target-sparc: fix 32-bit truncation in fpackfix

This is reported by Coverity. The algorithm description at
ftp://ftp.icm.edu.pl/packages/ggi/doc/hw/sparc/Sparc.pdf suggests
that the 32-bit parts of rs2, after the left shift, is treated
as a 64-bit integer. Bits 32 and above are used to do the
saturating truncation.

Backports commit 12a3567c4099be194b44987ac5d7d65b99bcfab7 from qemu
This commit is contained in:
Paolo Bonzini 2018-02-17 19:08:18 -05:00 committed by Lioncash
parent 272e412fc9
commit 1918761803
No known key found for this signature in database
GPG key ID: 4E3C3CC1031BA9C7

View file

@ -447,7 +447,7 @@ uint32_t helper_fpackfix(uint64_t gsr, uint64_t rs2)
for (word = 0; word < 2; word++) { for (word = 0; word < 2; word++) {
uint32_t val; uint32_t val;
int32_t src = rs2 >> (word * 32); int32_t src = rs2 >> (word * 32);
int64_t scaled = src << scale; int64_t scaled = (int64_t)src << scale;
int64_t from_fixed = scaled >> 16; int64_t from_fixed = scaled >> 16;
val = (from_fixed < -32768 ? -32768 : val = (from_fixed < -32768 ? -32768 :