Conversation
DIVS.L of $80000000 by -1 in the 32-bit form used a native i32
division, which panics ("attempt to divide with overflow") and takes
the emulator down. A program feeding edge cases to the Toolbox
fixed-point routines hit this on a Mac II with System 4.1.
While there:
- the 64-bit signed form zero-extended the divisor, so a negative
divisor gave a wrong quotient;
- overflow was only tested on the 64-bit forms, and accepted any
quotient whose high long was 0 or $FFFFFFFF: an unsigned quotient
above 32 bits, or a signed one outside the i32 range, went through.
Do signed divisions in 64 bits with a sign-extended divisor, checked
for i64::MIN / -1, and report overflow (V set, operands unchanged)
whenever the quotient doesn't fit in 32 bits.
Signed-off-by: Benjamin Herrenschmidt <benh@kernel.crashing.org>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
DIVS.L of $80000000 by -1 in the 32-bit form used a native i32 division causes a panics: "attempt to divide with overflow".
It takes the emulator down. A program feeding edge cases to the Toolbox fixed-point routines hit this on a Mac II with System 4.1 (among others).
While there:
Do signed divisions in 64 bits with a sign-extended divisor, checked for i64::MIN / -1, and report overflow (V set, operands unchanged) whenever the quotient doesn't fit in 32 bits.
Note: This was mostly found by AI after debugging a crash and the fix written by AI with a bit of guidance and review from me.