From nobody Wed Nov 5 14:28:10 2025 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) client-ip=208.118.235.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=fail(p=none dis=none) header.from=redhat.com Return-Path: Received: from lists.gnu.org (lists.gnu.org [208.118.235.17]) by mx.zohomail.com with SMTPS id 1534872428963758.9133541263075; Tue, 21 Aug 2018 10:27:08 -0700 (PDT) Received: from localhost ([::1]:55065 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fsAQt-0000Ru-N2 for importer@patchew.org; Tue, 21 Aug 2018 13:27:07 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:33723) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fsA4n-0002IO-V9 for qemu-devel@nongnu.org; Tue, 21 Aug 2018 13:04:22 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fsA4W-0006o0-45 for qemu-devel@nongnu.org; Tue, 21 Aug 2018 13:04:11 -0400 Received: from mail-wr1-x431.google.com ([2a00:1450:4864:20::431]:44511) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1fsA4V-0006NL-6r for qemu-devel@nongnu.org; Tue, 21 Aug 2018 13:03:59 -0400 Received: by mail-wr1-x431.google.com with SMTP id v16-v6so2038087wro.11 for ; Tue, 21 Aug 2018 10:03:43 -0700 (PDT) Received: from 640k.lan (dynamic-adsl-78-12-184-244.clienti.tiscali.it. [78.12.184.244]) by smtp.gmail.com with ESMTPSA id v6-v6sm2608955wmc.43.2018.08.21.10.03.41 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 21 Aug 2018 10:03:41 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id:in-reply-to:references; bh=fpxsKEKxH3A505HF3CRNTFj4UusA3nJfDcpC1PFGuO4=; b=WDF1L3V+9m1mRYmFtZGELHLA+ftIFlVygAQ7WlvHjU3otD5l+oFZ42GdcxRDMVaVps EffznE0XBZfnEaY2a4gi+rs6Zk6lv07kffg/gAfvJEFOFZUqpe2VPtuYPDjwo0Z2yjGn eO1Xv5XCt3FniopH3QetlB/ZQbdc7YV0GFiyDdEwkWIqSnXN0+mCjUusSFEc/ckOcbNq a0+9NoIVRze4eOD87EyZPdlDJEop2CbIbELesnqSzrQiDQvEfMgenWqM0MpgdVTYJlnZ MD/b1Ejrlsp9AoZfM9Dbs7Z9L1KaSQo9UiBPRjN/Fmsbx9Wo3W1w5VKFKToqzCoEBuUY 7BJA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :in-reply-to:references; bh=fpxsKEKxH3A505HF3CRNTFj4UusA3nJfDcpC1PFGuO4=; b=Gu5y6PSK5dl4An5DPab0mIraFdUL2agYfo9Qrz9Or55QrzowYPS8lzSo4AqvD8oo1t TSyrEOo0wZCCut2Og/q2rr99G0DwpqVrce0xFd3pz745ch57QvN35obA1b3iC6+twaxp /Ko7ZzK+ZO+QI4teqkW92XnkrI6ZjsOFjVNzO7842u6k6iYA2n52vTpYs9GLEJNA3q3Z 7ITsH6r1rYh4sbphr3Q4LENMpO74nq2uTMVH0wT2qI76TF+Vcl+aA3aFIclG+LUr5JW9 zSDXnqy4SaNoP/IDqyJk9e0nletxJz0gpdNgvUjy70A12lrGFogmI8ofFNVm8XfgDBhS DnNQ== X-Gm-Message-State: AOUpUlEZEh4ZG7GnR68+voQwWE0pXGdeb/oC/X3GangMTbdhF0aIDtjq 2SN2/8aNsFQ34+wbzgKWzRabXrmF X-Google-Smtp-Source: AA+uWPxVFH4vlr+Kdzt71fB/f3+wNc6fikBLlfF5wFY2m/k9LqP20+X96FOmZ/hl8PbWG6R/m2tRAQ== X-Received: by 2002:a5d:6892:: with SMTP id h18-v6mr32388420wru.108.1534871022079; Tue, 21 Aug 2018 10:03:42 -0700 (PDT) From: Paolo Bonzini To: qemu-devel@nongnu.org Date: Tue, 21 Aug 2018 19:02:07 +0200 Message-Id: <1534870966-9287-36-git-send-email-pbonzini@redhat.com> X-Mailer: git-send-email 1.8.3.1 In-Reply-To: <1534870966-9287-1-git-send-email-pbonzini@redhat.com> References: <1534870966-9287-1-git-send-email-pbonzini@redhat.com> X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 2a00:1450:4864:20::431 Subject: [Qemu-devel] [PULL 35/74] target-i386: fix segment limit check in ljmp X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Andrew Oates Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZohoMail: RDMRC_1 RDKM_2 RSF_0 Z_629925259 SPT_0 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" From: Andrew Oates The current implementation has three bugs, * segment limits are not enforced in protected mode if the L bit is set in the target segment descriptor * segment limits are not enforced in compatibility mode (ljmp to 32-bit code segment in long mode) * #GP(new_cs) is generated rather than #GP(0) Now the segment limits are enforced if we're not in long mode OR the target code segment doesn't have the L bit set. Signed-off-by: Andrew Oates Message-Id: <20180816011903.39816-1-andrew@andrewoates.com> Signed-off-by: Paolo Bonzini --- target/i386/seg_helper.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/target/i386/seg_helper.c b/target/i386/seg_helper.c index b2adddc..d1cbc6e 100644 --- a/target/i386/seg_helper.c +++ b/target/i386/seg_helper.c @@ -1633,8 +1633,8 @@ void helper_ljmp_protected(CPUX86State *env, int new_= cs, target_ulong new_eip, } limit =3D get_seg_limit(e1, e2); if (new_eip > limit && - !(env->hflags & HF_LMA_MASK) && !(e2 & DESC_L_MASK)) { - raise_exception_err_ra(env, EXCP0D_GPF, new_cs & 0xfffc, GETPC= ()); + (!(env->hflags & HF_LMA_MASK) || !(e2 & DESC_L_MASK))) { + raise_exception_err_ra(env, EXCP0D_GPF, 0, GETPC()); } cpu_x86_load_seg_cache(env, R_CS, (new_cs & 0xfffc) | cpl, get_seg_base(e1, e2), limit, e2); --=20 1.8.3.1