From: Ilya Leoshkevich Date: Tue, 4 Jul 2023 08:12:31 +0000 (+0200) Subject: target/s390x: Fix relative long instructions with large offsets X-Git-Tag: v8.1.0-rc0~18^2~13 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=349372ff9e3e7c047e258383f061a8617f66adc3;p=thirdparty%2Fqemu.git target/s390x: Fix relative long instructions with large offsets The expression "imm * 2" in gen_ri2() can wrap around if imm is large enough. Fix by casting imm to int64_t, like it's done in disas_jdest(). Fixes: e8ecdfeb30f0 ("Fix EXECUTE of relative branches") Signed-off-by: Ilya Leoshkevich Reviewed-by: David Hildenbrand Message-Id: <20230704081506.276055-8-iii@linux.ibm.com> Signed-off-by: Thomas Huth --- diff --git a/target/s390x/tcg/translate.c b/target/s390x/tcg/translate.c index a6079ab7b4f..6661b27efa4 100644 --- a/target/s390x/tcg/translate.c +++ b/target/s390x/tcg/translate.c @@ -5794,7 +5794,7 @@ static TCGv gen_ri2(DisasContext *s) disas_jdest(s, i2, is_imm, imm, ri2); if (is_imm) { - ri2 = tcg_constant_i64(s->base.pc_next + imm * 2); + ri2 = tcg_constant_i64(s->base.pc_next + (int64_t)imm * 2); } return ri2;