From nobody Sat Feb 28 02:46:08 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=jablonski.xyz ARC-Seal: i=1; a=rsa-sha256; t=1772224940; cv=none; d=zohomail.com; s=zohoarc; b=bdkiEH1jjESYwrWHmuEMr7VLjkRc4TyRxN9x8F+aE7kG+F7wBU/eOXKboEwZBIMXsPEnbk3mvEOYCmcAZ6p9pxrm0hc7mT3PH4uKu3lN7gg8+0nCGEvZdpjdqAMMDZ2Rink4Q95UVCDXosRAkvyDc+OkTx2Uz2iZf1JMCAIrjJI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1772224940; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=RDbi4ttHSzdqquBLMjV4+kyLt9CNxdkTZv/NdVntPT4=; b=PXMCTF9/A8sIXRy3FcgpF2B1fhvO90x+m4E868wduspBdwl2HGO5W1dDV35dfhNW/QxspqCrTTw8dgFpTP4gjlhJL7ENzRc8NVx7M+8cCf68QkuzRguaKzbNWt5RiNf0JA7gIRKpNNkAI48AIKnhBToWLix/OM7JdeJKukI+nLg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 17722249402331021.8419635461497; Fri, 27 Feb 2026 12:42:20 -0800 (PST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1vw4eX-0003Oj-Iw; Fri, 27 Feb 2026 15:41:37 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1vw4eC-0002c8-MF for qemu-devel@nongnu.org; Fri, 27 Feb 2026 15:41:16 -0500 Received: from fhigh-a7-smtp.messagingengine.com ([103.168.172.158]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1vw4eB-0007Qj-5A for qemu-devel@nongnu.org; Fri, 27 Feb 2026 15:41:16 -0500 Received: from phl-compute-04.internal (phl-compute-04.internal [10.202.2.44]) by mailfhigh.phl.internal (Postfix) with ESMTP id 8CAE6140018E; Fri, 27 Feb 2026 15:41:01 -0500 (EST) Received: from phl-frontend-03 ([10.202.2.162]) by phl-compute-04.internal (MEProxy); Fri, 27 Feb 2026 15:41:01 -0500 Received: by mail.messagingengine.com (Postfix) with ESMTPA; Fri, 27 Feb 2026 15:41:01 -0500 (EST) Received: from localhost (chomposaur [local]) by chomposaur (OpenSMTPD) with ESMTPA id 7f897a38; Fri, 27 Feb 2026 20:40:55 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jablonski.xyz; h=cc:cc:content-transfer-encoding:content-type:date:date:from :from:in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to; s=fm2; t=1772224861; x= 1772311261; bh=RDbi4ttHSzdqquBLMjV4+kyLt9CNxdkTZv/NdVntPT4=; b=L XjUivcWSfsexWCdRmcyuO+dyA6A8u3mOOCTBgs22sZ8OSzx3DH5SBReiuCPB6gfG YSyRBOLY9Q9/5gSMuHF0QSZNNApycr4NDBSna14i5WViIZvVu8yy+2yslnC1GjoJ ecxDPxsfaG9gVH9VrXpKN37rAcw/HJCfc6NNFDqYI9M/1g74s3jYMRtgIA6t/9nL 2IpPnDU/c4LVUPSjM9GkpccCplTSiYiM4PvvAqLb1wNycmUgPrQLISSufMP2l4hy EJthGXhMHHOxt9mIjg3QzjVlJI6roUqzxRaxlKW2IqrQLC35rDKWK7hTNJX4mSE0 2FwOcruhcqeKrU5L5kyIg== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:subject:subject:to:to:x-me-proxy:x-me-sender :x-me-sender:x-sasl-enc; s=fm3; t=1772224861; x=1772311261; bh=R Dbi4ttHSzdqquBLMjV4+kyLt9CNxdkTZv/NdVntPT4=; b=rzofRfbYtTebl8L2V FBwjsReIk3dmyAPPd6HRzpYtk/wlPTGr09NYUbVAkePn+PDyhpq+ywMn25NlSG88 PqMQqieoDWtlTZp1WuGMOJJ/FC68wvtMKig3SNXCJJS1QY2juJ91+x36skG9KPjW XQTdy/XloX+HKzVjGnpMikLwl9elJtopNzJJKGhPXSnyG760YrIC2VNMZBCRIZ1z LHpF1MMuX3fgSEHq5PiiP5+YBaOVjPfgukqp+4FREzOBkNxeaz78dfSjCGENMvXQ Pyu7beNCfYCz69FIsbMIHDBu3cpwN8zaDWoAUVUA+SFN/a86XPUjGjqiYoqYjH18 LJSSw== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeefgedrtddtgddvgeelleelucetufdoteggodetrf dotffvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfurfetoffkrfgpnffqhgenuceu rghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmnegfrh hlucfvnfffucdljedtmdenucfjughrpefhvfevufffkffojghfggfgsedtkeertdertddt necuhfhrohhmpeevhhgrugculfgrsghlohhnshhkihcuoegthhgrugesjhgrsghlohhnsh hkihdrgiihiieqnecuggftrfgrthhtvghrnhepgfeiteejhfelheefieetjefgleejfffh ueffvdduieejgfeuueeuvddvkeejhfelnecuvehluhhsthgvrhfuihiivgepudenucfrrg hrrghmpehmrghilhhfrhhomheptghhrggusehjrggslhhonhhskhhirdighiiipdhnsggp rhgtphhtthhopeehpdhmohguvgepshhmthhpohhuthdprhgtphhtthhopehqvghmuhdqug gvvhgvlhesnhhonhhgnhhurdhorhhgpdhrtghpthhtohepmhgrrhgtrghnughrvgdrlhhu rhgvrghusehrvgguhhgrthdrtghomhdprhgtphhtthhopehkrhgrgigvlhesrhgvughhrg htrdgtohhmpdhrtghpthhtohepsggrlhgrthhonhesvghikhdrsghmvgdrhhhupdhrtghp thhtoheptghhrggusehjrggslhhonhhskhhirdighiii X-ME-Proxy: Feedback-ID: ib26944c1:Fastmail From: Chad Jablonski To: qemu-devel@nongnu.org Cc: BALATON Zoltan , Gerd Hoffmann , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Chad Jablonski Subject: [PATCH v9 15/18] ati-vga: Move source bounds validation to ati_2d_blt Date: Fri, 27 Feb 2026 15:39:41 -0500 Message-ID: <20260227203944.746471-16-chad@jablonski.xyz> X-Mailer: git-send-email 2.52.0 In-Reply-To: <20260227203944.746471-1-chad@jablonski.xyz> References: <20260227203944.746471-1-chad@jablonski.xyz> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=103.168.172.158; envelope-from=chad@jablonski.xyz; helo=fhigh-a7-smtp.messagingengine.com X-Spam_score_int: 8 X-Spam_score: 0.8 X-Spam_bar: / X-Spam_report: (0.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FROM_SUSPICIOUS_NTLD=0.5, PDS_OTHER_BAD_TLD=1.999, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.706, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.401, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @jablonski.xyz) X-ZM-MESSAGEID: 1772224941638158500 Content-Type: text/plain; charset="utf-8" A call to ati_2d_blt implies that the source will be vram. Checking bounds is useful in that case. Other sources (HOST_DATA) will not make sense to check against vram bounds. Signed-off-by: Chad Jablonski Reviewed-by: BALATON Zoltan --- Changes from v8: The source bound validation was being performed in all cases, even for blits that weren't using the source. It now limits the validation to the ROP3_SRCCOPY case. --- hw/display/ati_2d.c | 19 +++++++++---------- 1 file changed, 9 insertions(+), 10 deletions(-) diff --git a/hw/display/ati_2d.c b/hw/display/ati_2d.c index 440c1d159a..dbc8791824 100644 --- a/hw/display/ati_2d.c +++ b/hw/display/ati_2d.c @@ -138,9 +138,9 @@ static void ati_2d_do_blt(ATI2DCtx *ctx, uint8_t use_pi= xman) return; } int dst_stride_words =3D ctx->dst_stride / sizeof(uint32_t); - if (ctx->dst.x > 0x3fff || ctx->dst.y > 0x3fff - || ctx->dst_bits >=3D ctx->vram_end || ctx->dst_bits + ctx->dst.x - + (ctx->dst.y + ctx->dst.height) * ctx->dst_stride >=3D ctx->vram= _end) { + if (ctx->dst.x > 0x3fff || ctx->dst.y > 0x3fff || + ctx->dst_bits >=3D ctx->vram_end || ctx->dst_bits + ctx->dst.x + + (ctx->dst.y + ctx->dst.height) * ctx->dst_stride >=3D ctx->vram_en= d) { qemu_log_mask(LOG_UNIMP, "blt outside vram not implemented\n"); return; } @@ -153,13 +153,6 @@ static void ati_2d_do_blt(ATI2DCtx *ctx, uint8_t use_p= ixman) return; } int src_stride_words =3D ctx->src_stride / sizeof(uint32_t); - if (ctx->src.x > 0x3fff || ctx->src.y > 0x3fff - || ctx->src_bits >=3D ctx->vram_end - || ctx->src_bits + ctx->src.x + (ctx->src.y + ctx->dst.height) - * ctx->src_stride >=3D ctx->vram_end) { - qemu_log_mask(LOG_UNIMP, "blt outside vram not implemented\n"); - return; - } =20 DPRINTF("pixman_blt(%p, %p, %d, %d, %d, %d, %d, %d, %d, %d, %d, %d= )\n", ctx->src_bits, ctx->dst_bits, src_stride_words, @@ -268,6 +261,12 @@ void ati_2d_blt(ATIVGAState *s) { ATI2DCtx ctx; setup_2d_blt_ctx(s, &ctx); + if (ctx.rop3 =3D=3D ROP3_SRCCOPY && (ctx.src.x > 0x3fff || ctx.src.y >= 0x3fff || + ctx.src_bits >=3D ctx.vram_end || ctx.src_bits + ctx.src.x + + (ctx.src.y + ctx.dst.height) * ctx.src_stride >=3D ctx.vram_end)) { + qemu_log_mask(LOG_UNIMP, "blt outside vram not implemented\n"); + return; + } ati_2d_do_blt(&ctx, s->use_pixman); ati_set_dirty(&s->vga, &ctx); } --=20 2.52.0