From nobody Mon Feb 9 09:52:57 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of redhat.com designates 205.139.110.120 as permitted sender) client-ip=205.139.110.120; envelope-from=philmd@redhat.com; helo=us-smtp-1.mimecast.com; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of redhat.com designates 205.139.110.120 as permitted sender) smtp.mailfrom=philmd@redhat.com; dmarc=pass(p=none dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1599131380; cv=none; d=zohomail.com; s=zohoarc; b=GqhsCqBQCGXtRVMIjHVdFUdwgNzHps1jURYz6dC0vyS0JKhMFUdf+rqYfgvOZrK1BlD6A1/3a7dwuSr2uhAzgxHSP0qjFJ3boo/5FX8OOvgNqEQ20O1n1s+dsk9T8PxbkG0SK6cnhicpaId+r3ahda/Z4TKnPA4lzsGSrZJNPLc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1599131380; h=Content-Type:Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:MIME-Version:Message-ID:References:Subject:To; bh=6vKwxcBB1Jm47jSnzS0OZNKGx56lCbflcLgkBcmGpYU=; b=ABL0HtroPif/rbAR+D2EqBMfRM8NAffttTGkGf7fbFKMDnd7sj9EoEYTfdZDqXTGs7y2PT4jbdlr5+HFXmxhbeZVLiXgTUIXBooz+mjBnnPNszvlZ8JNlSu/4ANP62EILPcOeMTiULlBpUgRN+7QdJxJuLRL9WTKNmHdLtJAtMU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of redhat.com designates 205.139.110.120 as permitted sender) smtp.mailfrom=philmd@redhat.com; dmarc=pass header.from= (p=none dis=none) header.from= Received: from us-smtp-1.mimecast.com (us-smtp-delivery-1.mimecast.com [205.139.110.120]) by mx.zohomail.com with SMTPS id 1599131380431620.0572843610375; Thu, 3 Sep 2020 04:09:40 -0700 (PDT) Received: from mail-wm1-f69.google.com (mail-wm1-f69.google.com [209.85.128.69]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-210-I-7YxIvKMLCSBWdoDjkKjg-1; Thu, 03 Sep 2020 07:09:38 -0400 Received: by mail-wm1-f69.google.com with SMTP id x81so840321wmg.8 for ; Thu, 03 Sep 2020 04:09:38 -0700 (PDT) Return-Path: Return-Path: Received: from localhost.localdomain (50.red-83-52-54.dynamicip.rima-tde.net. [83.52.54.50]) by smtp.gmail.com with ESMTPSA id h6sm3675958wmb.22.2020.09.03.04.09.34 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 03 Sep 2020 04:09:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1599131379; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=6vKwxcBB1Jm47jSnzS0OZNKGx56lCbflcLgkBcmGpYU=; b=c7CutQ7aLjyLcx3mrx4DS914Wtbj5iihfz3Gj1bBraM2YQPEVjxo7sTICrxCKLv5C1A21u gM4SJLpnkJ2WpyfBuX0eLojWX/hHv3MFRAk//mMV23h6dgUFMZKkflie8VUCdE0jFF0dW2 CWTok/+kdQQ8b+3cEOT12nrKn9lnY4Y= X-MC-Unique: I-7YxIvKMLCSBWdoDjkKjg-1 X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=6vKwxcBB1Jm47jSnzS0OZNKGx56lCbflcLgkBcmGpYU=; b=N80BiyK8wm4ZussLX8UkVT1lWAIWtv4VHMBmc+GlfheYk8QchVqM9mDeahf4Gvw82y ZQVmoslLhQxAf7YfsDv4eLogM++z+uIxKWLuhmRaW+XUqJebaMINKL11pHQ2fjylFAs4 jqIDY40cpwc5+de0nAH8Swc81brDA7tIQsnCB9yq8SI0MjGyqGyUTJ1FMQys4HBgHB0P f5S99P/oydPaGCD/O+BovHIKPSNYwLK7djhQNTTk2rfDXJLepAELh8y7wHUy7Gr7fOqd rPWA2ErWIziZhNG0klKC6Rtuce9aHU3JQu6J+nog0Tb3GSTnB8AyRQMU/xthjD1nUP/M uong== X-Gm-Message-State: AOAM5337jUPf6DzPxvXtIT8g8jVRYALIHthFosHjJlcCnpVVaRZbdTi9 z84t/Xt+pZaNoJLaM50nADrBdSrWTD15TypoqR873ax9H9oo7ZD0QuTfxa7PVZzkVy/Tl+EmhaO f6AsLTw6XRzrofA== X-Received: by 2002:adf:f7d0:: with SMTP id a16mr1759239wrq.381.1599131377060; Thu, 03 Sep 2020 04:09:37 -0700 (PDT) X-Google-Smtp-Source: ABdhPJx9ZzABMZHs/OnZtQQCj7u3oB9peViXkexZzHsdyPbqqnttBSyzIq0Xp6JVHBCMLGPo6NUwEw== X-Received: by 2002:adf:f7d0:: with SMTP id a16mr1759190wrq.381.1599131376857; Thu, 03 Sep 2020 04:09:36 -0700 (PDT) From: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= To: qemu-devel@nongnu.org Cc: John Snow , Gerd Hoffmann , Li Qiang , "Michael S. Tsirkin" , "Edgar E. Iglesias" , Eduardo Habkost , Richard Henderson , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Jan Kiszka , Emanuele Giuseppe Esposito , Eric Auger , Peter Chubb , Beniamino Galvani , Robert Foley , Paolo Bonzini , "Emilio G . Cota" , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Jason Wang , Andrew Baumann , Laszlo Ersek , Klaus Jensen , Stefan Hajnoczi , Tony Nguyen , Peter Xu , qemu-arm@nongnu.org, Prasad J Pandit , qemu-block@nongnu.org, Alistair Francis , Andrew Jeffery , Alexander Bulekov , Marcel Apfelbaum , "Edgar E . Iglesias" , Joel Stanley , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , Peter Maydell , qemu-ppc@nongnu.org, Mark Cave-Ayland , David Gibson , Richard Henderson Subject: [RFC PATCH 10/12] exec/memattrs: Introduce MemTxAttrs::direct_access field Date: Thu, 3 Sep 2020 13:08:29 +0200 Message-Id: <20200903110831.353476-11-philmd@redhat.com> X-Mailer: git-send-email 2.26.2 In-Reply-To: <20200903110831.353476-1-philmd@redhat.com> References: <20200903110831.353476-1-philmd@redhat.com> MIME-Version: 1.0 Authentication-Results: relay.mimecast.com; auth=pass smtp.auth=CUSA124A263 smtp.mailfrom=philmd@redhat.com X-Mimecast-Spam-Score: 0.002 X-Mimecast-Originator: redhat.com Content-Type: text/plain; charset="utf-8"; text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-ZohoMail-DKIM: pass (identity @redhat.com) Add the 'direct_access' bit to the memory attributes to restrict bus master access to ROM/RAM. Have read/write accessors return MEMTX_BUS_ERROR if an access is restricted and the region is not ROM/RAM ('direct'). Add corresponding trace events. Signed-off-by: Philippe Mathieu-Daud=C3=A9 --- include/exec/memattrs.h | 3 +++ exec.c | 8 ++++++++ trace-events | 1 + 3 files changed, 12 insertions(+) diff --git a/include/exec/memattrs.h b/include/exec/memattrs.h index 95f2d20d55b..c27cf639a96 100644 --- a/include/exec/memattrs.h +++ b/include/exec/memattrs.h @@ -35,6 +35,8 @@ typedef struct MemTxAttrs { unsigned int secure:1; /* Memory access is usermode (unprivileged) */ unsigned int user:1; + /* Bus master restricted to ROM/RAM slaves */ + unsigned int direct_access:1; /* Requester ID (for MSI for example) */ unsigned int requester_id:16; /* Invert endianness for this page */ @@ -66,6 +68,7 @@ typedef struct MemTxAttrs { #define MEMTX_OK 0 #define MEMTX_ERROR (1U << 0) /* device returned an error */ #define MEMTX_DECODE_ERROR (1U << 1) /* nothing at that address */ +#define MEMTX_BUS_ERROR (1U << 2) /* bus returned an error */ typedef uint32_t MemTxResult; =20 #endif diff --git a/exec.c b/exec.c index 7683afb6a8e..e6185eb04de 100644 --- a/exec.c +++ b/exec.c @@ -3213,6 +3213,10 @@ static MemTxResult flatview_write(FlatView *fv, hwad= dr addr, MemTxAttrs attrs, =20 l =3D len; mr =3D flatview_translate(fv, addr, &addr1, &l, true, attrs); + if (attrs.direct_access && !memory_access_is_direct(mr, true)) { + trace_memory_access_illegal(true, addr, len, mr->name); + return MEMTX_BUS_ERROR; + } result =3D flatview_write_continue(fv, addr, attrs, buf, len, addr1, l, mr); =20 @@ -3275,6 +3279,10 @@ static MemTxResult flatview_read(FlatView *fv, hwadd= r addr, =20 l =3D len; mr =3D flatview_translate(fv, addr, &addr1, &l, false, attrs); + if (attrs.direct_access && !memory_access_is_direct(mr, false)) { + trace_memory_access_illegal(false, addr, len, mr->name); + return MEMTX_BUS_ERROR; + } return flatview_read_continue(fv, addr, attrs, buf, len, addr1, l, mr); } diff --git a/trace-events b/trace-events index 42107ebc697..931896735b1 100644 --- a/trace-events +++ b/trace-events @@ -54,6 +54,7 @@ find_ram_offset_loop(uint64_t size, uint64_t candidate, u= int64_t offset, uint64_ ram_block_discard_range(const char *rbname, void *hva, size_t length, bool= need_madvise, bool need_fallocate, int ret) "%s@%p + 0x%zx: madvise: %d fa= llocate: %d ret: %d" memory_notdirty_write_access(uint64_t vaddr, uint64_t ram_addr, unsigned s= ize) "0x%" PRIx64 " ram_addr 0x%" PRIx64 " size %u" memory_notdirty_set_dirty(uint64_t vaddr) "0x%" PRIx64 +memory_access_illegal(bool is_write, uint64_t addr, uint64_t len, const ch= ar *mr_name) "is_write:%u addr:0x%08" PRIx64 " size:0x%04" PRIx64 " region:= '%s'" =20 # memory.c memory_region_ops_read(int cpu_index, void *mr, uint64_t addr, uint64_t va= lue, unsigned size) "cpu %d mr %p addr 0x%"PRIx64" value 0x%"PRIx64" size %= u" --=20 2.26.2