From b80217784f38be4737b3748ebcf68e05a5bac1af Mon Sep 17 00:00:00 2001 From: Tomasz Leman Date: Fri, 2 Oct 2026 13:22:06 +0200 Subject: [PATCH] ipc4: header: shift notification magic values as unsigned SOF_IPC4_NOTIFY_MODULE_EVENTID_ALSA_MAGIC_VAL and SOF_IPC4_NOTIFY_MODULE_EVENTID_COMPR_MAGIC_VAL are defined as (uint32_t)(0xA15A << 16) and (uint32_t)(0xC0C0 << 16). Both literals have bit 15 set, so the int shift produces a value above INT_MAX before the cast is applied, which is undefined behaviour (UBSan: "left shift of 41306 by 16 places cannot be represented in type 'int'", reported from tdfb_ipc4.c). GCC and clang currently wrap, so the resulting values are correct, but the expression is still ill-formed. Cast to uint32_t before shifting. The macro values are unchanged. Found by the IPC4 libFuzzer campaign with -fsanitize=undefined. Signed-off-by: Tomasz Leman --- src/include/ipc4/header.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/include/ipc4/header.h b/src/include/ipc4/header.h index 6a6eb59d02e5..d72108e7060c 100644 --- a/src/include/ipc4/header.h +++ b/src/include/ipc4/header.h @@ -176,8 +176,8 @@ struct ipc4_message_reply { #define SOF_IPC4_SWITCH_CONTROL_PARAM_ID 200 #define SOF_IPC4_ENUM_CONTROL_PARAM_ID 201 #define SOF_IPC4_BYTES_CONTROL_PARAM_ID 202 -#define SOF_IPC4_NOTIFY_MODULE_EVENTID_ALSA_MAGIC_VAL ((uint32_t)(0xA15A << 16)) -#define SOF_IPC4_NOTIFY_MODULE_EVENTID_COMPR_MAGIC_VAL ((uint32_t)(0xC0C0 << 16)) +#define SOF_IPC4_NOTIFY_MODULE_EVENTID_ALSA_MAGIC_VAL ((uint32_t)0xA15A << 16) +#define SOF_IPC4_NOTIFY_MODULE_EVENTID_COMPR_MAGIC_VAL ((uint32_t)0xC0C0 << 16) /** * struct sof_ipc4_ctrl_value_chan: generic channel mapped value data