Skip to content

Commit d70ef22

Browse files
Jiri Slabytorvalds
Jiri Slaby
authored andcommitted
futex: futex_wake_op, fix sign_extend32 sign bits
sign_extend32 counts the sign bit parameter from 0, not from 1. So we have to use "11" for 12th bit, not "12". This mistake means we have not allowed negative op and cmp args since commit 30d6e0a ("futex: Remove duplicated code and fix undefined behaviour") till now. Fixes: 30d6e0a ("futex: Remove duplicated code and fix undefined behaviour") Signed-off-by: Jiri Slaby <[email protected]> Cc: Ingo Molnar <[email protected]> Cc: Peter Zijlstra <[email protected]> Cc: Darren Hart <[email protected]> Signed-off-by: Linus Torvalds <[email protected]>
1 parent 51090c5 commit d70ef22

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

kernel/futex.c

+2-2
Original file line numberDiff line numberDiff line change
@@ -1582,8 +1582,8 @@ static int futex_atomic_op_inuser(unsigned int encoded_op, u32 __user *uaddr)
15821582
{
15831583
unsigned int op = (encoded_op & 0x70000000) >> 28;
15841584
unsigned int cmp = (encoded_op & 0x0f000000) >> 24;
1585-
int oparg = sign_extend32((encoded_op & 0x00fff000) >> 12, 12);
1586-
int cmparg = sign_extend32(encoded_op & 0x00000fff, 12);
1585+
int oparg = sign_extend32((encoded_op & 0x00fff000) >> 12, 11);
1586+
int cmparg = sign_extend32(encoded_op & 0x00000fff, 11);
15871587
int oldval, ret;
15881588

15891589
if (encoded_op & (FUTEX_OP_OPARG_SHIFT << 28)) {

0 commit comments

Comments
 (0)