[Qemu-devel] [PATCH] hw/misc/tz-mpc: Fix value of BLK_MAX register

Peter Maydell posted 1 patch 7 years, 1 month ago
Test checkpatch passed
Test asan passed
Test docker-mingw@fedora passed
Test docker-quick@centos7 passed
Test docker-clang@ubuntu passed
Patches applied successfully (tree, apply log)
git fetch https://github.com/patchew-project/qemu tags/patchew/20181213183249.3468-1-peter.maydell@linaro.org
hw/misc/tz-mpc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
[Qemu-devel] [PATCH] hw/misc/tz-mpc: Fix value of BLK_MAX register
Posted by Peter Maydell 7 years, 1 month ago
In the TZ Memory Protection Controller, the BLK_MAX register is supposed
to return the maximum permitted value of the BLK_IDX register. Our
implementation incorrectly returned max+1 (ie the total number of
valid index values, since BLK_IDX is zero-based).

Correct this off-by-one error. Since we consistently initialize
and use s->blk_max throughout the implementation as the 'size'
of the LUT, just adjust the value we return when the guest reads
the BLK_MAX register, rather than trying to change the semantics
of the s->blk_max internal struct field.

Fixes: https://bugs.launchpad.net/qemu/+bug/1806824
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
---
 hw/misc/tz-mpc.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/hw/misc/tz-mpc.c b/hw/misc/tz-mpc.c
index e0c58ba37ec..946147b1c02 100644
--- a/hw/misc/tz-mpc.c
+++ b/hw/misc/tz-mpc.c
@@ -150,7 +150,7 @@ static MemTxResult tz_mpc_reg_read(void *opaque, hwaddr addr,
         r = s->ctrl;
         break;
     case A_BLK_MAX:
-        r = s->blk_max;
+        r = s->blk_max - 1;
         break;
     case A_BLK_CFG:
         /* We are never in "init in progress state", so this just indicates
-- 
2.19.2


Re: [Qemu-devel] [PATCH] hw/misc/tz-mpc: Fix value of BLK_MAX register
Posted by Richard Henderson 7 years, 1 month ago
On 12/13/18 12:32 PM, Peter Maydell wrote:
> In the TZ Memory Protection Controller, the BLK_MAX register is supposed
> to return the maximum permitted value of the BLK_IDX register. Our
> implementation incorrectly returned max+1 (ie the total number of
> valid index values, since BLK_IDX is zero-based).
> 
> Correct this off-by-one error. Since we consistently initialize
> and use s->blk_max throughout the implementation as the 'size'
> of the LUT, just adjust the value we return when the guest reads
> the BLK_MAX register, rather than trying to change the semantics
> of the s->blk_max internal struct field.
> 
> Fixes: https://bugs.launchpad.net/qemu/+bug/1806824
> Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
> ---
>  hw/misc/tz-mpc.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)

Reviewed-by: Richard Henderson <richard.henderson@linaro.org>


r~