Re: Signed divides vs shifts (Re: [Security] /dev/urandom uses uninit bytes, leaks user data)

From: Al Viro
Date: Mon Dec 17 2007 - 13:24:22 EST


On Mon, Dec 17, 2007 at 06:55:57PM +0100, Eric Dumazet wrote:

> long *mid(long *a, long *b)
> {
> return ((a - b) / 2 + a);
> }

... is not actually a middle (you'd want b-a, not a-b there), but anyway

> It gave :
> mid:
> movq %rdi, %rdx
> subq %rsi, %rdx
> sarq $3, %rdx
> movq %rdx, %rax
> shrq $63, %rax
> addq %rdx, %rax
> sarq %rax
> leaq (%rdi,%rax,8), %rax
> ret
>
> while
>
> long *mid(long *a, long *b)
> {
> return ((a - b) / 2u + a);
> }

... undefined behaviour if a < b

> and while :
>
> long *mid(long *a, long *b)
> {
> return (((unsigned long)(a - b)) / 2 + a);
> }

undefined behaviour, again.
--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/