From: Peter Maydell Date: Fri, 22 Jul 2016 12:41:52 +0000 (+0100) Subject: linux-user: Handle brk() attempts with very large sizes X-Git-Tag: v2.7.0-rc2~15^2 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=ef4330c23bb47b97a859dbdbae1c784fd2ca402f;p=thirdparty%2Fqemu.git linux-user: Handle brk() attempts with very large sizes In do_brk(), we were inadvertently truncating the size of a requested brk() from the guest by putting it into an 'int' variable. This meant that we would incorrectly report success back to the guest rather than a failed allocation, typically resulting in the guest then segfaulting. Use abi_ulong instead. This fixes a crash in the '31370.cc' test in the gcc libstdc++ test suite (the test case starts by trying to allocate a very large size and reduces the size until the allocation succeeds). Signed-off-by: Peter Maydell Signed-off-by: Riku Voipio --- diff --git a/linux-user/syscall.c b/linux-user/syscall.c index df6f2a9d0f0..833f853200e 100644 --- a/linux-user/syscall.c +++ b/linux-user/syscall.c @@ -839,7 +839,7 @@ void target_set_brk(abi_ulong new_brk) abi_long do_brk(abi_ulong new_brk) { abi_long mapped_addr; - int new_alloc_size; + abi_ulong new_alloc_size; DEBUGF_BRK("do_brk(" TARGET_ABI_FMT_lx ") -> ", new_brk);