From: Igor Mammedov <imammedo@redhat.com>
To: qemu-devel@nongnu.org
Cc: peter.maydell@linaro.org, leif.lindholm@oss.qualcomm.com,
eauger@redhat.com
Subject: [PATCH 5/6] sbsa-gwdt: don't arm timer for compare values above INT64_MAX
Date: Wed, 2 Sep 2026 14:26:45 +0200 [thread overview]
Message-ID: <20260902122646.2848464-6-imammedo@redhat.com> (raw)
In-Reply-To: <20260902122646.2848464-1-imammedo@redhat.com>
QEMU timer subsystem uses int64_t, so a WCV value with bit 63 set
would overflow and cause the timer to fire immediately. The SBSA
spec defines WCV as an unsigned 64-bit compare value, so such
values are valid per spec and represent far-future deadlines
(however unpractical).
The current code is not affected: WCV writes don't reschedule the
timer yet, so a guest-supplied compare value never reaches the
timer API. The follow-up patch ("sbsa-gwdt: reschedule timer on
direct WCV load") changes that, at which point an out-of-range WCV
would overflow the timer. For example, Windows in GTDT mode writes
WCV in two 32-bit halves while the watchdog is running:
sbsa-gwdt_control_write [0x8] <- 0xffffffff # WOR (~4 sec)
sbsa-gwdt_control_write [0x0] <- 0x1 # WCS enable
sbsa-gwdt_control_write [0x14] <- 0xffffffff # WCVU (intermediate)
sbsa-gwdt_control_write [0x10] <- 0xa906ca28 # WCVL
sbsa-gwdt_control_write [0x14] <- 0xecb1 # WCVU (final)
The intermediate WCVU write (0xffffffff) yields a WCV above
INT64_MAX; once WCV writes arm the timer, this overflows QEMU's
signed timer and fires immediately -- triggering WS0 => WS1 =>
reboot before the final WCVU write lands.
Add the guard first, before the WCV rescheduling patch, so the
tree stays bisectable. Instead of arming the timer with an
unsupported deadline, leave it disarmed. This reuses
hw/timer/sse-timer.c:sse_set_timer() (commit 0b8ceee822
"hw/timer/sse-timer: Model the SSE Subsystem System Timer").
Introduce a sbsa_gwdt_set_timer() helper for this and route the
WOR-based timeout through it.
Signed-off-by: Igor Mammedov <imammedo@redhat.com>
---
hw/watchdog/sbsa_gwdt.c | 18 +++++++++++++++++-
1 file changed, 17 insertions(+), 1 deletion(-)
diff --git a/hw/watchdog/sbsa_gwdt.c b/hw/watchdog/sbsa_gwdt.c
index 1211f1ca65..0a1d981072 100644
--- a/hw/watchdog/sbsa_gwdt.c
+++ b/hw/watchdog/sbsa_gwdt.c
@@ -99,6 +99,22 @@ static uint64_t sbsa_gwdt_read(void *opaque, hwaddr addr, unsigned int size)
return ret;
}
+static void sbsa_gwdt_set_timer(SBSA_GWDTState *s, uint64_t deadline)
+{
+ /*
+ * WCV is an unsigned 64-bit compare value, but QEMUTimer stores the
+ * expiry as a signed int64_t. A deadline with bit 63 set would be seen
+ * as already expired and fire the watchdog immediately. Such a deadline
+ * is unreachable within any guest runtime, so treat it as "never" and
+ * leave the timer disarmed instead.
+ */
+ if (deadline <= INT64_MAX) {
+ timer_mod(s->timer, deadline);
+ } else {
+ timer_del(s->timer);
+ }
+}
+
static void sbsa_gwdt_wor_update_timer(SBSA_GWDTState *s, WdtRefreshType rtype)
{
uint64_t timeout = 0;
@@ -129,7 +145,7 @@ static void sbsa_gwdt_wor_update_timer(SBSA_GWDTState *s, WdtRefreshType rtype)
s->wcvu = timeout >> 32;
s->wcvl = timeout;
- timer_mod(s->timer, timeout);
+ sbsa_gwdt_set_timer(s, timeout);
}
static void sbsa_gwdt_rwrite(void *opaque, hwaddr offset, uint64_t data,
--
2.52.0
next prev parent reply other threads:[~2026-09-02 12:28 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-02 12:26 [PATCH 0/6] sbsa-gwdt cleanup and fixes Igor Mammedov
2026-09-02 12:26 ` [PATCH 1/6] sbsa-gwdt: reduce code ident Igor Mammedov
2026-09-08 14:28 ` Peter Maydell
2026-09-08 14:47 ` Igor Mammedov
2026-09-02 12:26 ` [PATCH 2/6] arm: gwdt: consolidate clear WS0 and WS1 on explicit refresh Igor Mammedov
2026-09-08 14:34 ` Peter Maydell
2026-09-02 12:26 ` [PATCH 3/6] arm: gwdt: simplify WCV update condition Igor Mammedov
2026-09-08 14:49 ` Peter Maydell
2026-09-02 12:26 ` [PATCH 4/6] sbsa-gwdt: rename sbsa_gwdt_update_timer() to sbsa_gwdt_wor_update_timer() Igor Mammedov
2026-09-08 14:56 ` Peter Maydell
2026-09-02 12:26 ` Igor Mammedov [this message]
2026-09-08 14:57 ` [PATCH 5/6] sbsa-gwdt: don't arm timer for compare values above INT64_MAX Peter Maydell
2026-09-02 12:26 ` [PATCH 6/6] sbsa-gwdt: reschedule timer on direct WCV load Igor Mammedov
2026-09-08 14:57 ` Peter Maydell
2026-09-08 15:08 ` [PATCH 0/6] sbsa-gwdt cleanup and fixes Peter Maydell
2026-09-09 8:17 ` Igor Mammedov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260902122646.2848464-6-imammedo@redhat.com \
--to=imammedo@redhat.com \
--cc=eauger@redhat.com \
--cc=leif.lindholm@oss.qualcomm.com \
--cc=peter.maydell@linaro.org \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.