From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:41474) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1WFLEA-0002QT-40 for qemu-devel@nongnu.org; Mon, 17 Feb 2014 05:15:11 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1WFLE5-0004sM-2f for qemu-devel@nongnu.org; Mon, 17 Feb 2014 05:15:06 -0500 Received: from mx1.redhat.com ([209.132.183.28]:20134) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1WFLE4-0004sH-PT for qemu-devel@nongnu.org; Mon, 17 Feb 2014 05:15:00 -0500 Date: Mon, 17 Feb 2014 11:14:56 +0100 From: Kevin Wolf Message-ID: <20140217101456.GD3502@dhcp-200-207.str.redhat.com> References: <1390558762-6941-1-git-send-email-kwolf@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1390558762-6941-1-git-send-email-kwolf@redhat.com> Subject: Re: [Qemu-devel] [PATCH] target-i386: Fix I/O bitmap checks for in/out List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Cc: peter.maydell@linaro.org, aliguori@amazon.com, rth@twiddle.net Am 24.01.2014 um 11:19 hat Kevin Wolf geschrieben: > Commit 1b90d56e changed the implementation of in/out imm to not assign > the accessed port number to cpu_T[0] as it appeared unnecessary. > However, currently gen_check_io() makes use of cpu_T[0] to implement the > I/O bitmap checks, so it's in fact still used and the change broke the > check, leading to #GP in legitimate cases (and probably also allowing > access to ports that shouldn't be allowed). > > This patch reintroduces the missing assignment for these cases. > > Signed-off-by: Kevin Wolf > Reviewed-by: Richard Henderson Ping? /me considers sending a one-patch pull request for an area he's absolutely not maintaining, but if this is the only way to get patches applied to qemu... Kevin > --- > target-i386/translate.c | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/target-i386/translate.c b/target-i386/translate.c > index b0f2279..5dd2450 100644 > --- a/target-i386/translate.c > +++ b/target-i386/translate.c > @@ -6284,6 +6284,7 @@ static target_ulong disas_insn(CPUX86State *env, DisasContext *s, > case 0xe5: > ot = mo_b_d32(b, dflag); > val = cpu_ldub_code(env, s->pc++); > + tcg_gen_movi_tl(cpu_T[0], val); > gen_check_io(s, ot, pc_start - s->cs_base, > SVM_IOIO_TYPE_MASK | svm_is_rep(prefixes)); > if (use_icount) > @@ -6300,6 +6301,7 @@ static target_ulong disas_insn(CPUX86State *env, DisasContext *s, > case 0xe7: > ot = mo_b_d32(b, dflag); > val = cpu_ldub_code(env, s->pc++); > + tcg_gen_movi_tl(cpu_T[0], val); > gen_check_io(s, ot, pc_start - s->cs_base, > svm_is_rep(prefixes)); > gen_op_mov_v_reg(ot, cpu_T[1], R_EAX); > -- > 1.8.1.4 >