From nobody Wed Nov 5 10:59:04 2025 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) client-ip=208.118.235.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists.gnu.org (lists.gnu.org [208.118.235.17]) by mx.zohomail.com with SMTPS id 153438242813613.625768319318468; Wed, 15 Aug 2018 18:20:28 -0700 (PDT) Received: from localhost ([::1]:52950 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fq6xa-0004MO-N6 for importer@patchew.org; Wed, 15 Aug 2018 21:20:22 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:59829) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1fq6wd-0003uh-UM for qemu-devel@nongnu.org; Wed, 15 Aug 2018 21:19:24 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1fq6wZ-00036A-Qs for qemu-devel@nongnu.org; Wed, 15 Aug 2018 21:19:23 -0400 Received: from mail-qt0-x235.google.com ([2607:f8b0:400d:c0d::235]:39335) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1fq6wW-00035D-04 for qemu-devel@nongnu.org; Wed, 15 Aug 2018 21:19:18 -0400 Received: by mail-qt0-x235.google.com with SMTP id q12-v6so3469660qtp.6 for ; Wed, 15 Aug 2018 18:19:14 -0700 (PDT) Received: from localhost.localdomain (c-65-96-174-46.hsd1.ma.comcast.net. [65.96.174.46]) by smtp.gmail.com with ESMTPSA id k3-v6sm15778649qta.37.2018.08.15.18.19.12 (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Wed, 15 Aug 2018 18:19:12 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id; bh=MB4+n46OPpw017n4nRL4qQ6F/qBeaZiLY4g6x4o0fkc=; b=jFQvZtdBjqH4nUrUdA9E1f8CLEbGaTK3hcS3kILn3WDm46BKJMrFWk+tHt0ph2F/Nr 9Z1w4QkiAkM2BOpRqq+BiqxNSkuxGAlPNltS3v+XWEEx4awPk1eESR6hAnBn+yUvHot0 XdTqPoPm3qQGVA/+z/3Q9AmZCXgwh8Q7MvV40su/Cf14Gd42Hwbho8k0ra1cutrVespW U9asXW3x8WDiAFJ01pp7MSOVSApvunv4dRZcu/jLmOy0mZOesBNZCuhSFuGvrv153hlt ZhzGj1KVbSGPfVLyB3B2Eq0jsywv6HWo09xb+MCYaEjPoOD2y6r14TVxVZVHehTY+Wjf pF3g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id; bh=MB4+n46OPpw017n4nRL4qQ6F/qBeaZiLY4g6x4o0fkc=; b=QIAzwhd06oG4HupwtaMMybkCWAskySVOchsc/lC8A8exKHC+LALAEL6gvrp5S4JBkB a8cUr6+HVMnhWL94um0zb/+rPC+ugs7mwgXKk5xUKPLqi4PbXf8BokUS/aWJAg91iQgU X1cLRqrYiv+b4p+rklSRROHHDkJmrOSE1rJyYtnF6uAVywQanIjqD5TJ4tLbsJMCm9ju Q0NMpDkYbvLloh0gkE7ad529YCZImHV1WVlkO2esi5c4B6Id+xN0N+UFm8o56VipD8Fa XVXPoTrsjCffL2n92o3z0I50j86Qw02uWHn1Loi5p6uc4afetsIxzivRaYgwHw4/4i0E V4tw== X-Gm-Message-State: AOUpUlHNHxqSwL38jm6W1/sOcgMh1/SaumLeFrkTRSNzclcCmqNbHo55 BWYI2LxZTvh73F0b6bfqMF4= X-Google-Smtp-Source: AA+uWPxNOBRM4Q9Z7MRLafcWasVi8+dakFhXQgHNxF6/ZimLFBWAtK/CoGqHgt113GR02uDCqsACDw== X-Received: by 2002:ac8:30b6:: with SMTP id v51-v6mr26340304qta.313.1534382354018; Wed, 15 Aug 2018 18:19:14 -0700 (PDT) From: andrew@andrewoates.com To: pbonzini@redhat.com, rth@twiddle.net, ehabkost@redhat.com, qemu-devel@nongnu.org Date: Wed, 15 Aug 2018 21:19:03 -0400 Message-Id: <20180816011903.39816-1-andrew@andrewoates.com> X-Mailer: git-send-email 2.17.0 X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 2607:f8b0:400d:c0d::235 Subject: [Qemu-devel] [PATCH] target-i386: fix segment limit check in ljmp X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Andrew Oates Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZohoMail: RDKM_2 RSF_0 Z_629925259 SPT_0 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" From: Andrew Oates The current implementation has three bugs, * segment limits are not enforced in protected mode if the L bit is set in the target segment descriptor[1] * segment limits are not enforced in compatability mode (ljmp to 32-bit code segment in long mode) * #GP(new_cs) is generated rather than #GP(0) Now the segment limits are enforced if we're not in long mode OR the target code segment doesn't have the L bit set. [1] this is an invalid configuration (in protected mode the L bit is reserved and should be set to zero), but qemu doesn't enforce that. Signed-off-by: Andrew Oates --- The limit check is still incorrect for ljmp-through-call-gate in 64-bit mode. That's a larger fix I'm still working on. target/i386/seg_helper.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/target/i386/seg_helper.c b/target/i386/seg_helper.c index 00301a0c04..975365fd30 100644 --- a/target/i386/seg_helper.c +++ b/target/i386/seg_helper.c @@ -1628,8 +1628,8 @@ void helper_ljmp_protected(CPUX86State *env, int new_= cs, target_ulong new_eip, } limit =3D get_seg_limit(e1, e2); if (new_eip > limit && - !(env->hflags & HF_LMA_MASK) && !(e2 & DESC_L_MASK)) { - raise_exception_err_ra(env, EXCP0D_GPF, new_cs & 0xfffc, GETPC= ()); + (!(env->hflags & HF_LMA_MASK) || !(e2 & DESC_L_MASK))) { + raise_exception_err_ra(env, EXCP0D_GPF, 0, GETPC()); } cpu_x86_load_seg_cache(env, R_CS, (new_cs & 0xfffc) | cpl, get_seg_base(e1, e2), limit, e2); --=20 2.17.0