qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Paolo Bonzini <pbonzini@redhat.com>
To: qemu-devel@nongnu.org
Cc: Maxime Coquelin <maxime.coquelin@redhat.com>,
	qemu-stable@nongnu.org, Peter Xu <peterx@redhat.com>
Subject: [Qemu-devel] [PULL 07/29] memory: fix off-by-one error in memory_region_notify_one()
Date: Wed, 18 Oct 2017 18:11:59 +0200	[thread overview]
Message-ID: <1508343141-31835-8-git-send-email-pbonzini@redhat.com> (raw)
In-Reply-To: <1508343141-31835-1-git-send-email-pbonzini@redhat.com>

From: Maxime Coquelin <maxime.coquelin@redhat.com>

This patch fixes an off-by-one error that could lead to the
notifyee to receive notifications for ranges it is not
registered to.

The bug has been spotted by code review.

Fixes: bd2bfa4c52e5 ("memory: introduce memory_region_notify_one()")
Cc: qemu-stable@nongnu.org
Cc: Peter Xu <peterx@redhat.com>
Signed-off-by: Maxime Coquelin <maxime.coquelin@redhat.com>
Message-Id: <20171010094247.10173-4-maxime.coquelin@redhat.com>
Reviewed-by: Peter Xu <peterx@redhat.com>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
---
 memory.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/memory.c b/memory.c
index 5e6351a..b637c12 100644
--- a/memory.c
+++ b/memory.c
@@ -1892,7 +1892,7 @@ void memory_region_notify_one(IOMMUNotifier *notifier,
      * Skip the notification if the notification does not overlap
      * with registered range.
      */
-    if (notifier->start > entry->iova + entry->addr_mask + 1 ||
+    if (notifier->start > entry->iova + entry->addr_mask ||
         notifier->end < entry->iova) {
         return;
     }
-- 
1.8.3.1

  parent reply	other threads:[~2017-10-18 16:13 UTC|newest]

Thread overview: 32+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-10-18 16:11 [Qemu-devel] [PULL 00/29] Misc patches for 2017-10-18 Paolo Bonzini
2017-10-18 16:11 ` [Qemu-devel] [PULL 01/29] checkpatch: refine mode selection Paolo Bonzini
2017-10-18 16:11 ` [Qemu-devel] [PULL 02/29] scsi-disk: support reporting of rotation rate Paolo Bonzini
2017-10-18 16:11 ` [Qemu-devel] [PULL 03/29] ide: " Paolo Bonzini
2017-10-18 16:11 ` [Qemu-devel] [PULL 04/29] char: don't skip client cleanup if 'connected' flag is unset Paolo Bonzini
2017-10-18 16:11 ` [Qemu-devel] [PULL 05/29] exec: add page_mask for flatview_do_translate Paolo Bonzini
2017-10-18 16:11 ` [Qemu-devel] [PULL 06/29] exec: simplify address_space_get_iotlb_entry Paolo Bonzini
2017-10-18 16:11 ` Paolo Bonzini [this message]
2017-10-18 16:12 ` [Qemu-devel] [PULL 08/29] pc: make sure that plugged CPUs are of the same type Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 09/29] disas: Always initialize read_memory_inner_func properly Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 10/29] build: remove CONFIG_LIBDECNUMBER Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 11/29] nios2: define tcg_env Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 12/29] docs/devel/loads-stores.rst: Document our various load and store APIs Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 13/29] tco: add trace events Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 14/29] target/i386: introduce x86_ld*_code Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 15/29] target/i386: trap on instructions longer than >15 bytes Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 16/29] memory: call log_start after region_add Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 17/29] kvm: fix alignment of ram address Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 18/29] kvm: tolerate non-existing slot for log_start/log_stop/log_sync Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 19/29] kvm: fix error message when failing to unregister slot Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 20/29] kvm: region_add and region_del is not called on updates Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 21/29] kvm: simplify kvm_align_section() Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 22/29] memory: reuse section_from_flat_range() Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 23/29] notdirty_mem_write: implement 8-byte accesses Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 24/29] watch_mem_write: " Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 25/29] qemu-pr-helper: use new libmultipath API Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 26/29] qdev: store DeviceState's canonical path to use when unparenting Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 27/29] Revert "qdev: Free QemuOpts when the QOM path goes away" Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 28/29] qdev: defer DEVICE_DEL event until instance_finalize() Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 29/29] scsi: reject configurations with logical block size > physical block size Paolo Bonzini
2017-10-18 17:13 ` [Qemu-devel] [PULL 00/29] Misc patches for 2017-10-18 no-reply
2017-10-19 15:47 ` Peter Maydell

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1508343141-31835-8-git-send-email-pbonzini@redhat.com \
    --to=pbonzini@redhat.com \
    --cc=maxime.coquelin@redhat.com \
    --cc=peterx@redhat.com \
    --cc=qemu-devel@nongnu.org \
    --cc=qemu-stable@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).