From nobody Tue Feb 10 11:15:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=jablonski.xyz ARC-Seal: i=1; a=rsa-sha256; t=1769784672; cv=none; d=zohomail.com; s=zohoarc; b=IQ3boMiTeO+S+Sf7gKOIdjETTGrsHk8H0NNdYpN+Bu0GLyzZvijTEQEfV9G0P0VafYngW4xguxj4K1/Jynat0vajEAqUmBVX7z+oegFPXJKRRSVpJRwQaR4kVn2oqlOTG6p2zqt+5j3/KRAZuYuURN4Vi8W7uzJWRUClxOMFt6Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1769784672; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=jFkm6fmhGUS6Iee0jwQIzG56FRBVEb+3L9zvD+WRoXo=; b=emfQddiWvasiCB/xha8bZvkt0c4/vLWXDST9zqIG7iyl4lEHKDsoZWhV0cC5xwfas75T5onSrTK3C+bHuKW5JfjOMPodeqlWKou7D2vjpH1ZGtcFuE1bYRvgsUAATwpiBuyaOiO3IXpky2XWC4REolVTHdjkrZmhNWMZymtUDzY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1769784672217250.74126868945802; Fri, 30 Jan 2026 06:51:12 -0800 (PST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1vlppq-0004xa-7L; Fri, 30 Jan 2026 09:50:58 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1vlppo-0004wk-BP for qemu-devel@nongnu.org; Fri, 30 Jan 2026 09:50:56 -0500 Received: from fhigh-b2-smtp.messagingengine.com ([202.12.124.153]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1vlppW-000394-78 for qemu-devel@nongnu.org; Fri, 30 Jan 2026 09:50:41 -0500 Received: from phl-compute-03.internal (phl-compute-03.internal [10.202.2.43]) by mailfhigh.stl.internal (Postfix) with ESMTP id 9D0AE7A0136; Fri, 30 Jan 2026 09:50:26 -0500 (EST) Received: from phl-frontend-03 ([10.202.2.162]) by phl-compute-03.internal (MEProxy); Fri, 30 Jan 2026 09:50:26 -0500 Received: by mail.messagingengine.com (Postfix) with ESMTPA; Fri, 30 Jan 2026 09:50:26 -0500 (EST) Received: from localhost (chomposaur [local]) by chomposaur (OpenSMTPD) with ESMTPA id ee27a70d; Fri, 30 Jan 2026 14:50:19 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jablonski.xyz; h=cc:cc:content-transfer-encoding:content-type:date:date:from :from:in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to; s=fm2; t=1769784626; x= 1769871026; bh=jFkm6fmhGUS6Iee0jwQIzG56FRBVEb+3L9zvD+WRoXo=; b=X mJTT4+0J/nG32CHzWy7RITQaUtf6O55X0trZoGWciaoSQAmWqkJvcKIHOhNOtb/Y mO/T8OyVSWebAvK5FKH0Wv9lpfwewUPax0ITBNxr5pvh/IaHi3G3PaUsIz4LJZfl pW/1ST+fzWFEBm8Nri39TEahXrGFieIbaSyVhmnQnPzjYMx4vUgOD3+yLkPAZ5ad o+sDUIlJ6TnihtSXKmb0gDozj1Uc2Q17WpKmvx8ct5NnKjYFLKuDuMp0Iv8xWwuK wXyEIYP23XqfuOUBSJIMprzzlCURRUSoBW64awSx788I0ZkFIuEjRnkcz/qsuyGz ypjD4Tf/ohoo5TVvUHxEg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to:x-me-proxy:x-me-sender :x-me-sender:x-sasl-enc; s=fm3; t=1769784626; x=1769871026; bh=j Fkm6fmhGUS6Iee0jwQIzG56FRBVEb+3L9zvD+WRoXo=; b=BcMDDqkCRYIK2W2af u/wpnbEcMZS5YQxe2qa88m9sAYQfnzDkP8oGz3wmesMoa8mHZWRtX4N00xqs0Khe H8N4ODvuvHU4FEeS9o6uFpw34fDn945qvsIo1rUze+LnN+Of6Spc5s/ges8NN0es e01uNvfvZjKhbrvYoeNohft70iWOL7pckhEcedqcyiaCSPTkPl6t4Lhg+Rk8+8jA 3w0KkoXE3zhWByjaCmsy6BNXs+AWAgxlciMJXunWHmXFDQLzAfsCZn/h7teoytmM Vv8/j+P596oFltlkm0zLbyFfBUW/WhiAjjtW41Nl4zhZp1lMYoY5lAmN0ykiCLZY 8rfkA== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefgedrtddtgdduieelfedvucetufdoteggodetrf dotffvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfurfetoffkrfgpnffqhgenuceu rghilhhouhhtmecufedttdenucgfrhhlucfvnfffucdljedtmdenucfjughrpefhvfevuf ffkffojghfggfgsedtkeertdertddtnecuhfhrohhmpeevhhgrugculfgrsghlohhnshhk ihcuoegthhgrugesjhgrsghlohhnshhkihdrgiihiieqnecuggftrfgrthhtvghrnhepgf eiteejhfelheefieetjefgleejfffhueffvdduieejgfeuueeuvddvkeejhfelnecuvehl uhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomheptghhrggusehjrg gslhhonhhskhhirdighiiipdhnsggprhgtphhtthhopeefpdhmohguvgepshhmthhpohhu thdprhgtphhtthhopegsrghlrghtohhnsegvihhkrdgsmhgvrdhhuhdprhgtphhtthhope hqvghmuhdquggvvhgvlhesnhhonhhgnhhurdhorhhgpdhrtghpthhtoheptghhrggusehj rggslhhonhhskhhirdighiii X-ME-Proxy: Feedback-ID: ib26944c1:Fastmail From: Chad Jablonski To: qemu-devel@nongnu.org Cc: balaton@eik.bme.hu, Chad Jablonski Subject: [PATCH v6 17/20] ati-vga: Move source bounds validation to ati_2d_blt Date: Fri, 30 Jan 2026 09:50:02 -0500 Message-ID: <20260130145005.731129-18-chad@jablonski.xyz> X-Mailer: git-send-email 2.52.0 In-Reply-To: <20260130145005.731129-1-chad@jablonski.xyz> References: <20260130145005.731129-1-chad@jablonski.xyz> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=202.12.124.153; envelope-from=chad@jablonski.xyz; helo=fhigh-b2-smtp.messagingengine.com X-Spam_score_int: -2 X-Spam_score: -0.3 X-Spam_bar: / X-Spam_report: (-0.3 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FROM_SUSPICIOUS_NTLD=0.499, PDS_OTHER_BAD_TLD=1.999, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @jablonski.xyz) X-ZM-MESSAGEID: 1769784675291154100 Content-Type: text/plain; charset="utf-8" A call to ati_2d_blt implies that the source will be vram. Checking bounds is useful in that case. Other sources (HOST_DATA) will not make sense to check against vram bounds. Signed-off-by: Chad Jablonski --- hw/display/ati_2d.c | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/hw/display/ati_2d.c b/hw/display/ati_2d.c index 89a9d006af..3ff874c3ed 100644 --- a/hw/display/ati_2d.c +++ b/hw/display/ati_2d.c @@ -155,14 +155,6 @@ static void ati_2d_do_blt(ATI2DCtx *ctx, uint8_t use_p= ixman) return; } int src_stride_words =3D ctx->src_stride / sizeof(uint32_t); - if (ctx->src.x > 0x3fff || ctx->src.y > 0x3fff - || ctx->src_bits >=3D ctx->vram_end - || ctx->src_bits + ctx->src.x - + (ctx->src.y + ctx->dst.height) - * ctx->src_stride >=3D ctx->vram_end) { - qemu_log_mask(LOG_UNIMP, "blt outside vram not implemented\n"); - return; - } =20 DPRINTF("pixman_blt(%p, %p, %d, %d, %d, %d, %d, %d, %d, %d, %d, %d= )\n", ctx->src_bits, ctx->dst_bits, @@ -277,6 +269,14 @@ void ati_2d_blt(ATIVGAState *s) { ATI2DCtx ctx; setup_2d_blt_ctx(s, &ctx); + if (ctx.src.x > 0x3fff || ctx.src.y > 0x3fff + || ctx.src_bits >=3D ctx.vram_end + || ctx.src_bits + ctx.src.x + + (ctx.src.y + ctx.dst.height) + * ctx.src_stride >=3D ctx.vram_end) { + qemu_log_mask(LOG_UNIMP, "blt outside vram not implemented\n"); + return; + } ati_2d_do_blt(&ctx, s->use_pixman); ati_set_dirty(&s->vga, &ctx); } --=20 2.52.0