diff options
author | Mark Dickinson <dickinsm@gmail.com> | 2009-12-02 17:33:41 (GMT) |
---|---|---|
committer | Mark Dickinson <dickinsm@gmail.com> | 2009-12-02 17:33:41 (GMT) |
commit | 34398184eb241dcc42ae0ed117c8be6e7a445495 (patch) | |
tree | 7a8bf408c30d5f219661c09902d1452503d5fc64 | |
parent | 5a73ff81f1caf8f7c13c459ac450f33695d2e626 (diff) | |
download | cpython-34398184eb241dcc42ae0ed117c8be6e7a445495.zip cpython-34398184eb241dcc42ae0ed117c8be6e7a445495.tar.gz cpython-34398184eb241dcc42ae0ed117c8be6e7a445495.tar.bz2 |
Issue #7406: Fix some occurrences of potential signed overflow in int
arithmetic.
-rw-r--r-- | Objects/intobject.c | 9 | ||||
-rw-r--r-- | Python/ceval.c | 8 |
2 files changed, 12 insertions, 5 deletions
diff --git a/Objects/intobject.c b/Objects/intobject.c index dce569a..43dedf2 100644 --- a/Objects/intobject.c +++ b/Objects/intobject.c @@ -461,7 +461,8 @@ int_add(PyIntObject *v, PyIntObject *w) register long a, b, x; CONVERT_TO_LONG(v, a); CONVERT_TO_LONG(w, b); - x = a + b; + /* casts in the line below avoid undefined behaviour on overflow */ + x = (long)((unsigned long)a + b); if ((x^a) >= 0 || (x^b) >= 0) return PyInt_FromLong(x); return PyLong_Type.tp_as_number->nb_add((PyObject *)v, (PyObject *)w); @@ -473,7 +474,8 @@ int_sub(PyIntObject *v, PyIntObject *w) register long a, b, x; CONVERT_TO_LONG(v, a); CONVERT_TO_LONG(w, b); - x = a - b; + /* casts in the line below avoid undefined behaviour on overflow */ + x = (long)((unsigned long)a - b); if ((x^a) >= 0 || (x^~b) >= 0) return PyInt_FromLong(x); return PyLong_Type.tp_as_number->nb_subtract((PyObject *)v, @@ -516,7 +518,8 @@ int_mul(PyObject *v, PyObject *w) CONVERT_TO_LONG(v, a); CONVERT_TO_LONG(w, b); - longprod = a * b; + /* casts in the next line avoid undefined behaviour on overflow */ + longprod = (long)((unsigned long)a * b); doubleprod = (double)a * (double)b; doubled_longprod = (double)longprod; diff --git a/Python/ceval.c b/Python/ceval.c index dd820f2..e5e7046 100644 --- a/Python/ceval.c +++ b/Python/ceval.c @@ -1321,7 +1321,9 @@ PyEval_EvalFrameEx(PyFrameObject *f, int throwflag) register long a, b, i; a = PyInt_AS_LONG(v); b = PyInt_AS_LONG(w); - i = a + b; + /* cast to avoid undefined behaviour + on overflow */ + i = (long)((unsigned long)a + b); if ((i^a) < 0 && (i^b) < 0) goto slow_add; x = PyInt_FromLong(i); @@ -1351,7 +1353,9 @@ PyEval_EvalFrameEx(PyFrameObject *f, int throwflag) register long a, b, i; a = PyInt_AS_LONG(v); b = PyInt_AS_LONG(w); - i = a - b; + /* cast to avoid undefined behaviour + on overflow */ + i = (long)((unsigned long)a - b); if ((i^a) < 0 && (i^~b) < 0) goto slow_sub; x = PyInt_FromLong(i); |