pthread_join() stores the thread's return value (a "void *", i.e.
8 bytes on 64 bit computers) into the address that is passed as second
parameter. However, the entries of thread_data are only normal "int"s,
i.e. only 4 bytes. The additional 4 bytes of the return value clobber
whatever is adjacent on the stack, i.e. other members of the thread_data
array (which will be re-written in the next iteration of the for-loop,
so that nobody noticed this problem), or another other local variable
on the stack for the last iteration. Use "intptr_t" to declare the
thread_data array entries with the correct size.

Fixes: 29f080881601c ("kselftest/arm64: check GCR_EL1 after context switch")
Cc: [email protected]
Signed-off-by: Thomas Huth <[email protected]>
---
 tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c 
b/tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c
index d23f154d3288c..5d9dc8bcfbf55 100644
--- a/tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c
+++ b/tools/testing/selftests/arm64/mte/check_gcr_el1_cswitch.c
@@ -69,7 +69,7 @@ void *execute_thread(void *x)
 int execute_test(pid_t pid)
 {
        pthread_t thread_id[MAX_THREADS];
-       int thread_data[MAX_THREADS];
+       intptr_t thread_data[MAX_THREADS];
 
        for (int i = 0; i < MAX_THREADS; i++)
                pthread_create(&thread_id[i], NULL,
-- 
2.55.0


Reply via email to