PR #20397 opened by Martin Storsjö (mstorsjo)
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20397
Patch URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20397.patch

If we're invoked with range == UINT_MAX, we end up doing
"rnd() % (UINT_MAX + 1)", which is equal to "rnd() % 0". On
arm (on all platforms) and on MSVC i386, this ends up crashing
at runtime.

This fixes the crash.


From 8a5cb3b0965c8216eb6dd8b213da3e8b9a0b0fa3 Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Martin=20Storsj=C3=B6?= <[email protected]>
Date: Tue, 2 Sep 2025 14:10:28 +0300
Subject: [PATCH] cehckasm: sw_ops: Avoid division by zero

If we're invoked with range == UINT_MAX, we end up doing
"rnd() % (UINT_MAX + 1)", which is equal to "rnd() % 0". On
arm (on all platforms) and on MSVC i386, this ends up crashing
at runtime.

This fixes the crash.
---
 tests/checkasm/sw_ops.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tests/checkasm/sw_ops.c b/tests/checkasm/sw_ops.c
index 35ade0c751..6f57ada32a 100644
--- a/tests/checkasm/sw_ops.c
+++ b/tests/checkasm/sw_ops.c
@@ -80,7 +80,7 @@ static void fill32f(float *line, int num, unsigned range)
 static void fill32(uint32_t *line, int num, unsigned range)
 {
     for (int i = 0; i < num; i++)
-        line[i] = range ? rnd() % (range + 1) : rnd();
+        line[i] = (range && range < UINT32_MAX) ? rnd() % (range + 1) : rnd();
 }
 
 static void fill16(uint16_t *line, int num, unsigned range)
-- 
2.49.1

_______________________________________________
ffmpeg-devel mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to