From: Laurent Vivier <laurent@vivier.eu>
To: qemu-devel@nongnu.org
Cc: Laurent Vivier <laurent@vivier.eu>,
Riku Voipio <riku.voipio@iki.fi>,
Luke Shumaker <lukeshu@parabola.nu>
Subject: [Qemu-devel] [PULL 13/18] linux-user: init_guest_space: Correctly handle guest_start in commpage initialization
Date: Tue, 13 Mar 2018 18:33:50 +0100 [thread overview]
Message-ID: <20180313173355.4468-14-laurent@vivier.eu> (raw)
In-Reply-To: <20180313173355.4468-1-laurent@vivier.eu>
From: Luke Shumaker <lukeshu@parabola.nu>
init_guest_commpage needs to check if the mapped space, which ends at
real_start+real_size overlaps with where it needs to put the commpage,
which is (assuming sane qemu_host_page_size) guest_base + 0xffff000, where
guest_base is real_start - guest_start.
[guest_base][ 0xffff0000 ][commpage]
[guest_base][guest_start][real_size] [commpage]
[ real_start ][real_size] [commpage]
^
fail if this gap < 0
Since init_guest_commpage wants to do everything relative to guest_base
(rather than real_start), it obviously needs to be comparing 0xffff0000
against guest_start+real_size, not just real_size.
This bug has been present since 806d102141b99d4f1e55a97d68b7ea8c8ba3129f in
2012, but guest_start is usually 0, and prior to v2.11 real_size was
usually much smaller than 0xffff0000, so it was uncommon for it to have
made a difference.
Signed-off-by: Luke Shumaker <lukeshu@parabola.nu>
Message-Id: <20171228180814.9749-5-lukeshu@lukeshu.com>
Reviewed-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Laurent Vivier <laurent@vivier.eu>
---
linux-user/elfload.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/linux-user/elfload.c b/linux-user/elfload.c
index dcdd756908..feecbd4163 100644
--- a/linux-user/elfload.c
+++ b/linux-user/elfload.c
@@ -1856,7 +1856,7 @@ unsigned long init_guest_space(unsigned long host_start,
#if defined(TARGET_ARM) && !defined(TARGET_AARCH64)
/* On 32-bit ARM, we need to also be able to map the commpage. */
int valid = init_guest_commpage(real_start - guest_start,
- real_size);
+ real_size + guest_start);
if (valid == 1) {
break;
} else if (valid == -1) {
--
2.14.3
next prev parent reply other threads:[~2018-03-13 17:34 UTC|newest]
Thread overview: 21+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-03-13 17:33 [Qemu-devel] [PULL 00/18] Linux user for 2.12 patches Laurent Vivier
2018-03-13 17:33 ` [Qemu-devel] [PULL 01/18] linux-user: Drop unicore32 code Laurent Vivier
2018-03-13 17:33 ` [Qemu-devel] [PULL 02/18] linux-user: Remove the unused "not implemented" signal handling stubs Laurent Vivier
2018-03-13 17:33 ` [Qemu-devel] [PULL 03/18] linux-user: allows to use "--systemd ALL" with qemu-binfmt-conf.sh Laurent Vivier
2018-03-13 17:33 ` [Qemu-devel] [PULL 04/18] linux-user: Support f_flags in statfs when available Laurent Vivier
2018-03-13 17:33 ` [Qemu-devel] [PULL 05/18] linux-user: fix mmap/munmap/mprotect/mremap/shmat Laurent Vivier
2018-03-13 17:33 ` [Qemu-devel] [PULL 06/18] linux-user: fix assertion in shmdt Laurent Vivier
2018-03-13 17:33 ` [Qemu-devel] [PULL 07/18] linux-user: fix target_mprotect/target_munmap error return values Laurent Vivier
2018-03-13 17:33 ` [Qemu-devel] [PULL 08/18] linux-user: drop unused target_msync function Laurent Vivier
2018-03-13 17:33 ` [Qemu-devel] [PULL 09/18] qemu-binfmt-conf.sh: add qemu-xtensa Laurent Vivier
2018-03-13 17:33 ` [Qemu-devel] [PULL 10/18] linux-user: Use #if to only call validate_guest_space for 32-bit ARM target Laurent Vivier
2018-03-13 17:33 ` [Qemu-devel] [PULL 11/18] linux-user: Rename validate_guest_space => init_guest_commpage Laurent Vivier
2018-03-13 17:33 ` [Qemu-devel] [PULL 12/18] linux-user: init_guest_space: Clean up if we can't initialize the commpage Laurent Vivier
2018-03-13 17:33 ` Laurent Vivier [this message]
2018-03-13 17:33 ` [Qemu-devel] [PULL 14/18] linux-user: init_guest_space: Clarify page alignment logic Laurent Vivier
2018-03-13 17:33 ` [Qemu-devel] [PULL 15/18] linux-user: init_guest_commpage: Add a comment about size check Laurent Vivier
2018-03-13 17:33 ` [Qemu-devel] [PULL 16/18] linux-user: init_guest_space: Clean up control flow a bit Laurent Vivier
2018-03-13 17:33 ` [Qemu-devel] [PULL 17/18] linux-user: init_guest_space: Don't try to align if we'll reject it Laurent Vivier
2018-03-13 17:33 ` [Qemu-devel] [PULL 18/18] linux-user: init_guest_space: Add a comment about search strategy Laurent Vivier
2018-03-13 18:43 ` [Qemu-devel] [PULL 00/18] Linux user for 2.12 patches no-reply
2018-03-15 18:52 ` Peter Maydell
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20180313173355.4468-14-laurent@vivier.eu \
--to=laurent@vivier.eu \
--cc=lukeshu@parabola.nu \
--cc=qemu-devel@nongnu.org \
--cc=riku.voipio@iki.fi \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).