@samitouri / QOSamiQemu / commits / 0103cb1cd1

target/s390x: Fix DR/D INT64_MIN / -1 host crash

helper_divs32() divides the 64-bit dividend by the 32-bit divisor as a 64-bit host operation, guarding only against a zero divisor. INT64_MIN / -1 therefore overflows the host division before the representability check runs; on hosts that trap this, QEMU is killed with SIGFPE instead of raising the fixed-point-divide exception the guest expects: qemu-s390x: QEMU internal SIGFPE {code=INTDIV, addr=...} helper_divs64() already guards the same case; add the missing check to helper_divs32(). Reported-by: Christian Borntraeger <borntraeger@linux.ibm.com> Fixes: b4e2bd3563af ("target-s390: Send signals for divide") Cc: qemu-stable@nongnu.org Signed-off-by: Ilya Leoshkevich <iii@linux.ibm.com> Reviewed-by: Richard Henderson <richard.henderson@linaro.org> Link: https://lore.kernel.org/qemu-devel/20260714190351.337923-2-iii@linux.ibm.com Signed-off-by: Eric Farman <farman@linux.ibm.com>

Ilya Leoshkevich committed Jul 14, 2026 at 21:02 UTC 0103cb1cd175a070f52ed0ca4fe0712c2ba2befc
1 file changed +2 -1
target/s390x/tcg/int_helper.c
+2 -1
@@ -39,7 +39,8 @@ uint64_t HELPER(divs32)(CPUS390XState *env, int64_t a, int64_t b64)
39 int32_t b = b64;
40 int64_t q, r;
41
42 - if (b == 0) {
42 + /* Catch divide by zero, and non-representable quotient (MIN / -1). */
43 + if (b == 0 || (b == -1 && a == (1ll << 63))) {
44 tcg_s390_program_interrupt(env, PGM_FIXPT_DIVIDE, GETPC());
45 }
46