From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:43584) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Wkyxy-0005NL-Bq for qemu-devel@nongnu.org; Thu, 15 May 2014 12:57:17 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1Wkyxr-0002hJ-IK for qemu-devel@nongnu.org; Thu, 15 May 2014 12:57:10 -0400 Received: from mail-wi0-x22c.google.com ([2a00:1450:400c:c05::22c]:52000) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1Wkyxr-0002gy-C4 for qemu-devel@nongnu.org; Thu, 15 May 2014 12:57:03 -0400 Received: by mail-wi0-f172.google.com with SMTP id hi2so10162952wib.5 for ; Thu, 15 May 2014 09:57:02 -0700 (PDT) Sender: Paolo Bonzini From: Paolo Bonzini Date: Thu, 15 May 2014 18:56:53 +0200 Message-Id: <1400173016-27214-1-git-send-email-pbonzini@redhat.com> Subject: [Qemu-devel] [PATCH 0/3] target-i386: fix CPL computation List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Cc: kevin@koconnor.net CS.RPL is not equal to the CPL in the few instructions between setting CR0.PE and reloading CS. We get this right in the common case, because writes to CR0 do not modify the CPL, but it would not be enough if an SMI comes exactly during that brief period. So this patch fixes the CPL to come from SS.DPL instead, which requires a couple changes to make access rights correct for VM86 mode, and to override the CPL to CS.RPL during task switches (more details in patch 2). Tested with FreeDOS and kvm-unit-tests. Paolo Bonzini (3): target-i386: fix segment flags for SMM and VM86 mode target-i386: prepare CPL checks for next patch target-i386: get CPL from SS.DPL target-i386/cpu.h | 8 +++----- target-i386/kvm.c | 2 +- target-i386/machine.c | 8 ++++++++ target-i386/seg_helper.c | 27 ++++++++++++--------------- target-i386/smm_helper.c | 24 ++++++++++++++++++------ 5 files changed, 42 insertions(+), 27 deletions(-) -- 1.8.3.1