From nobody Tue Feb 10 18:55:54 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=jablonski.xyz ARC-Seal: i=1; a=rsa-sha256; t=1770065480; cv=none; d=zohomail.com; s=zohoarc; b=KvNSWaJSX+hv5iReyfAJBj2evCiHnvNs5k21Zu19zhB5gHm/rPhZR6eideEIww2DL1NtH7uPEnTXoRb/eenJcoouS5SkSBEI3PcbAEBEax/L6JVciXDF/Sc57l204AGLb0qEVH5rSHvFAZRaPhrtCNQioN3hl8MAZyvGaaAzvjw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1770065480; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=gx3Da9YMvZQEvf4t7Zwfk28zoTGZPSETN0NVxxGKBm8=; b=chiV/+Qi/lbrcSzPiuzlxjsZjXvDebeDBgRWLh7CjREBPDdtIIuzKbRjX94OIiSmyYBy4bYPywvzPLCNPrTl1h24huXw/6MohIuT17+pNxpm0CoyMm6qXV7W8rC6L9EGDj+CzzjSGj8k3TQTrDrwHprICZhG/iRTE6ccCySllfs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1770065480202165.70020847888338; Mon, 2 Feb 2026 12:51:20 -0800 (PST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1vn0rC-00012m-Es; Mon, 02 Feb 2026 15:49:19 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1vn0q5-0007Ky-H9 for qemu-devel@nongnu.org; Mon, 02 Feb 2026 15:48:07 -0500 Received: from fout-b4-smtp.messagingengine.com ([202.12.124.147]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1vn0q2-0001p3-W6 for qemu-devel@nongnu.org; Mon, 02 Feb 2026 15:48:04 -0500 Received: from phl-compute-04.internal (phl-compute-04.internal [10.202.2.44]) by mailfout.stl.internal (Postfix) with ESMTP id A62AB1D0012B; Mon, 2 Feb 2026 15:48:00 -0500 (EST) Received: from phl-frontend-04 ([10.202.2.163]) by phl-compute-04.internal (MEProxy); Mon, 02 Feb 2026 15:48:00 -0500 Received: by mail.messagingengine.com (Postfix) with ESMTPA; Mon, 2 Feb 2026 15:48:00 -0500 (EST) Received: from localhost (chomposaur [local]) by chomposaur (OpenSMTPD) with ESMTPA id 8f18439c; Mon, 2 Feb 2026 20:47:53 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jablonski.xyz; h=cc:cc:content-transfer-encoding:content-type:date:date:from :from:in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to; s=fm2; t=1770065280; x= 1770151680; bh=gx3Da9YMvZQEvf4t7Zwfk28zoTGZPSETN0NVxxGKBm8=; b=n vppRLbXlPfOA6NTn3IqjMAAwIanI4tTifJNHzxj6E3q3jfPqNsP5mIZycXX7YRW8 G1qDgKT6c5JSxBQknbI36jaszRUKIBYuUg1j4HyIbED3It2TvNUaEJCbjQeQJ+Wa xwVwxLJXdAJSuSZCSsENbiEMBL4Km6uldm8o7P+FdAqqNnpfVx9WXhcLmnsHOef+ y7wVrKh32ngxWgIa6LpBz5zJ12np3JsHriu4BlSWmMVGBWXKLTuARvVdjwtOE82s TcZPPpZeGFyQMABy69odlRmNCtQCN12R2i/PVE6RvTT6Mn69eZmc4LjMEzkKl8QM qkCDSxYIHwbf0Y4JHY3Vg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to:x-me-proxy:x-me-sender :x-me-sender:x-sasl-enc; s=fm3; t=1770065280; x=1770151680; bh=g x3Da9YMvZQEvf4t7Zwfk28zoTGZPSETN0NVxxGKBm8=; b=MnykO9WIYlA7KxnTm pb7dSBGXFzfgPet2Rdyb6dj749oekkHn6vuPiJetFYoWnPRd0zqZWAsVkPyOrp7f N8CjNdy35SHM4mY8cmU8OubC7BNOsa/0bgV6UdHtebLntqnrbZtmknOFuNddL2My gscvgv8FCR5Lk2JL6CoKUja0DAtDDChuZmOsB+jbUwT1KAvB2YahLbgbKyFoLM3o ginb/x1DJpsaY/3ha7t9BNo97kQPVj0rncjxWHgwIICkdeLNQXoG9UScuU1m9Qpv gaF2MvQABgMbnAIpGAAvFQJBWdxclFlUMOZXROmgRCxG9J0+kf3Y+pF4OJQuufW3 bHSXQ== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefgedrtddtgddujeekieegucetufdoteggodetrf dotffvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfurfetoffkrfgpnffqhgenuceu rghilhhouhhtmecufedttdenucgfrhhlucfvnfffucdljedtmdenucfjughrpefhvfevuf ffkffojghfggfgsedtkeertdertddtnecuhfhrohhmpeevhhgrugculfgrsghlohhnshhk ihcuoegthhgrugesjhgrsghlohhnshhkihdrgiihiieqnecuggftrfgrthhtvghrnhepgf eiteejhfelheefieetjefgleejfffhueffvdduieejgfeuueeuvddvkeejhfelnecuvehl uhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomheptghhrggusehjrg gslhhonhhskhhirdighiiipdhnsggprhgtphhtthhopeefpdhmohguvgepshhmthhpohhu thdprhgtphhtthhopehqvghmuhdquggvvhgvlhesnhhonhhgnhhurdhorhhgpdhrtghpth htoheptghhrggusehjrggslhhonhhskhhirdighiiipdhrtghpthhtohepsggrlhgrthho nhesvghikhdrsghmvgdrhhhu X-ME-Proxy: Feedback-ID: ib26944c1:Fastmail From: Chad Jablonski To: qemu-devel@nongnu.org Cc: balaton@eik.bme.hu, Chad Jablonski Subject: [PATCH v7 16/19] ati-vga: Move source bounds validation to ati_2d_blt Date: Mon, 2 Feb 2026 15:47:34 -0500 Message-ID: <20260202204738.3080092-17-chad@jablonski.xyz> X-Mailer: git-send-email 2.52.0 In-Reply-To: <20260202204738.3080092-1-chad@jablonski.xyz> References: <20260202204738.3080092-1-chad@jablonski.xyz> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=202.12.124.147; envelope-from=chad@jablonski.xyz; helo=fout-b4-smtp.messagingengine.com X-Spam_score_int: -2 X-Spam_score: -0.3 X-Spam_bar: / X-Spam_report: (-0.3 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FROM_SUSPICIOUS_NTLD=0.499, PDS_OTHER_BAD_TLD=1.999, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @jablonski.xyz) X-ZM-MESSAGEID: 1770065482212158500 Content-Type: text/plain; charset="utf-8" A call to ati_2d_blt implies that the source will be vram. Checking bounds is useful in that case. Other sources (HOST_DATA) will not make sense to check against vram bounds. Signed-off-by: Chad Jablonski --- hw/display/ati_2d.c | 16 ++++++++-------- 1 file changed, 8 insertions(+), 8 deletions(-) diff --git a/hw/display/ati_2d.c b/hw/display/ati_2d.c index e1e48ac81f..4b16265733 100644 --- a/hw/display/ati_2d.c +++ b/hw/display/ati_2d.c @@ -152,14 +152,6 @@ static void ati_2d_do_blt(ATI2DCtx *ctx, uint8_t use_p= ixman) return; } int src_stride_words =3D ctx->src_stride / sizeof(uint32_t); - if (ctx->src.x > 0x3fff || ctx->src.y > 0x3fff - || ctx->src_bits >=3D ctx->vram_end - || ctx->src_bits + ctx->src.x - + (ctx->src.y + ctx->dst.height) - * ctx->src_stride >=3D ctx->vram_end) { - qemu_log_mask(LOG_UNIMP, "blt outside vram not implemented\n"); - return; - } =20 DPRINTF("pixman_blt(%p, %p, %d, %d, %d, %d, %d, %d, %d, %d, %d, %d= )\n", ctx->src_bits, ctx->dst_bits, @@ -275,6 +267,14 @@ void ati_2d_blt(ATIVGAState *s) { ATI2DCtx ctx; setup_2d_blt_ctx(s, &ctx); + if (ctx.src.x > 0x3fff || ctx.src.y > 0x3fff + || ctx.src_bits >=3D ctx.vram_end + || ctx.src_bits + ctx.src.x + + (ctx.src.y + ctx.dst.height) + * ctx.src_stride >=3D ctx.vram_end) { + qemu_log_mask(LOG_UNIMP, "blt outside vram not implemented\n"); + return; + } ati_2d_do_blt(&ctx, s->use_pixman); ati_set_dirty(&s->vga, &ctx); } --=20 2.52.0