From nobody Sun May 19 01:26:39 2024 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zoho.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=fail(p=none dis=none) header.from=linaro.org Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 15537708737621013.4903860554431; Thu, 28 Mar 2019 04:01:13 -0700 (PDT) Received: from localhost ([127.0.0.1]:34415 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1h9SmU-00083s-LL for importer@patchew.org; Thu, 28 Mar 2019 07:01:10 -0400 Received: from eggs.gnu.org ([209.51.188.92]:49121) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1h9Shg-0003tL-4F for qemu-devel@nongnu.org; Thu, 28 Mar 2019 06:56:13 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1h9SZe-0007j6-Rs for qemu-devel@nongnu.org; Thu, 28 Mar 2019 06:47:56 -0400 Received: from mail-wm1-x344.google.com ([2a00:1450:4864:20::344]:36258) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1h9SZe-0007il-IC for qemu-devel@nongnu.org; Thu, 28 Mar 2019 06:47:54 -0400 Received: by mail-wm1-x344.google.com with SMTP id h18so3432022wml.1 for ; Thu, 28 Mar 2019 03:47:54 -0700 (PDT) Received: from orth.archaic.org.uk (orth.archaic.org.uk. [81.2.115.148]) by smtp.gmail.com with ESMTPSA id a82sm3471780wmf.11.2019.03.28.03.47.51 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 28 Mar 2019 03:47:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=b65SQePJbxC0zWnt6ZidOS/kWhKQ3fDnRDkZmHQ4sH4=; b=EtmMPZDwQaCKeL/JECM84DkdjQZdJCnFXOFhMm8+Ppk97VdcD0UjkJ/9PcyxICo3Tc chjZRRIIFGhLEv2qnP6pdJyKg1v/9HSU5TgTmIOaR6zN67QU8wARVS1I4Hi4leVXpjEq Sj4i4YZ73BYhGEFS32hv+qgfqBFhFi6HkhGIRgvJaKDfVC4ek5qwUYe6Dy3q62KAGOeA KZ7s/nUsg+PjcxV0icVKgWYf4/1H2xY1fdq6qhl7aBr1j3KAl7DnX17bzMeYr3E5y21p EgIck7iJutWXFXUUe0TcCUQJhQRPvlhfsuLS2Fo5+4Qn4yEuLTgnFOC88U2dY99GCGBG sKDQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=b65SQePJbxC0zWnt6ZidOS/kWhKQ3fDnRDkZmHQ4sH4=; b=VOiQp3wQkfm2OqAB1yaHt5oG8abu9aQP+cgF/8OmAcGE1itk0Pe5/lIzjFudZMlgP/ jNAFhsp1mHtpXhI/em5ZqV7qRYaKX4yzzbivdZMVb407Va+zoCR4xUGqD0Oly915FOlD 1xdbjIWMpbUUdXs0e7amQ2dbrQ+Z7bbZbyoNmHdMGLi4G6glmYtAi8QUGk+3LpD2AeB+ iltaDNZ3mll0vR7hu1xnT3ScEEp3giboKjWpSbSpYRVXF4DY26iQIWNXWTh3mKacl0Il P0GYU5t3D6YQgRxjsmRITIJ7+eyEi8cP4DmMHq2eOZWgo40v3r1GQvhr5u+6xIrMWEt7 9rCw== X-Gm-Message-State: APjAAAWp3ZWAA91zj5TwlvgAflR71/ACQqSJMTh+/4c6G5TaGGE117St mPq0biX4/+ED3TVW03bPHLnReQEt+w0= X-Google-Smtp-Source: APXvYqyC2OaERw6e+dV93nB4wRzgDhoeFVPlZBYvMo6KXIZkWrJlLuOfPW63+yyNoOdhYUlwKrRHeg== X-Received: by 2002:a7b:c111:: with SMTP id w17mr22503276wmi.6.1553770073115; Thu, 28 Mar 2019 03:47:53 -0700 (PDT) From: Peter Maydell To: qemu-devel@nongnu.org Date: Thu, 28 Mar 2019 10:47:50 +0000 Message-Id: <20190328104750.25046-1-peter.maydell@linaro.org> X-Mailer: git-send-email 2.20.1 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 2a00:1450:4864:20::344 Subject: [Qemu-devel] [PATCH for-4.0] target/i386: Generate #UD for LOCK on a register increment X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Paolo Bonzini , Richard Henderson , Eduardo Habkost , patches@linaro.org Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail-DKIM: fail (Header signature does not verify) Content-Type: text/plain; charset="utf-8" Fix a TCG crash due to attempting an atomic increment operation without having set up the address first. This is a similar case to that dealt with in commit e84fcd7f662a0d8198703, and we fix it in the same way. Fixes: https://bugs.launchpad.net/qemu/+bug/1807675 Signed-off-by: Peter Maydell Acked-by: Paolo Bonzini --- target/i386/translate.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/target/i386/translate.c b/target/i386/translate.c index 49cd298374b..b725bec37cd 100644 --- a/target/i386/translate.c +++ b/target/i386/translate.c @@ -1398,6 +1398,11 @@ static void gen_op(DisasContext *s1, int op, TCGMemO= p ot, int d) static void gen_inc(DisasContext *s1, TCGMemOp ot, int d, int c) { if (s1->prefix & PREFIX_LOCK) { + if (d !=3D OR_TMP0) { + /* Lock prefix when destination is not memory */ + gen_illegal_opcode(s1); + return; + } tcg_gen_movi_tl(s1->T0, c > 0 ? 1 : -1); tcg_gen_atomic_add_fetch_tl(s1->T0, s1->A0, s1->T0, s1->mem_index, ot | MO_LE); --=20 2.20.1