All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Michael S. Tsirkin" <mst@redhat.com>
To: Marcel Apfelbaum <marcel.a@redhat.com>
Cc: "Peter Maydell" <peter.maydell@linaro.org>,
	"Jan Kiszka" <jan.kiszka@siemens.com>,
	qemu-devel@nongnu.org, "Paolo Bonzini" <pbonzini@redhat.com>,
	"Andreas Färber" <afaerber@suse.de>,
	"Richard Henderson" <rth@twiddle.net>
Subject: Re: [Qemu-devel] [PATCH] exec: limit system memory size
Date: Mon, 4 Nov 2013 12:07:34 +0200	[thread overview]
Message-ID: <20131104100734.GB30026@redhat.com> (raw)
In-Reply-To: <1383558605.2264.22.camel@localhost.localdomain>

On Mon, Nov 04, 2013 at 11:50:05AM +0200, Marcel Apfelbaum wrote:
> On Mon, 2013-11-04 at 08:06 +0200, Michael S. Tsirkin wrote:
> > The page table logic in exec.c assumes
> > that memory addresses are at most TARGET_PHYS_ADDR_SPACE_BITS.
> > 
> > But pci addresses are full 64 bit so if we try to render them ignoring
> > the extra bits, we get strange effects with sections overlapping each
> > other.
> > 
> > To fix, simply limit the system memory size to
> >  1 << TARGET_PHYS_ADDR_SPACE_BITS,
> > pci addresses will be rendered within that.
> > 
> > Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
> > ---
> >  exec.c | 6 +++++-
> >  1 file changed, 5 insertions(+), 1 deletion(-)
> > 
> > diff --git a/exec.c b/exec.c
> > index 030118e..c7a8df5 100644
> > --- a/exec.c
> > +++ b/exec.c
> > @@ -1801,7 +1801,12 @@ void address_space_destroy_dispatch(AddressSpace *as)
> >  static void memory_map_init(void)
> >  {
> >      system_memory = g_malloc(sizeof(*system_memory));
> > -    memory_region_init(system_memory, NULL, "system", INT64_MAX);
> > +
> > +    assert(TARGET_PHYS_ADDR_SPACE_BITS <= 64);
> > +
> > +    memory_region_init(system_memory, NULL, "system",
> > +                       TARGET_PHYS_ADDR_SPACE_BITS == 64 ?
> > +                       UINT64_MAX : (0x1ULL << TARGET_PHYS_ADDR_SPACE_BITS));
> 
> Michael, thanks again for the help.
> 
> I am concerned that we cannot use all the UINT64_MAX
> address space.

Well, exec isn't ready for this, it expects at most
TARGET_PHYS_ADDR_SPACE_BITS.
Fortunately there's no way for CPU to initiate io outside
this area.

So this is another place where device to device IO
would be broken.

> By the way, this patch makes the memory size aligned to page size,
> so the call to register_subpage (the asserted code) is diverted
> to register_multipage that does not have an assert.

I tested with (0x1ULL << TARGET_PHYS_ADDR_SPACE_BITS) - 1
as well, works fine.

> That leads me to another question?
> Maybe the fact that INT64_MAX is not aligned to page size makes
> all the trouble? 

It's not what's causing the trouble, it's merely making
the bug visible since subpage is the only path that actually checks that
sections do not overlap.

> What do you think?
> 
> Regarding this patch:
> Maybe we should to add an assert inside memory_region_init 
> in order to protect all the code that creates memory regions?

To make sure sections don't overlap? Sure. Go for it.

> And also maybe we should add a define MAX_MEMORY_REGION_SIZE
> to be used in all places we want a "maximum size" memory region?
> 
> Thanks,
> Marcel

I think we can't define this in a target independent way really.

> >      address_space_init(&address_space_memory, system_memory, "memory");
> >  
> >      system_io = g_malloc(sizeof(*system_io));
> 
> 

  reply	other threads:[~2013-11-04 10:04 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-11-04  6:06 [Qemu-devel] [PATCH] exec: limit system memory size Michael S. Tsirkin
2013-11-04  6:15 ` Michael S. Tsirkin
2013-11-04  9:50 ` Marcel Apfelbaum
2013-11-04 10:07   ` Michael S. Tsirkin [this message]
2013-11-04 10:54     ` Paolo Bonzini
2013-11-04 11:14       ` Michael S. Tsirkin
2013-11-04 11:22         ` Paolo Bonzini
2013-11-04 12:04           ` Michael S. Tsirkin
2013-11-04 12:11             ` Paolo Bonzini
2013-11-04 12:26 ` Paolo Bonzini

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20131104100734.GB30026@redhat.com \
    --to=mst@redhat.com \
    --cc=afaerber@suse.de \
    --cc=jan.kiszka@siemens.com \
    --cc=marcel.a@redhat.com \
    --cc=pbonzini@redhat.com \
    --cc=peter.maydell@linaro.org \
    --cc=qemu-devel@nongnu.org \
    --cc=rth@twiddle.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.