From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:36941) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bmkhw-0005UM-I1 for qemu-devel@nongnu.org; Wed, 21 Sep 2016 12:49:17 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bmkhs-00080u-B7 for qemu-devel@nongnu.org; Wed, 21 Sep 2016 12:49:15 -0400 Received: from mail-wm0-f67.google.com ([74.125.82.67]:35308) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bmkhs-00080o-5h for qemu-devel@nongnu.org; Wed, 21 Sep 2016 12:49:12 -0400 Received: by mail-wm0-f67.google.com with SMTP id 133so9630853wmq.2 for ; Wed, 21 Sep 2016 09:49:12 -0700 (PDT) Sender: Paolo Bonzini References: <1474465525-31581-1-git-send-email-ppandit@redhat.com> From: Paolo Bonzini Message-ID: <82247f9a-3f0a-271d-48ef-7c9b8b0808b0@redhat.com> Date: Wed, 21 Sep 2016 18:48:09 +0200 MIME-Version: 1.0 In-Reply-To: <1474465525-31581-1-git-send-email-ppandit@redhat.com> Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit Subject: Re: [Qemu-devel] [PATCH for v2.6.0] net: imx: check buffer descriptor length List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: P J P , Qemu Developers Cc: Jason Wang , Li Qiang , Prasad J Pandit On 21/09/2016 15:45, P J P wrote: > From: Prasad J Pandit > > i.MX Fast Ethernet Controller uses buffer descriptors to manage > data flow to/fro receive & transmit queues. While transmitting > packets, it could continue to read buffer descriptors if a buffer > descriptor has length of zero. Add check to avoid it. > > Reported-by: Li Qiang > Signed-off-by: Prasad J Pandit > --- > hw/net/imx_fec.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/hw/net/imx_fec.c b/hw/net/imx_fec.c > index e60e338..31870b0 100644 > --- a/hw/net/imx_fec.c > +++ b/hw/net/imx_fec.c > @@ -276,7 +276,7 @@ static void imx_fec_do_tx(IMXFECState *s) > imx_fec_read_bd(&bd, addr); > FEC_PRINTF("tx_bd %x flags %04x len %d data %08x\n", > addr, bd.flags, bd.length, bd.data); > - if ((bd.flags & FEC_BD_R) == 0) { > + if (!bd.length || (bd.flags & FEC_BD_R) == 0) { > /* Run out of descriptors to transmit. */ > break; > } > Same here---and same bug as the previous patch too: diff --git a/hw/net/imx_fec.c b/hw/net/imx_fec.c index 1c415ab..50c7564 100644 --- a/hw/net/imx_fec.c +++ b/hw/net/imx_fec.c @@ -429,7 +429,7 @@ static void imx_fec_do_tx(IMXFECState *s) frame_size += len; if (bd.flags & ENET_BD_L) { /* Last buffer in frame. */ - qemu_send_packet(qemu_get_queue(s->nic), frame, len); + qemu_send_packet(qemu_get_queue(s->nic), frame, frame_size); ptr = frame; frame_size = 0; s->regs[ENET_EIR] |= ENET_INT_TXF; Paolo