From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([140.186.70.92]:50142) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Rpm9S-00048K-HO for qemu-devel@nongnu.org; Tue, 24 Jan 2012 14:35:31 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1Rpm9P-0004lY-QR for qemu-devel@nongnu.org; Tue, 24 Jan 2012 14:35:30 -0500 Received: from mail-bk0-f45.google.com ([209.85.214.45]:33663) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Rpm9P-0004lE-LH for qemu-devel@nongnu.org; Tue, 24 Jan 2012 14:35:27 -0500 Received: by bkbzu17 with SMTP id zu17so2068318bkb.4 for ; Tue, 24 Jan 2012 11:35:24 -0800 (PST) From: Vasily Khoruzhick Date: Tue, 24 Jan 2012 22:32:30 +0300 Message-Id: <1327433550-20827-1-git-send-email-anarsoul@gmail.com> In-Reply-To: <1327433142.17939.0.camel@anarsoul-laptop.lan> References: <1327433142.17939.0.camel@anarsoul-laptop.lan> Subject: [Qemu-devel] [PATCH v2] pxa2xx_lcd: SRAM is valid location for the framebuffer List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Peter Maydell , Andrzej Zaborowski , "qemu-devel@nongnu.org" Cc: Vasily Khoruzhick Signed-off-by: Vasily Khoruzhick --- v2: fix descptr validation hw/pxa2xx_lcd.c | 13 +++++++++---- 1 files changed, 9 insertions(+), 4 deletions(-) diff --git a/hw/pxa2xx_lcd.c b/hw/pxa2xx_lcd.c index 4e9f7b4..de0fa48 100644 --- a/hw/pxa2xx_lcd.c +++ b/hw/pxa2xx_lcd.c @@ -308,9 +308,12 @@ static void pxa2xx_descriptor_load(PXA2xxLCDState *s) } else descptr = s->dma_ch[i].descriptor; - if (!(descptr >= PXA2XX_SDRAM_BASE && descptr + - sizeof(desc) <= PXA2XX_SDRAM_BASE + ram_size)) + if (!((descptr >= PXA2XX_SDRAM_BASE && descptr + + sizeof(desc) <= PXA2XX_SDRAM_BASE + ram_size) || + (descptr >= PXA2XX_INTERNAL_BASE && descptr + + sizeof(desc) <= PXA2XX_INTERNAL_BASE + PXA2XX_INTERNAL_SIZE))) { continue; + } cpu_physical_memory_read(descptr, (void *)&desc, sizeof(desc)); s->dma_ch[i].descriptor = tswap32(desc.fdaddr); @@ -830,8 +833,10 @@ static void pxa2xx_update_display(void *opaque) continue; } fbptr = s->dma_ch[ch].source; - if (!(fbptr >= PXA2XX_SDRAM_BASE && - fbptr <= PXA2XX_SDRAM_BASE + ram_size)) { + if (!((fbptr >= PXA2XX_SDRAM_BASE && + fbptr <= PXA2XX_SDRAM_BASE + ram_size) || + (fbptr >= PXA2XX_INTERNAL_BASE && + fbptr <= PXA2XX_INTERNAL_BASE + PXA2XX_INTERNAL_SIZE))) { pxa2xx_dma_ber_set(s, ch); continue; } -- 1.7.8.4