From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:40486) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Vp0Rq-0002Hx-UA for qemu-devel@nongnu.org; Fri, 06 Dec 2013 13:48:27 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1Vp0Rl-0005Sd-Bj for qemu-devel@nongnu.org; Fri, 06 Dec 2013 13:48:22 -0500 Received: from isrv.corpit.ru ([86.62.121.231]:57233) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Vp0Rl-0005I9-4P for qemu-devel@nongnu.org; Fri, 06 Dec 2013 13:48:17 -0500 Message-ID: <52A21BE9.2070201@msgid.tls.msk.ru> Date: Fri, 06 Dec 2013 22:48:09 +0400 From: Michael Tokarev MIME-Version: 1.0 References: <1386334344-24620-1-git-send-email-agraf@suse.de> In-Reply-To: <1386334344-24620-1-git-send-email-agraf@suse.de> Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Subject: Re: [Qemu-devel] [PATCH] x86: only allow real mode to access 32bit without LMA List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Alexander Graf Cc: QEMU Developers 06.12.2013 16:52, Alexander Graf wrote: > When we're running in non-64bit mode with qemu-system-x86_64 we can > still end up with virtual addresses that are above the 32bit boundary > if a segment offset is set up. > > GNU Hurd does exactly that. It sets the segment offset to 0x80000000 and > puts its EIP value to 0x8xxxxxxx to access low memory. > > This doesn't hit us when we enable paging, as there we just mask away the > unused bits. But with real mode, we assume that vaddr == paddr which is > wrong in this case. Real hardware wraps the virtual address around at the > 32bit boundary. So let's do the same. > > This fixes booting GNU Hurd in qemu-system-x86_64 for me. > > Reported-by: Michael Tokarev > Signed-off-by: Alexander Graf > --- > target-i386/helper.c | 6 ++++++ > 1 file changed, 6 insertions(+) > > diff --git a/target-i386/helper.c b/target-i386/helper.c > index 7c196ff..ed965d6 100644 > --- a/target-i386/helper.c > +++ b/target-i386/helper.c > @@ -531,6 +531,12 @@ int cpu_x86_handle_mmu_fault(CPUX86State *env, target_ulong addr, > > if (!(env->cr[0] & CR0_PG_MASK)) { > pte = addr; > +#ifdef TARGET_X86_64 > + if (!(env->hflags & HF_LMA_MASK)) { > + /* Without long mode we can only address 32bits in real mode */ > + pte = (uint32_t)pte; > + } > +#endif > virt_addr = addr & TARGET_PAGE_MASK; > prot = PAGE_READ | PAGE_WRITE | PAGE_EXEC; > page_size = 4096; Tested-by: Michael Tokarev Well, it isn't much of testing, I too just run hurd image and see that it can work in qemu-x86_64 tcg mode, while without this patch it segfaults. Should I apply this to trivial queue? :) Thanks, /mjt