[PATCH] powerpc: Fix VSX register number on __strncpy_power9 [BZ #29197]

Matheus Castanho msc@linux.ibm.com
Tue Jun 7 14:50:50 GMT 2022


Paul E Murphy <murphyp@linux.ibm.com> writes:

> On 6/7/22 9:30 AM, Matheus Castanho via Libc-alpha wrote:
>> __strncpy_power9 initializes VR 18 with zeroes to be used throughout the
>> code, including when zero-padding the destination string. However, the
>> v18 reference was mistakenly being used for stxv and stxvl, which take a
>> VSX vector as operand. The code ended up using the uninitialized VSR 18
>> register by mistake.
>> Both occurrences have been changed to use the proper VSX number for VR 18
>> (i.e. VSR 50).
>> Tested on powerpc, powerpc64 and powerpc64le.
>> Suggested-by: Kewen Lin <linkw@gcc.gnu.org>
>> ---
>>   sysdeps/powerpc/powerpc64/le/power9/strncpy.S | 4 ++--
>>   1 file changed, 2 insertions(+), 2 deletions(-)
>> diff --git a/sysdeps/powerpc/powerpc64/le/power9/strncpy.S
>> b/sysdeps/powerpc/powerpc64/le/power9/strncpy.S
>> index ae23161316..deb94671cc 100644
>> --- a/sysdeps/powerpc/powerpc64/le/power9/strncpy.S
>> +++ b/sysdeps/powerpc/powerpc64/le/power9/strncpy.S
>> @@ -352,7 +352,7 @@ L(zero_padding_loop):
>>   	cmpldi	cr6,r5,16	/* Check if length was reached.  */
>>   	ble	cr6,L(zero_padding_end)
>> -	stxv	v18,0(r11)
>> +	stxv	32+v18,0(r11)
>>   	addi	r11,r11,16
>>   	addi	r5,r5,-16
>> @@ -360,7 +360,7 @@ L(zero_padding_loop):
>>   L(zero_padding_end):
>>   	sldi	r10,r5,56	/* stxvl wants size in top 8 bits  */
>> -	stxvl	v18,r11,r10	/* Partial store  */
>> +	stxvl	32+v18,r11,r10	/* Partial store  */
>>   	blr
>>   	.align	4
>
> LGTM, will you also backport this as needed too?

Yes, that's the idea. Ideally to all affected releases.

> If this wasn't caught by a test-case, I think adding one would be desirable too.

string/test-strncpy.c already checks if the bytes beyond the terminating
NUL have been properly set [1]. But the issue is that vs18 is also zero
when the test starts, so even with the bug the string ends up in the
expected state.

To actually trigger the bug we would have to fill vs18 with something !=
NUL before calling __strncpy_power9 (as is done in the reproducer). But
since this is very Power-specific and the test is generic, I'm not sure
what's the best way forward.

--
Matheus Castanho


More information about the Libc-alpha mailing list