qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Paolo Bonzini <pbonzini@redhat.com>
To: qemu-devel@nongnu.org
Cc: Richard Henderson <richard.henderson@linaro.org>
Subject: [PULL 09/13] target/i386/tcg: check for correct busy state before switching to a new task
Date: Sun, 14 Jul 2024 13:10:39 +0200	[thread overview]
Message-ID: <20240714111043.14132-10-pbonzini@redhat.com> (raw)
In-Reply-To: <20240714111043.14132-1-pbonzini@redhat.com>

This step is listed in the Intel manual: "Checks that the new task is available
(call, jump, exception, or interrupt) or busy (IRET return)".

The AMD manual lists the same operation under the "Preventing recursion"
paragraph of "12.3.4 Nesting Tasks", though it is not clear if the processor
checks the busy bit in the IRET case.

Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
---
 target/i386/tcg/seg_helper.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/target/i386/tcg/seg_helper.c b/target/i386/tcg/seg_helper.c
index 809ee3d9833..0242f9d8b58 100644
--- a/target/i386/tcg/seg_helper.c
+++ b/target/i386/tcg/seg_helper.c
@@ -369,6 +369,11 @@ static int switch_tss_ra(CPUX86State *env, int tss_selector,
         old_tss_limit_max = 43;
     }
 
+    /* new TSS must be busy iff the source is an IRET instruction  */
+    if (!!(e2 & DESC_TSS_BUSY_MASK) != (source == SWITCH_TSS_IRET)) {
+        raise_exception_err_ra(env, EXCP0A_TSS, tss_selector & 0xfffc, retaddr);
+    }
+
     /* read all the registers from the new TSS */
     if (type & 8) {
         /* 32 bit */
-- 
2.45.2



  parent reply	other threads:[~2024-07-14 11:11 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2024-07-14 11:10 [PULL 00/13] target/i386 changes for 2024-07-12 Paolo Bonzini
2024-07-14 11:10 ` [PULL 01/13] target/i386/tcg: fix POP to memory in long mode Paolo Bonzini
2024-07-14 11:10 ` [PULL 02/13] target/i386/tcg: Remove SEG_ADDL Paolo Bonzini
2024-07-14 11:10 ` [PULL 03/13] target/i386/tcg: Allow IRET from user mode to user mode with SMAP Paolo Bonzini
2024-07-14 11:10 ` [PULL 04/13] target/i386/tcg: use PUSHL/PUSHW for error code Paolo Bonzini
2024-07-14 11:10 ` [PULL 05/13] target/i386/tcg: Reorg push/pop within seg_helper.c Paolo Bonzini
2024-07-14 11:10 ` [PULL 06/13] target/i386/tcg: Introduce x86_mmu_index_{kernel_,}pl Paolo Bonzini
2024-07-14 11:10 ` [PULL 07/13] target/i386/tcg: Compute MMU index once Paolo Bonzini
2024-07-14 11:10 ` [PULL 08/13] target/i386/tcg: Use DPL-level accesses for interrupts and call gates Paolo Bonzini
2024-07-14 11:10 ` Paolo Bonzini [this message]
2024-07-14 11:10 ` [PULL 10/13] target/i386/tcg: use X86Access for TSS access Paolo Bonzini
2024-07-14 11:10 ` [PULL 11/13] target/i386/tcg: save current task state before loading new one Paolo Bonzini
2024-07-14 11:10 ` [PULL 12/13] i386/sev: Don't allow automatic fallback to legacy KVM_SEV*_INIT Paolo Bonzini
2024-07-14 11:10 ` [PULL 13/13] Revert "qemu-char: do not operate on sources from finalize callbacks" Paolo Bonzini
2024-07-14 22:47 ` [PULL 00/13] target/i386 changes for 2024-07-12 Richard Henderson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20240714111043.14132-10-pbonzini@redhat.com \
    --to=pbonzini@redhat.com \
    --cc=qemu-devel@nongnu.org \
    --cc=richard.henderson@linaro.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).