[newlib-cygwin] riscv: fix integer wraparound in memcpy

Corinna Vinschen corinna@sourceware.org
Mon Jul 27 08:14:53 GMT 2020


https://sourceware.org/git/gitweb.cgi?p=newlib-cygwin.git;h=123b8065237a3fb644528d3e95216ade336334bd

commit 123b8065237a3fb644528d3e95216ade336334bd
Author: PkmX via Newlib <newlib@sourceware.org>
Date:   Fri Jul 24 19:07:45 2020 +0800

    riscv: fix integer wraparound in memcpy
    
    This patch fixes a bug in RISC-V's memcpy implementation where an
    integer wraparound occurs when src + size < 8 * sizeof(long), causing
    the word-sized copy loop to be incorrectly entered.
    
    Signed-off-by: Chih-Mao Chen <cmchen@andestech.com>

Diff:
---
 newlib/libc/machine/riscv/memcpy.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/newlib/libc/machine/riscv/memcpy.c b/newlib/libc/machine/riscv/memcpy.c
index 07e8e0076..4098f3ab1 100644
--- a/newlib/libc/machine/riscv/memcpy.c
+++ b/newlib/libc/machine/riscv/memcpy.c
@@ -51,9 +51,9 @@ small:
   const long *lb = (const long *)b;
   long *lend = (long *)((uintptr_t)end & ~msk);
 
-  if (unlikely (la < (lend - 8)))
+  if (unlikely (lend - la > 8))
     {
-      while (la < (lend - 8))
+      while (lend - la > 8)
 	{
 	  long b0 = *lb++;
 	  long b1 = *lb++;


More information about the Newlib-cvs mailing list