idtree: fix right shift of signed ints, crash on large ids on AIX
authorRusty Russell <rusty@rustcorp.com.au>
Tue, 5 Oct 2010 02:36:19 +0000 (13:06 +1030)
committerRusty Russell <rusty@rustcorp.com.au>
Wed, 6 Oct 2010 08:31:09 +0000 (08:31 +0000)
Right-shifting signed integers in undefined; indeed it seems that on
AIX with their compiler, doing a 30-bit shift on (INT_MAX-200) gives
0, not 1 as we might expect.

The obvious fix is to make id and oid unsigned: l (level count) is also
logically unsigned.

(Note: Samba doesn't generally get to ids > 1 billion, but ctdb does)

Reported-by: Chris Cowan <cc@us.ibm.com>
Signed-off-by: Rusty Russell <rusty@rustcorp.com.au>
Autobuild-User: Rusty Russell <rusty@samba.org>
Autobuild-Date: Wed Oct  6 08:31:09 UTC 2010 on sn-devel-104

lib/util/idtree.c

index c14796101a2926c4713c07a250754801a5b1498b..6611992a25ff887fbfe1340e139fb99d92f7cff6 100644 (file)
@@ -105,7 +105,7 @@ static int sub_alloc(struct idr_context *idp, void *ptr, int *starting_id)
        int n, m, sh;
        struct idr_layer *p, *pn;
        struct idr_layer *pa[MAX_LEVEL];
-       int l, id, oid;
+       unsigned int l, id, oid;
        uint32_t bm;
 
        memset(pa, 0, sizeof(pa));