x86-64 strncpy: Properly handle the length parameter [BZ# 29839]

Message ID 20221202003602.358708-1-hjl.tools@gmail.com
State Committed
Commit e5672763c44f16ddbc42809f5def7c6a962602bd
Headers
Series x86-64 strncpy: Properly handle the length parameter [BZ# 29839] |

Commit Message

H.J. Lu Dec. 2, 2022, 12:36 a.m. UTC
  On x32, the size_t parameter may be passed in the lower 32 bits of a
64-bit register with the non-zero upper 32 bits.  The string/memory
functions written in assembly can only use the lower 32 bits of a
64-bit register as length or must clear the upper 32 bits before using
the full 64-bit register for length.

This pach fixes strncpy for x32.  Tested on x86-64 and x32.  On x86-64,
libc.so is the same with and without the fix.
---
 sysdeps/x86_64/multiarch/strncpy-avx2.S | 4 ++++
 sysdeps/x86_64/multiarch/strncpy-evex.S | 4 ++++
 2 files changed, 8 insertions(+)
  

Comments

Noah Goldstein Dec. 2, 2022, 1:38 a.m. UTC | #1
On Thu, Dec 1, 2022 at 4:36 PM H.J. Lu <hjl.tools@gmail.com> wrote:
>
> On x32, the size_t parameter may be passed in the lower 32 bits of a
> 64-bit register with the non-zero upper 32 bits.  The string/memory
> functions written in assembly can only use the lower 32 bits of a
> 64-bit register as length or must clear the upper 32 bits before using
> the full 64-bit register for length.
>
> This pach fixes strncpy for x32.  Tested on x86-64 and x32.  On x86-64,
> libc.so is the same with and without the fix.
> ---
>  sysdeps/x86_64/multiarch/strncpy-avx2.S | 4 ++++
>  sysdeps/x86_64/multiarch/strncpy-evex.S | 4 ++++
>  2 files changed, 8 insertions(+)
>
> diff --git a/sysdeps/x86_64/multiarch/strncpy-avx2.S b/sysdeps/x86_64/multiarch/strncpy-avx2.S
> index e9afd8fbed..3e6350ce4a 100644
> --- a/sysdeps/x86_64/multiarch/strncpy-avx2.S
> +++ b/sysdeps/x86_64/multiarch/strncpy-avx2.S
> @@ -52,6 +52,10 @@
>
>         .section SECTION(.text), "ax", @progbits
>  ENTRY(STRNCPY)
> +# ifdef __ILP32__
> +       /* Clear the upper 32 bits.  */
> +       movl    %edx, %edx
> +# endif
>         /* Filter zero length strings and very long strings.  Zero
>            length strings just return, very long strings are handled by
>            just running rep stos{b|l} to zero set (which will almost
> diff --git a/sysdeps/x86_64/multiarch/strncpy-evex.S b/sysdeps/x86_64/multiarch/strncpy-evex.S
> index 49eaf4cbd9..dec8cccc2b 100644
> --- a/sysdeps/x86_64/multiarch/strncpy-evex.S
> +++ b/sysdeps/x86_64/multiarch/strncpy-evex.S
> @@ -80,6 +80,10 @@
>
>         .section SECTION(.text), "ax", @progbits
>  ENTRY(STRNCPY)
> +# ifdef __ILP32__
> +       /* Clear the upper 32 bits.  */
> +       movl    %edx, %edx
> +# endif
>         /* Filter zero length strings and very long strings.  Zero
>            length strings just return, very long strings are handled by
>            just running rep stos{b|l} to zero set (which will almost
> --
> 2.38.1
>

LGTM.

Reviewed-by: Noah Goldstein <goldstein.w.n@gmail.com>
  

Patch

diff --git a/sysdeps/x86_64/multiarch/strncpy-avx2.S b/sysdeps/x86_64/multiarch/strncpy-avx2.S
index e9afd8fbed..3e6350ce4a 100644
--- a/sysdeps/x86_64/multiarch/strncpy-avx2.S
+++ b/sysdeps/x86_64/multiarch/strncpy-avx2.S
@@ -52,6 +52,10 @@ 
 
 	.section SECTION(.text), "ax", @progbits
 ENTRY(STRNCPY)
+# ifdef __ILP32__
+	/* Clear the upper 32 bits.  */
+	movl	%edx, %edx
+# endif
 	/* Filter zero length strings and very long strings.  Zero
 	   length strings just return, very long strings are handled by
 	   just running rep stos{b|l} to zero set (which will almost
diff --git a/sysdeps/x86_64/multiarch/strncpy-evex.S b/sysdeps/x86_64/multiarch/strncpy-evex.S
index 49eaf4cbd9..dec8cccc2b 100644
--- a/sysdeps/x86_64/multiarch/strncpy-evex.S
+++ b/sysdeps/x86_64/multiarch/strncpy-evex.S
@@ -80,6 +80,10 @@ 
 
 	.section SECTION(.text), "ax", @progbits
 ENTRY(STRNCPY)
+# ifdef __ILP32__
+	/* Clear the upper 32 bits.  */
+	movl	%edx, %edx
+# endif
 	/* Filter zero length strings and very long strings.  Zero
 	   length strings just return, very long strings are handled by
 	   just running rep stos{b|l} to zero set (which will almost