From mboxrd@z Thu Jan 1 00:00:00 1970 From: malc Subject: Re: [Qemu-devel] [PATCH] memory: use signed arithmetic Date: Wed, 3 Aug 2011 01:15:58 +0400 (MSD) Message-ID: References: <1312318249-7011-1-git-send-email-avi@redhat.com> Mime-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Cc: Anthony Liguori , qemu-devel@nongnu.org, Jan Kiszka , kvm@vger.kernel.org To: Avi Kivity Return-path: Received: from fe02x03-cgp.akado.ru ([77.232.31.165]:58986 "EHLO akado.ru" rhost-flags-OK-OK-OK-FAIL) by vger.kernel.org with ESMTP id S1755189Ab1HBVQL (ORCPT ); Tue, 2 Aug 2011 17:16:11 -0400 In-Reply-To: <1312318249-7011-1-git-send-email-avi@redhat.com> Sender: kvm-owner@vger.kernel.org List-ID: On Tue, 2 Aug 2011, Avi Kivity wrote: > When trying to map an alias of a ram region, where the alias starts at > address A and we map it into address B, and A > B, we had an arithmetic > underflow. Because we use unsigned arithmetic, the underflow converted > into a large number which failed addrrange_intersects() tests. > > The concrete example which triggered this was cirrus vga mapping > the framebuffer at offsets 0xc0000-0xc7fff (relative to the start of > the framebuffer) into offsets 0xa0000 (relative to system addres space > start). > > With our favorite analogy of a windowing system, this is equivalent to > dragging a subwindow off the left edge of the screen, and failing to clip > it into its parent window which is on screen. > > Fix by switching to signed arithmetic. http://stackoverflow.com/questions/3679047/integer-overflow-in-c-standards-and-compilers In other words UB land [..snip..] -- mailto:av1474@comtv.ru