From: Paolo Bonzini <pbonzini@redhat.com>
To: qemu-devel@nongnu.org
Cc: Peter Crosthwaite <peter.crosthwaite@xilinx.com>
Subject: [Qemu-devel] [PULL 16/22] exec: Respect as_translate_internal length clamp
Date: Tue, 28 Apr 2015 16:40:23 +0200 [thread overview]
Message-ID: <1430232029-9457-17-git-send-email-pbonzini@redhat.com> (raw)
In-Reply-To: <1430232029-9457-1-git-send-email-pbonzini@redhat.com>
From: Peter Crosthwaite <peter.crosthwaite@xilinx.com>
address_space_translate_internal will clamp the *plen length argument
based on the size of the memory region being queried. The iommu walker
logic in addresss_space_translate was ignoring this by discarding the
post fn call value of *plen. Fix by just always using *plen as the
length argument throughout the fn, removing the len local variable.
This fixes a bootloader bug when a single elf section spans multiple
QEMU memory regions.
Signed-off-by: Peter Crosthwaite <peter.crosthwaite@xilinx.com>
Message-Id: <1426570554-15940-1-git-send-email-peter.crosthwaite@xilinx.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
---
exec.c | 6 ++----
1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/exec.c b/exec.c
index 065f5e8..4717928 100644
--- a/exec.c
+++ b/exec.c
@@ -380,7 +380,6 @@ MemoryRegion *address_space_translate(AddressSpace *as, hwaddr addr,
IOMMUTLBEntry iotlb;
MemoryRegionSection *section;
MemoryRegion *mr;
- hwaddr len = *plen;
rcu_read_lock();
for (;;) {
@@ -395,7 +394,7 @@ MemoryRegion *address_space_translate(AddressSpace *as, hwaddr addr,
iotlb = mr->iommu_ops->translate(mr, addr, is_write);
addr = ((iotlb.translated_addr & ~iotlb.addr_mask)
| (addr & iotlb.addr_mask));
- len = MIN(len, (addr | iotlb.addr_mask) - addr + 1);
+ *plen = MIN(*plen, (addr | iotlb.addr_mask) - addr + 1);
if (!(iotlb.perm & (1 << is_write))) {
mr = &io_mem_unassigned;
break;
@@ -406,10 +405,9 @@ MemoryRegion *address_space_translate(AddressSpace *as, hwaddr addr,
if (xen_enabled() && memory_access_is_direct(mr, is_write)) {
hwaddr page = ((addr & TARGET_PAGE_MASK) + TARGET_PAGE_SIZE) - addr;
- len = MIN(page, len);
+ *plen = MIN(page, *plen);
}
- *plen = len;
*xlat = addr;
rcu_read_unlock();
return mr;
--
2.3.5
next prev parent reply other threads:[~2015-04-28 14:41 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-04-28 14:40 [Qemu-devel] [PULL 00/22] Memory, TCG, NBD, build system changes for 2015-04-27 Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 01/22] translate-all: use glib for all page descriptor allocations Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 02/22] exec: Atomic access to bounce buffer Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 03/22] linux-user, bsd-user: Remove two calls to cpu_exec_init_all Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 04/22] exec: Protect map_client_list with mutex Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 05/22] exec: Notify cpu_register_map_client caller if the bounce buffer is available Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 06/22] dma-helpers: Fix race condition of continue_after_map_failure and dma_aio_cancel Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 07/22] memory: add memory_region_ram_resize Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 08/22] acpi-build: remove dependency from ram_addr.h Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 09/22] sun4m: fix slavio sysctrl and led register sizes Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 10/22] sb16: remove useless mixer_write_indexw Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 11/22] gus: clean up MemoryRegionPortio Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 12/22] ide: there is only one data port Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 13/22] ioport: remove wrong comment Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 14/22] ioport: loosen assertions on emulation of 16-bit ports Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 15/22] ioport: reserve the whole range of an I/O port in the AddressSpace Paolo Bonzini
2015-04-28 14:40 ` Paolo Bonzini [this message]
2015-04-28 14:40 ` [Qemu-devel] [PULL 17/22] configure: Add support for tcmalloc Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 18/22] milkymist: do not modify libs-softmmu Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 19/22] Makefile.target: prepend $libs_softmmu to $LIBS Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 20/22] target-i386: disable LINT0 after reset Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 21/22] translate-all: use bitmap helpers for PageDesc's bitmap Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 22/22] nbd/trivial: fix type cast for ioctl Paolo Bonzini
2015-04-28 15:54 ` [Qemu-devel] [PULL 00/22] Memory, TCG, NBD, build system changes for 2015-04-27 Peter Maydell
2015-04-29 1:53 ` Fam Zheng
2015-04-29 8:15 ` Paolo Bonzini
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1430232029-9457-17-git-send-email-pbonzini@redhat.com \
--to=pbonzini@redhat.com \
--cc=peter.crosthwaite@xilinx.com \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).