xen-devel.lists.xenproject.org archive mirror
 help / color / mirror / Atom feed
* [PATCH] x86: fix bug_line()
@ 2013-10-11 15:25 Jan Beulich
  2013-10-11 17:17 ` Keir Fraser
  0 siblings, 1 reply; 2+ messages in thread
From: Jan Beulich @ 2013-10-11 15:25 UTC (permalink / raw)
  To: xen-devel; +Cc: Keir Fraser

[-- Attachment #1: Type: text/plain, Size: 1203 bytes --]

Due to the packing into a bit field together with a relocated field,
the computation can overflow when the relocated field ends up getting a
negative value stored. Hence it isn't sufficient to correct the value
by 1 in this case, but we also need to mask the result to the width of
the original bit field.

Signed-off-by: Jan Beulich <jbeulich@suse.com>

--- a/xen/include/asm-x86/bug.h
+++ b/xen/include/asm-x86/bug.h
@@ -15,9 +15,11 @@ struct bug_frame {
 
 #define bug_loc(b) ((const void *)(b) + (b)->loc_disp)
 #define bug_ptr(b) ((const void *)(b) + (b)->ptr_disp)
-#define bug_line(b) ((((b)->line_hi + ((b)->loc_disp < 0)) <<                \
+#define bug_line(b) (((((b)->line_hi + ((b)->loc_disp < 0)) &                \
+                       ((1 << BUG_LINE_HI_WIDTH) - 1)) <<                    \
                       BUG_LINE_LO_WIDTH) +                                   \
-                     (b)->line_lo + ((b)->ptr_disp < 0))
+                     (((b)->line_lo + ((b)->ptr_disp < 0)) &                 \
+                      ((1 << BUG_LINE_LO_WIDTH) - 1)))
 #define bug_msg(b) ((const char *)(b) + (b)->msg_disp[1])
 
 #define BUGFRAME_run_fn 0




[-- Attachment #2: x86-bug-line.patch --]
[-- Type: text/plain, Size: 1220 bytes --]

x86: fix bug_line()

Due to the packing into a bit field together with a relocated field,
the computation can overflow when the relocated field ends up getting a
negative value stored. Hence it isn't sufficient to correct the value
by 1 in this case, but we also need to mask the result to the width of
the original bit field.

Signed-off-by: Jan Beulich <jbeulich@suse.com>

--- a/xen/include/asm-x86/bug.h
+++ b/xen/include/asm-x86/bug.h
@@ -15,9 +15,11 @@ struct bug_frame {
 
 #define bug_loc(b) ((const void *)(b) + (b)->loc_disp)
 #define bug_ptr(b) ((const void *)(b) + (b)->ptr_disp)
-#define bug_line(b) ((((b)->line_hi + ((b)->loc_disp < 0)) <<                \
+#define bug_line(b) (((((b)->line_hi + ((b)->loc_disp < 0)) &                \
+                       ((1 << BUG_LINE_HI_WIDTH) - 1)) <<                    \
                       BUG_LINE_LO_WIDTH) +                                   \
-                     (b)->line_lo + ((b)->ptr_disp < 0))
+                     (((b)->line_lo + ((b)->ptr_disp < 0)) &                 \
+                      ((1 << BUG_LINE_LO_WIDTH) - 1)))
 #define bug_msg(b) ((const char *)(b) + (b)->msg_disp[1])
 
 #define BUGFRAME_run_fn 0

[-- Attachment #3: Type: text/plain, Size: 126 bytes --]

_______________________________________________
Xen-devel mailing list
Xen-devel@lists.xen.org
http://lists.xen.org/xen-devel

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH] x86: fix bug_line()
  2013-10-11 15:25 [PATCH] x86: fix bug_line() Jan Beulich
@ 2013-10-11 17:17 ` Keir Fraser
  0 siblings, 0 replies; 2+ messages in thread
From: Keir Fraser @ 2013-10-11 17:17 UTC (permalink / raw)
  To: Jan Beulich, xen-devel

On 11/10/2013 16:25, "Jan Beulich" <JBeulich@suse.com> wrote:

> Due to the packing into a bit field together with a relocated field,
> the computation can overflow when the relocated field ends up getting a
> negative value stored. Hence it isn't sufficient to correct the value
> by 1 in this case, but we also need to mask the result to the width of
> the original bit field.
> 
> Signed-off-by: Jan Beulich <jbeulich@suse.com>

Acked-by: Keir Fraser <keir@xen.org>

> --- a/xen/include/asm-x86/bug.h
> +++ b/xen/include/asm-x86/bug.h
> @@ -15,9 +15,11 @@ struct bug_frame {
>  
>  #define bug_loc(b) ((const void *)(b) + (b)->loc_disp)
>  #define bug_ptr(b) ((const void *)(b) + (b)->ptr_disp)
> -#define bug_line(b) ((((b)->line_hi + ((b)->loc_disp < 0)) <<
> \
> +#define bug_line(b) (((((b)->line_hi + ((b)->loc_disp < 0)) &
> \
> +                       ((1 << BUG_LINE_HI_WIDTH) - 1)) <<
> \
>                        BUG_LINE_LO_WIDTH) +
> \
> -                     (b)->line_lo + ((b)->ptr_disp < 0))
> +                     (((b)->line_lo + ((b)->ptr_disp < 0)) &
> \
> +                      ((1 << BUG_LINE_LO_WIDTH) - 1)))
>  #define bug_msg(b) ((const char *)(b) + (b)->msg_disp[1])
>  
>  #define BUGFRAME_run_fn 0
> 
> 
> 

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2013-10-11 17:17 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-10-11 15:25 [PATCH] x86: fix bug_line() Jan Beulich
2013-10-11 17:17 ` Keir Fraser

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).