qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Paolo Bonzini <pbonzini@redhat.com>
To: qemu-devel@nongnu.org
Cc: Peter Crosthwaite <peter.crosthwaite@xilinx.com>
Subject: [Qemu-devel] [PULL 16/22] exec: Respect as_translate_internal length clamp
Date: Tue, 28 Apr 2015 16:40:23 +0200	[thread overview]
Message-ID: <1430232029-9457-17-git-send-email-pbonzini@redhat.com> (raw)
In-Reply-To: <1430232029-9457-1-git-send-email-pbonzini@redhat.com>

From: Peter Crosthwaite <peter.crosthwaite@xilinx.com>

address_space_translate_internal will clamp the *plen length argument
based on the size of the memory region being queried. The iommu walker
logic in addresss_space_translate was ignoring this by discarding the
post fn call value of *plen. Fix by just always using *plen as the
length argument throughout the fn, removing the len local variable.

This fixes a bootloader bug when a single elf section spans multiple
QEMU memory regions.

Signed-off-by: Peter Crosthwaite <peter.crosthwaite@xilinx.com>
Message-Id: <1426570554-15940-1-git-send-email-peter.crosthwaite@xilinx.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
---
 exec.c | 6 ++----
 1 file changed, 2 insertions(+), 4 deletions(-)

diff --git a/exec.c b/exec.c
index 065f5e8..4717928 100644
--- a/exec.c
+++ b/exec.c
@@ -380,7 +380,6 @@ MemoryRegion *address_space_translate(AddressSpace *as, hwaddr addr,
     IOMMUTLBEntry iotlb;
     MemoryRegionSection *section;
     MemoryRegion *mr;
-    hwaddr len = *plen;
 
     rcu_read_lock();
     for (;;) {
@@ -395,7 +394,7 @@ MemoryRegion *address_space_translate(AddressSpace *as, hwaddr addr,
         iotlb = mr->iommu_ops->translate(mr, addr, is_write);
         addr = ((iotlb.translated_addr & ~iotlb.addr_mask)
                 | (addr & iotlb.addr_mask));
-        len = MIN(len, (addr | iotlb.addr_mask) - addr + 1);
+        *plen = MIN(*plen, (addr | iotlb.addr_mask) - addr + 1);
         if (!(iotlb.perm & (1 << is_write))) {
             mr = &io_mem_unassigned;
             break;
@@ -406,10 +405,9 @@ MemoryRegion *address_space_translate(AddressSpace *as, hwaddr addr,
 
     if (xen_enabled() && memory_access_is_direct(mr, is_write)) {
         hwaddr page = ((addr & TARGET_PAGE_MASK) + TARGET_PAGE_SIZE) - addr;
-        len = MIN(page, len);
+        *plen = MIN(page, *plen);
     }
 
-    *plen = len;
     *xlat = addr;
     rcu_read_unlock();
     return mr;
-- 
2.3.5

  parent reply	other threads:[~2015-04-28 14:41 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2015-04-28 14:40 [Qemu-devel] [PULL 00/22] Memory, TCG, NBD, build system changes for 2015-04-27 Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 01/22] translate-all: use glib for all page descriptor allocations Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 02/22] exec: Atomic access to bounce buffer Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 03/22] linux-user, bsd-user: Remove two calls to cpu_exec_init_all Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 04/22] exec: Protect map_client_list with mutex Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 05/22] exec: Notify cpu_register_map_client caller if the bounce buffer is available Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 06/22] dma-helpers: Fix race condition of continue_after_map_failure and dma_aio_cancel Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 07/22] memory: add memory_region_ram_resize Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 08/22] acpi-build: remove dependency from ram_addr.h Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 09/22] sun4m: fix slavio sysctrl and led register sizes Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 10/22] sb16: remove useless mixer_write_indexw Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 11/22] gus: clean up MemoryRegionPortio Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 12/22] ide: there is only one data port Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 13/22] ioport: remove wrong comment Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 14/22] ioport: loosen assertions on emulation of 16-bit ports Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 15/22] ioport: reserve the whole range of an I/O port in the AddressSpace Paolo Bonzini
2015-04-28 14:40 ` Paolo Bonzini [this message]
2015-04-28 14:40 ` [Qemu-devel] [PULL 17/22] configure: Add support for tcmalloc Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 18/22] milkymist: do not modify libs-softmmu Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 19/22] Makefile.target: prepend $libs_softmmu to $LIBS Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 20/22] target-i386: disable LINT0 after reset Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 21/22] translate-all: use bitmap helpers for PageDesc's bitmap Paolo Bonzini
2015-04-28 14:40 ` [Qemu-devel] [PULL 22/22] nbd/trivial: fix type cast for ioctl Paolo Bonzini
2015-04-28 15:54 ` [Qemu-devel] [PULL 00/22] Memory, TCG, NBD, build system changes for 2015-04-27 Peter Maydell
2015-04-29  1:53   ` Fam Zheng
2015-04-29  8:15     ` Paolo Bonzini

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1430232029-9457-17-git-send-email-pbonzini@redhat.com \
    --to=pbonzini@redhat.com \
    --cc=peter.crosthwaite@xilinx.com \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).