All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] target/ppc: Validate HTABMASK and reserved bits in SDR1 for 32-bit mode
@ 2026-08-07  9:17 sesame_h
  2026-08-11 13:17 ` Chinmay Rath
  0 siblings, 1 reply; 5+ messages in thread
From: sesame_h @ 2026-08-07  9:17 UTC (permalink / raw)
  To: qemu-devel
  Cc: qemu-ppc, npiggin, adityag, milesg, harshpb, rathc, Minhang Zhang

From: Minhang Zhang <zhangminhang@kylinos.cn>

ppc_store_sdr1() had validation for 64-bit SDR1 values but lacked
corresponding checks for the 32-bit case.  According to the Power ISA,
in 32-bit mode SDR1 bits 16-22 are reserved (must be zero) and
HTABMASK (bits 23-31) must consist of a consecutive string of
1-bits starting from the LSB, i.e., be of the form 2^n-1.

Add checks to reject invalid HTABMASK values and log a guest error
for non-zero reserved bits, following the same pattern used by the
existing 64-bit validation.

Signed-off-by: Minhang Zhang <zhangminhang@kylinos.cn>
---
 target/ppc/mmu_common.c | 18 ++++++++++++++++--
 1 file changed, 16 insertions(+), 2 deletions(-)

diff --git a/target/ppc/mmu_common.c b/target/ppc/mmu_common.c
index 2499e61..59e8324 100644
--- a/target/ppc/mmu_common.c
+++ b/target/ppc/mmu_common.c
@@ -57,9 +57,23 @@ void ppc_store_sdr1(CPUPPCState *env, target_ulong value)
                      " stored in SDR1", htabsize);
             return;
         }
-    }
+    } else
 #endif /* defined(TARGET_PPC64) */
-    /* FIXME: Should check for valid HTABMASK values in 32-bit case */
+    {
+        target_ulong htabmask = value & SDR_32_HTABMASK;
+        if (value & 0x007F0000UL) {
+            qemu_log_mask(LOG_GUEST_ERROR,
+                          "Invalid SDR1: reserved bits 0x" TARGET_FMT_lx
+                          " set\n", value & 0x007F0000UL);
+            value &= ~0x007F0000UL;
+        }
+        if ((htabmask & (htabmask + 1)) != 0) {
+            qemu_log_mask(LOG_GUEST_ERROR,
+                          "Invalid HTABMASK 0x" TARGET_FMT_lx
+                          " in SDR1 (must be of form 2^n-1)\n", htabmask);
+            return;
+        }
+    }
     env->spr[SPR_SDR1] = value;
 }
 
-- 
2.43.0



^ permalink raw reply related	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2026-08-14  8:30 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-07  9:17 [PATCH] target/ppc: Validate HTABMASK and reserved bits in SDR1 for 32-bit mode sesame_h
2026-08-11 13:17 ` Chinmay Rath
2026-08-11 13:21   ` Chinmay Rath
2026-08-14  3:06     ` sesame_h
2026-08-14  8:29       ` Chinmay Rath

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.