From nobody Mon Feb 9 16:29:27 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=jablonski.xyz ARC-Seal: i=1; a=rsa-sha256; t=1770223677; cv=none; d=zohomail.com; s=zohoarc; b=k2UMbPYeeW2AYUc98IQ5AgDytLE+AogTwnHAR3DuaHwXuhAdLyIcaNRGvwUiA53Kl9/TKXZt1O1sBdQobVEuEh6M+ChZmCuHeBZfoElPEyS21/aodnCksEk1UtYDXzGQlsahp3DYUUbfKns++dVsFsCa7lKoX+ZOEYJEZCwaYrw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1770223677; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=WHB7HXBOW3/SU+k+R5lQR6UvT5Yz3Ua6vmh5gkfmy7A=; b=AQGhLjKpM27HdbMs2/Te7/0DqoWKKvWosiA70FIAMeiy84ZKZWHgrnIzZAM5B3GbAaa3h72fmk2hJoTyDBnHu8WcI+cZeJjdwVrQDIEOqk0ZnYjNy7keF2samBGo4azhQoMSPr71Qt9J2BtPcIQWZaFs06zu2UxjVBXBUwFDe2Q= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1770223677720259.19820177186796; Wed, 4 Feb 2026 08:47:57 -0800 (PST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1vng1Y-0007Hv-Ft; Wed, 04 Feb 2026 11:46:40 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1vng1L-000745-Ls for qemu-devel@nongnu.org; Wed, 04 Feb 2026 11:46:28 -0500 Received: from fout-b7-smtp.messagingengine.com ([202.12.124.150]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1vng1K-0004Y7-3l for qemu-devel@nongnu.org; Wed, 04 Feb 2026 11:46:27 -0500 Received: from phl-compute-02.internal (phl-compute-02.internal [10.202.2.42]) by mailfout.stl.internal (Postfix) with ESMTP id 09A5A1D00175; Wed, 4 Feb 2026 11:46:15 -0500 (EST) Received: from phl-frontend-04 ([10.202.2.163]) by phl-compute-02.internal (MEProxy); Wed, 04 Feb 2026 11:46:15 -0500 Received: by mail.messagingengine.com (Postfix) with ESMTPA; Wed, 4 Feb 2026 11:46:14 -0500 (EST) Received: from localhost (chomposaur [local]) by chomposaur (OpenSMTPD) with ESMTPA id 8c0ca560; Wed, 4 Feb 2026 16:46:08 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jablonski.xyz; h=cc:cc:content-transfer-encoding:content-type:date:date:from :from:in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to; s=fm2; t=1770223574; x= 1770309974; bh=WHB7HXBOW3/SU+k+R5lQR6UvT5Yz3Ua6vmh5gkfmy7A=; b=U evrr9rSRS/kYdz82nlILkA3auvNQf+Rdm02Zin7F1CK6ntamRELCBEn7CV3Lsbew eB3Ibo0KIys3S1TFhSoStKQ4RMxYUtPgbas/+ag1QZPytRW1PTKideCLFsO21yiw 2xR+LJHOF+rdNvyLG7OvrjhhDIzo5Pw52ECx/eassXOeLufzKlFKTbuzFnwW/RP2 kZmwd0kK0Pi3yz2/L8+6OQN0j2GM7/ExReDrX9OYRSOh7NN9LpyM0c+95KARcG16 kLsO8EGagYBJUrTEqI43ixoNR2cdHjdtL9PseYxKRpjttKT8QpfJCG3089nhnh6p ahAzRPAbeMh3vtfrTY+gg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to:x-me-proxy:x-me-sender :x-me-sender:x-sasl-enc; s=fm3; t=1770223574; x=1770309974; bh=W HB7HXBOW3/SU+k+R5lQR6UvT5Yz3Ua6vmh5gkfmy7A=; b=GfJYdGSR8vJ213fIq 2YSFonkwNydIipkgHpqLn+Ni+sBByW7qpjWMRJKOTEWdWyO1qdcen/RBOJvAyiea 2VcvXqcsVBach+knO+dVjYkNzcQVWonIPV6E26/A+lUEGs5u9A1utB74k3u+AfsS YMg7rF0Jv3/LODN3fQva2rUTZfmxOSKD79F43eUSnrBEuOchThYBy+kjIV15rru0 O/OxNnjIh8vsNbqOMxSviNDyZntUcOAjQJtRnR+dmhkv1EQJp+nqJxE+iMgHxWoM 1cekVT6ouBNz36qZzxehoyhfu9hiCvDSUgWBqPHjbdiDVx8CBdwowXffYVHoxZcX S8zmw== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefgedrtddtgddukedvleehucetufdoteggodetrf dotffvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfurfetoffkrfgpnffqhgenuceu rghilhhouhhtmecufedttdenucgfrhhlucfvnfffucdljedtmdenucfjughrpefhvfevuf ffkffojghfggfgsedtkeertdertddtnecuhfhrohhmpeevhhgrugculfgrsghlohhnshhk ihcuoegthhgrugesjhgrsghlohhnshhkihdrgiihiieqnecuggftrfgrthhtvghrnhepgf eiteejhfelheefieetjefgleejfffhueffvdduieejgfeuueeuvddvkeejhfelnecuvehl uhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomheptghhrggusehjrg gslhhonhhskhhirdighiiipdhnsggprhgtphhtthhopeefpdhmohguvgepshhmthhpohhu thdprhgtphhtthhopehqvghmuhdquggvvhgvlhesnhhonhhgnhhurdhorhhgpdhrtghpth htoheptghhrggusehjrggslhhonhhskhhirdighiiipdhrtghpthhtohepsggrlhgrthho nhesvghikhdrsghmvgdrhhhu X-ME-Proxy: Feedback-ID: ib26944c1:Fastmail From: Chad Jablonski To: qemu-devel@nongnu.org Cc: balaton@eik.bme.hu, Chad Jablonski Subject: [PATCH v8 15/18] ati-vga: Move source bounds validation to ati_2d_blt Date: Wed, 4 Feb 2026 11:46:03 -0500 Message-ID: <20260204164606.3425246-16-chad@jablonski.xyz> X-Mailer: git-send-email 2.52.0 In-Reply-To: <20260204164606.3425246-1-chad@jablonski.xyz> References: <20260204164606.3425246-1-chad@jablonski.xyz> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=202.12.124.150; envelope-from=chad@jablonski.xyz; helo=fout-b7-smtp.messagingengine.com X-Spam_score_int: -2 X-Spam_score: -0.3 X-Spam_bar: / X-Spam_report: (-0.3 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FROM_SUSPICIOUS_NTLD=0.499, PDS_OTHER_BAD_TLD=1.999, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @jablonski.xyz) X-ZM-MESSAGEID: 1770223677889158500 Content-Type: text/plain; charset="utf-8" A call to ati_2d_blt implies that the source will be vram. Checking bounds is useful in that case. Other sources (HOST_DATA) will not make sense to check against vram bounds. Signed-off-by: Chad Jablonski Reviewed-by: BALATON Zoltan --- hw/display/ati_2d.c | 13 ++++++------- 1 file changed, 6 insertions(+), 7 deletions(-) diff --git a/hw/display/ati_2d.c b/hw/display/ati_2d.c index 8a820bc91f..463da001d9 100644 --- a/hw/display/ati_2d.c +++ b/hw/display/ati_2d.c @@ -153,13 +153,6 @@ static void ati_2d_do_blt(ATI2DCtx *ctx, uint8_t use_p= ixman) return; } int src_stride_words =3D ctx->src_stride / sizeof(uint32_t); - if (ctx->src.x > 0x3fff || ctx->src.y > 0x3fff - || ctx->src_bits >=3D ctx->vram_end - || ctx->src_bits + ctx->src.x + (ctx->src.y + ctx->dst.height) - * ctx->src_stride >=3D ctx->vram_end) { - qemu_log_mask(LOG_UNIMP, "blt outside vram not implemented\n"); - return; - } =20 DPRINTF("pixman_blt(%p, %p, %d, %d, %d, %d, %d, %d, %d, %d, %d, %d= )\n", ctx->src_bits, ctx->dst_bits, src_stride_words, @@ -267,6 +260,12 @@ void ati_2d_blt(ATIVGAState *s) { ATI2DCtx ctx; setup_2d_blt_ctx(s, &ctx); + if (ctx.src.x > 0x3fff || ctx.src.y > 0x3fff + || ctx.src_bits >=3D ctx.vram_end || ctx.src_bits + ctx.src.x + + (ctx.src.y + ctx.dst.height) * ctx.src_stride >=3D ctx.vram_end= ) { + qemu_log_mask(LOG_UNIMP, "blt outside vram not implemented\n"); + return; + } ati_2d_do_blt(&ctx, s->use_pixman); ati_set_dirty(&s->vga, &ctx); } --=20 2.52.0