Skip to content

Fix 68020 DIVS.L/DIVU.L overflow and signed 64-bit division - #387

Open
ozbenh wants to merge 1 commit into
twvd:masterfrom
ozbenh:fix-divl-overflow
Open

ozbenh wants to merge 1 commit into
twvd:masterfrom
ozbenh:fix-divl-overflow

Conversation

@ozbenh

@ozbenh ozbenh commented Oct 1, 2026 •

Copy link
Copy Markdown

DIVS.L of $80000000 by -1 in the 32-bit form used a native i32 division causes a panics: "attempt to divide with overflow".

It takes the emulator down. A program feeding edge cases to the Toolbox fixed-point routines hit this on a Mac II with System 4.1 (among others).

While there:

  • the 64-bit signed form zero-extended the divisor, so a negative divisor gave a wrong quotient;
  • overflow was only tested on the 64-bit forms, and accepted any quotient whose high long was 0 or $FFFFFFFF: an unsigned quotient above 32 bits, or a signed one outside the i32 range, went through.

Do signed divisions in 64 bits with a sign-extended divisor, checked for i64::MIN / -1, and report overflow (V set, operands unchanged) whenever the quotient doesn't fit in 32 bits.

Note: This was mostly found by AI after debugging a crash and the fix written by AI with a bit of guidance and review from me.

DIVS.L of $80000000 by -1 in the 32-bit form used a native i32
division, which panics ("attempt to divide with overflow") and takes
the emulator down. A program feeding edge cases to the Toolbox
fixed-point routines hit this on a Mac II with System 4.1.

While there:
- the 64-bit signed form zero-extended the divisor, so a negative
  divisor gave a wrong quotient;
- overflow was only tested on the 64-bit forms, and accepted any
  quotient whose high long was 0 or $FFFFFFFF: an unsigned quotient
  above 32 bits, or a signed one outside the i32 range, went through.

Do signed divisions in 64 bits with a sign-extended divisor, checked
for i64::MIN / -1, and report overflow (V set, operands unchanged)
whenever the quotient doesn't fit in 32 bits.

Signed-off-by: Benjamin Herrenschmidt <benh@kernel.crashing.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant