From: "Michael S. Tsirkin" <mst@redhat.com>
To: qemu-devel@nongnu.org
Cc: Peter Maydell <peter.maydell@linaro.org>,
Peter Xu <peterx@redhat.com>,
QEMU Stable <qemu-stable@nongnu.org>,
Eric Auger <eric.auger@redhat.com>,
Jean-Philippe Brucker <jean-philippe@linaro.org>
Subject: [PULL v2 13/38] virtio-iommu: Fix virtio_iommu_mr()
Date: Tue, 3 Nov 2020 23:51:17 -0500 [thread overview]
Message-ID: <20201104044937.226370-14-mst@redhat.com> (raw)
In-Reply-To: <20201104044937.226370-1-mst@redhat.com>
From: Jean-Philippe Brucker <jean-philippe@linaro.org>
Due to an invalid mask, virtio_iommu_mr() may return the wrong memory
region. It hasn't been too problematic so far because the function was
only used to test existence of an endpoint, but that is about to change.
Fixes: cfb42188b24d ("virtio-iommu: Implement attach/detach command")
Cc: QEMU Stable <qemu-stable@nongnu.org>
Acked-by: Eric Auger <eric.auger@redhat.com>
Reviewed-by: Peter Xu <peterx@redhat.com>
Signed-off-by: Jean-Philippe Brucker <jean-philippe@linaro.org>
Message-Id: <20201030180510.747225-2-jean-philippe@linaro.org>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
---
hw/virtio/virtio-iommu.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/hw/virtio/virtio-iommu.c b/hw/virtio/virtio-iommu.c
index 21ec63b108..4c8f3909b7 100644
--- a/hw/virtio/virtio-iommu.c
+++ b/hw/virtio/virtio-iommu.c
@@ -101,7 +101,7 @@ static IOMMUMemoryRegion *virtio_iommu_mr(VirtIOIOMMU *s, uint32_t sid)
bus_n = PCI_BUS_NUM(sid);
iommu_pci_bus = iommu_find_iommu_pcibus(s, bus_n);
if (iommu_pci_bus) {
- devfn = sid & PCI_DEVFN_MAX;
+ devfn = sid & (PCI_DEVFN_MAX - 1);
dev = iommu_pci_bus->pbdev[devfn];
if (dev) {
return &dev->iommu_mr;
--
MST
next prev parent reply other threads:[~2020-11-04 4:57 UTC|newest]
Thread overview: 40+ messages / expand[flat|nested] mbox.gz Atom feed top
2020-11-04 4:50 [PULL v2 00/38] pc,pci,vhost,virtio: fixes Michael S. Tsirkin
2020-11-04 4:50 ` [PULL v2 01/38] pc: comment style fixup Michael S. Tsirkin
2020-11-04 4:50 ` [PULL v2 02/38] virtio-mem: Make sure "addr" is always multiples of the block size Michael S. Tsirkin
2020-11-04 4:50 ` [PULL v2 03/38] virtio-mem: Make sure "usable_region_size" " Michael S. Tsirkin
2020-11-04 4:50 ` [PULL v2 04/38] virtio-mem: Probe THP size to determine default " Michael S. Tsirkin
2020-11-04 4:50 ` [PULL v2 05/38] memory-device: Support big alignment requirements Michael S. Tsirkin
2020-11-04 4:50 ` [PULL v2 06/38] memory-device: Add get_min_alignment() callback Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 07/38] virito-mem: Implement get_min_alignment() Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 08/38] hw/acpi : Don't use '#' flag of printf format Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 09/38] hw/acpi : add space before the open parenthesis '(' Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 10/38] hw/acpi : add spaces around operator Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 11/38] hw/virtio/vhost-backend: Fix Coverity CID 1432871 Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 12/38] hw/smbios: Fix leaked fd in save_opt_one() error path Michael S. Tsirkin
2020-11-04 4:51 ` Michael S. Tsirkin [this message]
2020-11-04 4:51 ` [PULL v2 14/38] virtio-iommu: Store memory region in endpoint struct Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 15/38] virtio-iommu: Add memory notifiers for map/unmap Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 16/38] virtio-iommu: Call memory notifiers in attach/detach Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 17/38] virtio-iommu: Add replay() memory region callback Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 18/38] virtio-iommu: Add notify_flag_changed() " Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 19/38] memory: Add interface to set iommu page size mask Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 20/38] vfio: Set IOMMU page size as per host supported page size Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 21/38] virtio-iommu: Set supported page size mask Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 22/38] vfio: Don't issue full 2^64 unmap Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 23/38] vhost-vdpa: Add qemu_close in vhost_vdpa_cleanup Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 24/38] net: Add vhost-vdpa in show_netdevs() Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 25/38] Revert "vhost-blk: set features before setting inflight feature" Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 26/38] vhost-blk: set features before setting inflight feature Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 27/38] libvhost-user: follow QEMU comment style Michael S. Tsirkin
2020-11-04 4:51 ` [PULL v2 28/38] configure: introduce --enable-vhost-user-blk-server Michael S. Tsirkin
2020-11-04 4:52 ` [PULL v2 29/38] block/export: make vhost-user-blk config space little-endian Michael S. Tsirkin
2020-11-04 4:52 ` [PULL v2 30/38] block/export: fix vhost-user-blk get_config() information leak Michael S. Tsirkin
2020-11-04 4:52 ` [PULL v2 31/38] contrib/vhost-user-blk: fix " Michael S. Tsirkin
2020-11-04 4:52 ` [PULL v2 32/38] test: new qTest case to test the vhost-user-blk-server Michael S. Tsirkin
2020-11-04 4:52 ` [PULL v2 33/38] tests/qtest: add multi-queue test case to vhost-user-blk-test Michael S. Tsirkin
2020-11-04 4:52 ` [PULL v2 34/38] libqtest: add qtest_socket_server() Michael S. Tsirkin
2020-11-04 4:52 ` [PULL v2 35/38] vhost-user-blk-test: rename destroy_drive() to destroy_file() Michael S. Tsirkin
2020-11-04 4:52 ` [PULL v2 36/38] vhost-user-blk-test: close fork child file descriptors Michael S. Tsirkin
2020-11-04 4:52 ` [PULL v2 37/38] vhost-user-blk-test: drop unused return value Michael S. Tsirkin
2020-11-04 4:52 ` [PULL v2 38/38] vhost-user-blk-test: fix races by using fd passing Michael S. Tsirkin
2020-11-04 10:28 ` [PULL v2 00/38] pc,pci,vhost,virtio: fixes Peter Maydell
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20201104044937.226370-14-mst@redhat.com \
--to=mst@redhat.com \
--cc=eric.auger@redhat.com \
--cc=jean-philippe@linaro.org \
--cc=peter.maydell@linaro.org \
--cc=peterx@redhat.com \
--cc=qemu-devel@nongnu.org \
--cc=qemu-stable@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).