[PATCH] D88798: [flang] Fix heap overflow in Real formatting.

Michael Kruse via Phabricator via llvm-commits llvm-commits at lists.llvm.org
Tue Oct 13 23:23:57 PDT 2020


Meinersbur updated this revision to Diff 298046.
Meinersbur added a comment.

Copy integer part-wise instead of memcpy. memcpy/reinterpret_cast assumed platform endianess.


Repository:
  rG LLVM Github Monorepo

CHANGES SINCE LAST ACTION
  https://reviews.llvm.org/D88798/new/

https://reviews.llvm.org/D88798

Files:
  flang/lib/Evaluate/real.cpp


Index: flang/lib/Evaluate/real.cpp
===================================================================
--- flang/lib/Evaluate/real.cpp
+++ flang/lib/Evaluate/real.cpp
@@ -496,14 +496,25 @@
     }
   } else {
     using B = decimal::BinaryFloatingPointNumber<P>;
-    const auto *value{reinterpret_cast<const B *>(this)};
+    constexpr static const auto bits{word_.bits};
+    typename B::RawType b = word_.ToUInt64();
+    if constexpr (bits > 64) {
+      auto d{word_};
+      for (int i{64}; i < bits; i += 64) {
+        d = d.SHIFTR(64);
+        const typename B::RawType l{d.ToUInt64()};
+        b |= (l << i);
+      }
+    }
+    B value{b};
+
     char buffer[24000]; // accommodate real*16
     decimal::DecimalConversionFlags flags{}; // default: exact representation
     if (minimal) {
       flags = decimal::Minimize;
     }
     auto result{decimal::ConvertToDecimal<P>(buffer, sizeof buffer, flags,
-        static_cast<int>(sizeof buffer), decimal::RoundNearest, *value)};
+        static_cast<int>(sizeof buffer), decimal::RoundNearest, value)};
     const char *p{result.str};
     if (DEREF(p) == '-' || *p == '+') {
       o << *p++;


-------------- next part --------------
A non-text attachment was scrubbed...
Name: D88798.298046.patch
Type: text/x-patch
Size: 1159 bytes
Desc: not available
URL: <http://lists.llvm.org/pipermail/llvm-commits/attachments/20201014/6fb92d84/attachment.bin>


More information about the llvm-commits mailing list