From nobody Tue Aug 25 00:45:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1779486940; cv=none; d=zohomail.com; s=zohoarc; b=ZkOP+8LI/pec+bXmjkslKoej2pz3zUqUJCudpHIrU1LQJ65Vitl2CHIOnPGO7Rruv+ZTs2GGuumbHcNApOJFcnav1goLbWPDUTzzyu2xr4v3qHbQKMq5VXEuUP5icv9E93mJ/eaJjO3NQxUlRjW7KinOKszHigH0d7lQTOXDaVY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1779486940; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=MH8s54HgoCkNvbvV80TY1a65+7U3ht5lT6SyUgOE1lk=; b=V4/MyOT4gVRHiONvbg38noe3WjlV4WAur8yEsOpbnCEeN53H/2Gt/JaHUqTAqxKazfKXKk14X94xVq1nYE+uzkmqA3woqGwkIK4cDIvc7VmgErNjh+o6dJJkGtDhW6XcXUmNjeR05f4rA+sP4GYuvtAct4o3rB4X5yARVYVb7zg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1779486940583752.4531295323887; Fri, 22 May 2026 14:55:40 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wQXmv-0003eq-8m; Fri, 22 May 2026 17:52:13 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wQXmR-0002e2-DP; Fri, 22 May 2026 17:51:43 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wQXmL-0003om-53; Fri, 22 May 2026 17:51:42 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id BBD501AFB73; Sat, 23 May 2026 00:49:20 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id E2E533B71C2; Sat, 23 May 2026 00:49:24 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1779486560; bh=nSbJccUXo9jKpv2H2W8hWaOn1ytKiY+C0ZzYGiaskuM=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=TZFhN1AUWVrfKWrB/zec0Xmo7tJgwM0c6cu4lhCtjnKPA+a3H32bVgc/gGJPKVmT6 FwTfQrwNz1Kg2DWcbMUTCytoP+4DdyVof1FEnOcQOdJ2q36wIMtYRLU7KDqHqNmJNY GlVjLMvehvA/dqD38e+iVgb4r0v84mp5f8OmdVv2dVl6dw+3KCsxX60+9MSn6zQEuW gi0V93Gqk1M4kUMwneWGk/Hw68IbKjY6Z831mvAsiq7K3ARPysZdMehamMFOjkdWzI GLppQkIGxJKTjdboXsgcmNoFiEOdT9zPJdcQBO9TYnuKDKOJoMRtwkwzXTpaj+lYN1 iV95LbUTewJ6w== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , Junjie Cao , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Michael Tokarev Subject: [Stable-10.2.3 125/149] hw/display/cirrus_vga: Fix packed-24 color-expansion transparent copies Date: Sat, 23 May 2026 00:48:57 +0300 Message-ID: <20260522214923.807017-26-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1779486942719154100 From: Peter Maydell For the "color expansion" subtype of raster operations, the source pixel format is a monochrome bitmap, and the destination can be any of 8, 16, 24 or 32bpp. For these pattern operations, the GR2F register includes a field which specifies how much to skip at the start of each scanline. In the 8, 16 and 32 bit cases, this field is 3 bits and is a count of pixels to skip. We get this case right. However, for the 24 bit case, the field is 5 bits and is a count of destination bytes to skip. In commit ad81218e40e27 ("depth=3D24 write mask fix (Volker Ruppert)") in 2005, we updated the code to (attempt to) handle the 5-bit mask case. However, we don't do the right thing when the 5-bit mask indicates that we need to skip more than 8 bits of the input bitmap: we will right-shift the 0x80 constant completely off the right hand side, and will be off-by-one for all the source bitmap loads. Fix this by calculating the whole number of input bytes we need to skip and the residual number of bits. In the 8/16/32bpp case the bytes to skip is always zero. Cc: qemu-stable@nongnu.org Fixes: ad81218e40e27 ("depth=3D24 write mask fix (Volker Ruppert)") Signed-off-by: Peter Maydell Reviewed-by: Junjie Cao Tested-by: Junjie Cao Message-ID: <20260410183249.4046456-3-peter.maydell@linaro.org> Signed-off-by: Philippe Mathieu-Daud=C3=A9 (cherry picked from commit 27d14251b904e6dd60c1053a893b52e085f48a3a) Signed-off-by: Michael Tokarev diff --git a/hw/display/cirrus_vga_rop2.h b/hw/display/cirrus_vga_rop2.h index 8be35ec6e2..33f9b3b613 100644 --- a/hw/display/cirrus_vga_rop2.h +++ b/hw/display/cirrus_vga_rop2.h @@ -108,12 +108,34 @@ glue(glue(glue(cirrus_colorexpand_transp_, ROP_NAME),= _),DEPTH) unsigned int col; unsigned bitmask; unsigned index; + + /* + * Raster ops where the source is a monochrome bitmap with + * color expansion to 8/16/24/32bpp destination. + */ + #if DEPTH =3D=3D 24 + /* + * For packed-24 modes, GR2F bits [4:0] are a count of destination + * bytes to be suppressed for each scanline, which we keep in + * dstskipleft. We want to track the number of whole bytes + * to skip in the source (always either 0 or 1) and the number + * of bits within the byte to skip. + */ int dstskipleft =3D s->vga.gr[0x2f] & 0x1f; - int srcskipleft =3D dstskipleft / 3; + int srcskipleftbits =3D (dstskipleft / 3) & 0x7; + int srcskipleftbytes =3D (dstskipleft / 3) >> 3; #else - int srcskipleft =3D s->vga.gr[0x2f] & 0x07; - int dstskipleft =3D srcskipleft * (DEPTH / 8); + /* + * In all other modes, GR2F bits [2:0] are a count of how many + * destination pixels to suppress for each scanline, which is our + * srcskipleftbits. We get dstskipleft, the number of bytes to + * skip, by multiplying this by the bytes-per-pixel. In these + * modes we never need to skip an entire source byte. + */ + int srcskipleftbits =3D s->vga.gr[0x2f] & 0x07; + int srcskipleftbytes =3D 0; + int dstskipleft =3D srcskipleftbits * (DEPTH / 8); #endif =20 if (s->cirrus_blt_modeext & CIRRUS_BLTMODEEXT_COLOREXPINV) { @@ -125,7 +147,8 @@ glue(glue(glue(cirrus_colorexpand_transp_, ROP_NAME), _= ),DEPTH) } =20 for(y =3D 0; y < bltheight; y++) { - bitmask =3D 0x80 >> srcskipleft; + bitmask =3D 0x80 >> srcskipleftbits; + srcaddr +=3D srcskipleftbytes; bits =3D cirrus_src(s, srcaddr++) ^ bits_xor; addr =3D dstaddr + dstskipleft; for (x =3D dstskipleft; x < bltwidth; x +=3D (DEPTH / 8)) { --=20 2.47.3