From: Peter Maydell <peter.maydell@linaro.org>
To: qemu-devel@nongnu.org
Subject: [PULL 03/11] target/arm: PSTATE.PAN should not clear exec bits
Date: Mon, 6 Apr 2020 11:11:57 +0100 [thread overview]
Message-ID: <20200406101205.23027-4-peter.maydell@linaro.org> (raw)
In-Reply-To: <20200406101205.23027-1-peter.maydell@linaro.org>
Our implementation of the PSTATE.PAN bit incorrectly cleared all
access permission bits for privileged access to memory which is
user-accessible. It should only affect the privileged read and write
permissions; execute permission is dealt with via XN/PXN instead.
Fixes: 81636b70c226dc27d7ebc8d
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-id: 20200330170651.20901-1-peter.maydell@linaro.org
---
target/arm/helper.c | 6 ++++--
1 file changed, 4 insertions(+), 2 deletions(-)
diff --git a/target/arm/helper.c b/target/arm/helper.c
index 163c91a1ccd..ed7eb8ab54e 100644
--- a/target/arm/helper.c
+++ b/target/arm/helper.c
@@ -10025,9 +10025,11 @@ static int get_S1prot(CPUARMState *env, ARMMMUIdx mmu_idx, bool is_aa64,
prot_rw = user_rw;
} else {
if (user_rw && regime_is_pan(env, mmu_idx)) {
- return 0;
+ /* PAN forbids data accesses but doesn't affect insn fetch */
+ prot_rw = 0;
+ } else {
+ prot_rw = simple_ap_to_rw_prot_is_user(ap, false);
}
- prot_rw = simple_ap_to_rw_prot_is_user(ap, false);
}
if (ns && arm_is_secure(env) && (env->cp15.scr_el3 & SCR_SIF)) {
--
2.20.1
next prev parent reply other threads:[~2020-04-06 10:20 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-04-06 10:11 [PULL 00/11] target-arm queue Peter Maydell
2020-04-06 10:11 ` [PULL 01/11] target/arm: don't expose "ieee_half" via gdbstub Peter Maydell
2020-04-06 10:11 ` [PULL 02/11] hw/arm/collie: Put StrongARMState* into a CollieMachineState struct Peter Maydell
2020-04-06 10:11 ` Peter Maydell [this message]
2020-04-06 10:11 ` [PULL 04/11] target/arm: Remove obsolete TODO note from get_phys_addr_lpae() Peter Maydell
2020-04-06 10:11 ` [PULL 05/11] hw/gpio/aspeed_gpio.c: Don't directly include assert.h Peter Maydell
2020-04-06 10:12 ` [PULL 06/11] dump: Fix writing of ELF section Peter Maydell
2020-04-06 10:12 ` [PULL 07/11] dma/xlnx-zdma: Remove comment Peter Maydell
2020-04-06 10:12 ` [PULL 08/11] dma/xlnx-zdma: Populate DBG0.CMN_BUF_FREE Peter Maydell
2020-04-06 10:12 ` [PULL 09/11] dma/xlnx-zdma: Clear DMA_DONE when halting Peter Maydell
2020-04-06 10:12 ` [PULL 10/11] dma/xlnx-zdma: Advance the descriptor address when stopping Peter Maydell
2020-04-06 10:12 ` [PULL 11/11] dma/xlnx-zdma: Reorg to fix CUR_DSCR Peter Maydell
2020-04-06 12:52 ` [PULL 00/11] target-arm queue Peter Maydell
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20200406101205.23027-4-peter.maydell@linaro.org \
--to=peter.maydell@linaro.org \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.