From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from 3.mo560.mail-out.ovh.net (3.mo560.mail-out.ovh.net [46.105.58.226]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 587AD39525D for ; Tue, 20 Jan 2026 20:15:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=46.105.58.226 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768940131; cv=none; b=rzcE4jhvmP9HIZAfRM4yIRXQol/sPr9rPYzJQROwuc0nakOKErNpnU9puKyWFVtdZ8K3hHKkfqfJAOuNwxWuekR6QsDC8qEiZGfZFf/8A/2IxAfqUGx6cL/XJfNcLVh1GtPhO9ChZdAdSJJJ/+b5Ylf5XnxdtZnBRLvBQb2FNXw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1768940131; c=relaxed/simple; bh=ZXYoX6Fx6LC7nKBaqd+b3WP6TVgN/JafbEiLuYkvOME=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=YBWeg2xjETOjXF5xsbvGjuwn2R1qm7bIh7RkBfVS5wO4W15b82j84IqvB+RsrztZaehwNkT6+XqUMhZM/Lhv0DQ+jSIlZCoiGb8ewKfnmqYXOyUdmg2HetY9t17zYStCjAd4mGWSOxJGJtMGj//EIvtn/suElVKEPbNWPOjh3YY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=formalgen.com; spf=pass smtp.mailfrom=formalgen.com; dkim=pass (2048-bit key) header.d=formalgen.com header.i=@formalgen.com header.b=k1j+Dawr; arc=none smtp.client-ip=46.105.58.226 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=formalgen.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=formalgen.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=formalgen.com header.i=@formalgen.com header.b="k1j+Dawr" Received: from director3.ghost.mail-out.ovh.net (unknown [10.110.54.231]) by mo560.mail-out.ovh.net (Postfix) with ESMTP id 4dwZZJ1HFJzBNGH for ; Tue, 20 Jan 2026 17:48:55 +0000 (UTC) Received: from ghost-submission-7d8d68f679-jxl6q (unknown [10.111.174.132]) by director3.ghost.mail-out.ovh.net (Postfix) with ESMTPS id 2A0D1C04D9; Tue, 20 Jan 2026 17:48:55 +0000 (UTC) Received: from formalgen.com ([37.59.142.95]) by ghost-submission-7d8d68f679-jxl6q with ESMTPSA id FJOyNwbAb2kJJAAASiHvJA (envelope-from ); Tue, 20 Jan 2026 17:48:55 +0000 Authentication-Results:garm.ovh; auth=pass (GARM-95G001d55a032e-d886-453e-a3fe-1fd5145413e5, BD04578FE93AF9D298F1B82426988FE6DFB30C64) smtp.auth=david.desobry@formalgen.com X-OVh-ClientIp:90.91.42.105 Message-ID: <6d28349e-9912-474d-a750-71488e2fc976@formalgen.com> Date: Tue, 20 Jan 2026 18:48:54 +0100 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] x86/lib: Fix num_digits() signed overflow for INT_MIN To: "H. Peter Anvin" , tglx@kernel.org, mingo@redhat.com, bp@alien8.de, dave.hansen@linux.intel.com Cc: x86@kernel.org, linux-kernel@vger.kernel.org References: <20260120094258.41313-1-david.desobry@formalgen.com> <53DB5B87-BA96-44B1-AE1B-9055CB7B9350@zytor.com> Content-Language: en-US From: David Desobry In-Reply-To: <53DB5B87-BA96-44B1-AE1B-9055CB7B9350@zytor.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-Ovh-Tracer-Id: 13837028382564731867 X-VR-SPAMSTATE: OK X-VR-SPAMSCORE: 0 X-VR-SPAMCAUSE: dmFkZTGEo27Jn4UjiZnICqaMuH+ck/8s+bYNUGFe7IActPzKYYj/enJpIr+9NXkWwN1lI7pd7H8WsQ0O+c5r50Qb739nXX4e65V08gmWBVOn0yvtW8Cc4CylfoDIhJtMWf7Rjv/XWGDN8bDLQDVou5b6/yVbPS5lBrIzO2fdj7uGT5iBkAXysuYmNzYDX5CeA7BGQL5RrxV/Etx1UYaO6YAwCrfv9iBoCyEJvZfEGjjsK5JJb1ui6mFs0FmC/9JBIkU8nNnWGfkMjFk72LBWV9qAkkd4Zxm3gfEZSEcUhbmcrTFSSnTI40vMcDlD40gQuo66K6FzERmA8yh0HSATayrgro6DQjT2Y2ejK2KppccDuBZDoaXxVfZ/7ckQoAGGAwO1PshgiPGUHrqISYXxAzek0OwVy7y6UfqPgSsXufamiaSKdsWNBigSCBXZIIy7aBxKKAYpUqjyv3mkz+of7puyaUpTEak5ViXLEnO7k1tjnJEnBj5w7rclAGXUgcZI+tkxIzEnmlHnhL025zgf6puPzxpu20yP6pj+Dn1RQ2gGKcA8f0i4JpG4LLeaMUht/tyxx+ThUpRLDaoeDMbivvCE770kmTWQvEuwdP9SDGB9e9D+mcNhFjiAANrQ6gcBHgcE4Alhl/82ckh09O4pPu4Cr4BeIWPtE+lFsTK3KjwJye0nSQ DKIM-Signature: a=rsa-sha256; bh=6LCX5kYUq7pVu12YV5CtoS+zAzmOKKASlnVapN0Td/I=; c=relaxed/relaxed; d=formalgen.com; h=From; s=ovhmo-selector-1; t=1768931336; v=1; b=k1j+DawrZXvPRjhrnkbTlPfQ3y7KeEow5Fb8DUexSD7k7Hjbr9STVd6sU2jascIwOglZGsMQ R+JSkjT+kFvZk8G4nzQdbYua/bEb5vJuDLuPWKAIdTnT0w0x+/mGeUPB3sST8nyyuTMAD+XFBkM OGTGCDpYEovItGO7x96tGWVdpSD7s4C/fYzSnbYEUob6Fr9GRu+9QcDKxCXkUqE/TuqiUFXd854 I/XTtzj2ODBLalcZsPg9cnbKwuMkQW+3rQ+nnAd7HmWfyp3yWChNw+phghxmHG4BuyhjKEVCZzt +BEHxxN9dyTKzgNug+Lx88anHn1jLwH7SnQ/SMju8zRbw== Fair point! I've sent a v2 that replaces the loop with a switch statement (using GCC ranges). It's faster, handles INT_MIN properly via an unsigned cast, and I've cleaned up that mobile-submission comment while I was at it. Le 20/01/2026 à 17:23, H. Peter Anvin a écrit : > On January 20, 2026 1:42:58 AM PST, David Desobry wrote: >> In num_digits(), the negation of the input value "val = -val" >> causes undefined behavior when val is INT_MIN, as its absolute >> value cannot be represented as a signed 32-bit integer. >> >> This leads to incorrect results (returning 2 instead of 11). >> By promoting the value to long long before negation, we ensure >> the absolute value is correctly handled. >> >> Signed-off-by: David Desobry >> --- >> arch/x86/lib/misc.c | 7 ++++--- >> 1 file changed, 4 insertions(+), 3 deletions(-) >> >> diff --git a/arch/x86/lib/misc.c b/arch/x86/lib/misc.c >> index 40b81c338ae5..c975db6ccb9f 100644 >> --- a/arch/x86/lib/misc.c >> +++ b/arch/x86/lib/misc.c >> @@ -8,15 +8,16 @@ >> */ >> int num_digits(int val) >> { >> + long long v = val; >> long long m = 10; >> int d = 1; >> >> - if (val < 0) { >> + if (v < 0) { >> d++; >> - val = -val; >> + v = -v; >> } >> >> - while (val >= m) { >> + while (v >= m) { >> m *= 10; >> d++; >> } > That has got to be the dumbest possible implementation of that task, bug or no bug. > > A switch statement would be simpler and faster.