19:43 ` Pierrick Bouvier
2026-09-05 18:09 ` [PATCH 07/17] tests/tcg/hexagon: add bit interleave and convergent rounding tests Brian Cain
2026-09-10 17:54 ` Sid Manning
2026-09-05 18:09 ` [PATCH 08/17] tests/tcg/hexagon: add cond call, tstbit-jump, and endloop01 tests Brian Cain
2026-09-14 19:44 ` Pierrick Bouvier
2026-09-05 18:09 ` [PATCH 09/17] tests/tcg/hexagon: add dczeroa cache line zero test Brian Cain
2026-09-10 18:14 ` Sid Manning
2026-09-05 18:09 ` [PATCH 10/17] tests/tcg/hexagon: add HVX vwhist tests Brian Cain
2026-09-14 21:21 ` Pierrick Bouvier
2026-09-05 18:09 ` [PATCH 11/17] tests/tcg/hexagon: add sfrecipa edge case tests Brian Cain
2026-09-14 21:22 ` Pierrick Bouvier
2026-09-05 18:09 ` [PATCH 12/17] tests/tcg/hexagon: add dfmpyhh Brian Cain
2026-09-14 21:22 ` Pierrick Bouvier
2026-09-05 18:09 ` [PATCH 13/17] tests/tcg/hexagon: add unconditional store-immediate tests Brian Cain
2026-09-14 21:23 ` Pierrick Bouvier
2026-09-05 18:09 ` [PATCH 14/17] tests/tcg/hexagon: add predicate register transfer test Brian Cain
2026-09-14 21:23 ` Pierrick Bouvier
2026-09-05 18:09 ` [PATCH 15/17] tests/tcg/hexagon: add rounding conv, sffma:lib, and sfinvsqrta Brian Cain
2026-09-14 21:23 ` Pierrick Bouvier
2026-09-05 18:09 ` [PATCH 16/17] tests/tcg/hexagon: add scalar+HVX and masked store tests Brian Cain
2026-09-14 21:24 ` Pierrick Bouvier
2026-09-05 18:09 ` [PATCH 17/17] tests/tcg/hexagon: add decbin MPS test case Brian Cain
2026-09-14 21:24 ` Pierrick Bouvier
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260905180949.1852673-4-brian.cain@oss.qualcomm.com \
--to=brian.cain@oss.qualcomm.com \
--cc=alex.bennee@linaro.org \
--cc=pierrick.bouvier@oss.qualcomm.com \
--cc=qemu-devel@nongnu.org \
--cc=sid.manning@oss.qualcomm.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.