From nobody Sun Jul 26 11:03:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1783359256; cv=none; d=zohomail.com; s=zohoarc; b=OegaGLzMfPP/tKqf5QvM4UqfPHciRhfdMbiXrx8pnjW7sScZH02EZ3/peGXCsBKSjct4wOrlvpxbv8Fu8yd4/5tO/uK4X6KqWADg+MLVdZc7uB1LAbFp03iIv5ccpbFdBKSenG4y2Y4uh58+X0SUP9KprR/o9/+uRYfTy23IlD8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783359256; h=Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=kMkmNSdkpmxypOmCNIZ6s6HhJiiuCbTO1iVZOoCp2tM=; b=dhsKOjn8udkJqVDYHm1OdLZRmsltMwYVj/d1TZOZtS4ALrm+ObjS4vHJtfVfk+OtWdGFsNEilO6aqlg9wSLVoptXRF2RX0YbI9Fy8jYptSfX0Cukz08eU60mm7XZsCQCyEmsQYon9ZZ2R1Er2UbA8kAEHKRoEF7llW61Mbj9be0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783359256271737.6357173918972; Mon, 6 Jul 2026 10:34:16 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgnCZ-0007Li-K1; Mon, 06 Jul 2026 13:33:51 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgnCH-0007Dz-8g for qemu-devel@nongnu.org; Mon, 06 Jul 2026 13:33:34 -0400 Received: from mail-wm1-x332.google.com ([2a00:1450:4864:20::332]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wgnCF-00045j-2D for qemu-devel@nongnu.org; Mon, 06 Jul 2026 13:33:32 -0400 Received: by mail-wm1-x332.google.com with SMTP id 5b1f17b1804b1-493d3135f62so11988915e9.2 for ; Mon, 06 Jul 2026 10:33:28 -0700 (PDT) Received: from lanath.. (wildly.archaic.org.uk. [81.2.115.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-493e006b6besm467365e9.2.2026.07.06.10.33.26 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 06 Jul 2026 10:33:26 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1783359208; x=1783964008; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to; bh=kMkmNSdkpmxypOmCNIZ6s6HhJiiuCbTO1iVZOoCp2tM=; b=yIIQQxwpohcTO/AUkHLr04UjSVprH+M4SHOek2aePr/n5OqeiNxD/TdDH1HBthdOTZ 6ektiSSx2yp0E3wGQc3+gTf9yL+ZYwuH+akDhaH9SiHQ89vGYoVbXGrTma28lxKdt+5d fFywTFJ1aY2SfHgl54+1UQTkvzRK+nRl37xhq8V/ZZWTbPIwNgg23VTDXwGPSMfZ78ti VHw8s3YB5aWfmv1uFKyck4GLFABd/xNkN+gIriIdcUoKKA1QclpiJoJw+UN1fZ8RP6Qq XppHvzHCrsDiN0HzT/gtOqrYxOda7i4Xk/8pIQJsK+SJTG8/wBl/2D0kWqSTRqKuzdC6 ninw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783359208; x=1783964008; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=kMkmNSdkpmxypOmCNIZ6s6HhJiiuCbTO1iVZOoCp2tM=; b=SGI3dgvz73ePJckLuzGKtJCzKv9euc/gJ2Ibt44QoHf4W9SOly30O3WRU4ctVMP9eY i9YrZaTfvakLqIiQOsfzZF/mcfp47vfjFBW3yfy7U1RRf8vfzQt7hhKQ2ssEHGRssjIw DvYAbmuvIXFvZOu45qfQuLRPJl5/9wtnX/xzkrGH1bK5lYG+NAzZUzexz4J6h7kGoOwO FYGd0dcz7TPUlYUNFQu0+qWIroaupMyrhk3HGFeHDdEtZq77IenHPubYQWGenR8uWFgj JsBQgvShxAp4JfI12SToEzjzY0Ig5v1rJU1ZKYW+IxxIFLdwOXVXPxeQJJwCjc8XIkSj qHdA== X-Forwarded-Encrypted: i=1; AHgh+RqIXQIWCtkNUbq6jLoQYgNc4DxrHUHFDSEfSjDU/8+tFiKAaVIO7CWWPgrgQa4akJ+wFQpoMbSsW69q@nongnu.org X-Gm-Message-State: AOJu0Yw7Kjsg50mSB+tF2ZE7ir4ODipGMUY4K6c84OunRZAZKz9gs+Fd sviWVBAgL0PkmA+0tsSUXnPdag6IXV9l2GKRQOYcGm1txxQ4N2rf6wEqzQL3MrDG1JM= X-Gm-Gg: AfdE7cnI0EOSbUkx9f1jsKjBEbTYtPU2mJ7TWZZl1m8VtMEaSYnsc5BW8MYv7oAFtMG g3BshetB4cBGGit4/F3FSB+y+8SaFzOxqn8uXaWlGUosLg1BWC5o7mTbBghoxrI769jSbGYmoia 0C5UyRNzdZtHoQ4UlWqLXZuaZYEOerQWumcdEHZx8nIYdbP7PxWIVJcNdFNDUfPIj83I/EnK89Y 1eqP6C4bTIL2f+sOncaM1Cy4+rqMfZ5Wa/8cb/rsuNP9Vt+z5DP+OBTp/X7myRsvLGPPAcnv6mo RJkZUjHgE/P2H7TEIHD7+SaVdWrUDKcE4de+tnukUaQasghJW1opg+Dq9N+loxXY6iMF7quBi8a iNlvKgJdlHdp1eP1OckYWtSVAhrIBB+YP6muuJIB1IsRWXKFdymW27TcMyiel6wKrh4hhrclx8z 4r43IaoJif0IzxAEclSw3nNJkXlP16G98LZfmAG3Q41SzaHyIX/wwzByMHGX1fdyjNA5qFesfrN lFkxJQ/jKpFwZf7hWaHpA== X-Received: by 2002:a05:600c:37ce:b0:492:4363:e7d6 with SMTP id 5b1f17b1804b1-493df0777bemr19584785e9.37.1783359207262; Mon, 06 Jul 2026 10:33:27 -0700 (PDT) From: Peter Maydell To: qemu-arm@nongnu.org, qemu-devel@nongnu.org Subject: [PATCH 1/3] hw/display/exynos4210_fimd: Factor out finding screen width/height Date: Mon, 6 Jul 2026 18:33:22 +0100 Message-ID: <20260706173324.804340-2-peter.maydell@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706173324.804340-1-peter.maydell@linaro.org> References: <20260706173324.804340-1-peter.maydell@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::332; envelope-from=peter.maydell@linaro.org; helo=mail-wm1-x332.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1783359257509158500 Content-Type: text/plain; charset="utf-8" Currently we hard-code the expressions for getting the global screen width and height out of the VIDTCON2 register where we need them. Use functions instead. Make the global_width variable in exynos4210_fimd_update() uint32_t for consistency. (The values are clamped to well below INT_MAX, so there is no overflow risk here.) Stable CC because this is a prerequisite for an upcoming bugfix commit. Cc: qemu-stable@nongnu.org Signed-off-by: Peter Maydell --- hw/display/exynos4210_fimd.c | 22 ++++++++++++++++------ 1 file changed, 16 insertions(+), 6 deletions(-) diff --git a/hw/display/exynos4210_fimd.c b/hw/display/exynos4210_fimd.c index 7507e4fd3c..43ad5fa0b4 100644 --- a/hw/display/exynos4210_fimd.c +++ b/hw/display/exynos4210_fimd.c @@ -1195,15 +1195,25 @@ static void exynos4210_fimd_update_irq(Exynos4210fi= mdState *s) } } =20 +static uint32_t exynos4210_fimd_global_width(Exynos4210fimdState *s) +{ + return ((s->vidtcon[2] >> FIMD_VIDTCON2_HOR_SHIFT) & + FIMD_VIDTCON2_SIZE_MASK) + 1; +} + +static uint32_t exynos4210_fimd_global_height(Exynos4210fimdState *s) +{ + return ((s->vidtcon[2] >> FIMD_VIDTCON2_VER_SHIFT) & + FIMD_VIDTCON2_SIZE_MASK) + 1; +} + static void exynos4210_update_resolution(Exynos4210fimdState *s) { DisplaySurface *surface =3D qemu_console_surface(s->console); =20 /* LCD resolution is stored in VIDEO TIME CONTROL REGISTER 2 */ - uint32_t width =3D ((s->vidtcon[2] >> FIMD_VIDTCON2_HOR_SHIFT) & - FIMD_VIDTCON2_SIZE_MASK) + 1; - uint32_t height =3D ((s->vidtcon[2] >> FIMD_VIDTCON2_VER_SHIFT) & - FIMD_VIDTCON2_SIZE_MASK) + 1; + uint32_t width =3D exynos4210_fimd_global_width(s); + uint32_t height =3D exynos4210_fimd_global_height(s); =20 if (s->ifb =3D=3D NULL || surface_width(surface) !=3D width || surface_height(surface) !=3D height) { @@ -1229,14 +1239,14 @@ static bool exynos4210_fimd_update(void *opaque) bool blend =3D false; uint8_t *host_fb_addr; bool is_dirty =3D false; - int global_width; + uint32_t global_width; =20 if (!s || !s->console || !s->enabled || surface_bits_per_pixel(qemu_console_surface(s->console)) =3D=3D 0)= { return true; } =20 - global_width =3D (s->vidtcon[2] & FIMD_VIDTCON2_SIZE_MASK) + 1; + global_width =3D exynos4210_fimd_global_width(s); exynos4210_update_resolution(s); surface =3D qemu_console_surface(s->console); =20 --=20 2.43.0 From nobody Sun Jul 26 11:03:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1783359269; cv=none; d=zohomail.com; s=zohoarc; b=SOO9fCQvmPFJfNtYpATooBcLXdzhkJy27dNZdewCiAjHgaiKuM2vlaYS5eXLvJHtZePjIJSEIseQwHFadXbW01BH6iFWY8rTypHiuPiwE3sWWbjAphspp3tv7izeSeuO9kbbPUkgA0UBoj2UFxMyKU2fdgHLQO0UAvRJLBl+ItE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783359269; h=Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=A0FNVhKwjG3aDw/GRmOzMnN8MY+Svb77ZDzchT5mAYc=; b=Ccz4PiFnZ2X0ZUUOHk8W8TFcJEoavp0s91M1Ckhw8rpK/mAca4NM7RPauswc+HxXeAapiVW+QAGPAYCOK8FdQuydhj5mSZJCDUGEIYRWcekFbSvGBWmTgnCtzynpWjCW1wcO8LaYnP+iIBRHnykhs8vBSjaHiu3htYC2VAXyTmE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178335926966279.74977717239096; Mon, 6 Jul 2026 10:34:29 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgnCP-0007Ft-T9; Mon, 06 Jul 2026 13:33:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgnCI-0007E5-Af for qemu-devel@nongnu.org; Mon, 06 Jul 2026 13:33:34 -0400 Received: from mail-wm1-x32e.google.com ([2a00:1450:4864:20::32e]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wgnCF-00045y-4N for qemu-devel@nongnu.org; Mon, 06 Jul 2026 13:33:34 -0400 Received: by mail-wm1-x32e.google.com with SMTP id 5b1f17b1804b1-493b966dd74so11226775e9.3 for ; Mon, 06 Jul 2026 10:33:30 -0700 (PDT) Received: from lanath.. (wildly.archaic.org.uk. [81.2.115.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-493e006b6besm467365e9.2.2026.07.06.10.33.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 06 Jul 2026 10:33:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1783359209; x=1783964009; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to; bh=A0FNVhKwjG3aDw/GRmOzMnN8MY+Svb77ZDzchT5mAYc=; b=CK0y51EFpliVP2OZdPAeTlpHqiEYzCBkMs0ndn4VBYI2OW1A17PvwDY7t3r4sqiF6/ z4By+HhfQuCvpiCdjCjACn9yfGQGIYW9y+O42tBWT2hGWdikQzdZvLE6uZwcbD3e9fIn yr1OrtI0nc7mf3JHFhlOWaWlejGBiJYewQp4hv3dAL1hZRVXFRUsEFtMAmfTuBWYnTfH 4nP1j2L8a/9tS0zwTBNW2eCnDnrGBQxyxQIbzhs3Mqc9YqKN6iNz5/B2W/c2NxI1RRUP B9hKpD1kwpUSWO+1dbJnSA2it9Z624oUZxIsVSqKGPPRwD/lLO/UZ4e4V1yDbIj8p596 wFrw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783359209; x=1783964009; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=A0FNVhKwjG3aDw/GRmOzMnN8MY+Svb77ZDzchT5mAYc=; b=ReC84f9MUp18sOaBfnfvcLkpwpExTGzL0cC2xRCLbvAe1J9eWPjrYM5nO3kM5vmzIc fiM1jY2n4QSSbpiNoOKts1fZOiOQObdcmmBNw55HkVSroG7toykMpBFzmNvNhtmRcYMJ JpXg3FjTaAR08PWsKAf46ltkH81fDf21pphBSr70KDvyoWVRHigiaLXP58NVKqnxv45C xefC4tjQwqMvJquO72XZn6yaRqO0KiwS0a10wPSJ7SYR0L8EsWVhECv3AYOVrELxYPXK x5gLQl86vFUKc+hjKrk2IBjHgrtl5LwFoYAppvPWdvk13suB+KyDm6qJKBLLm0mGmk5/ /Dmg== X-Forwarded-Encrypted: i=1; AHgh+Rp7C5EhAB4am5G67k7raMeb68UI2EYLVc3h7KSX/TvQzujz6wOUfsgy2/7+9588BQErJsGRvX3JZ4sD@nongnu.org X-Gm-Message-State: AOJu0YyvOpFbSCFOl4ceqaK51Z1lnAKtkkyRhH/ruUJbc53sTUo5+mzQ VggH85+VNGYgbEmMwC3lcGsqGvEiz4XMvTHIYITeLukzE2ObETSn0gLParcdZ2NmsWY9yF3I3qy KKyunNYo5eA== X-Gm-Gg: AfdE7cniSyOeq83dvLWR147jmIBo936v2UAr3kaWeKQf7JQvV86lm4R1/NK2gx70jkg CYqsN+gVG49gqF4O+g2qewY76rI/lULwalTRyiWw3L5OM+8UPHkKy6U9z+B03yRgyKd3VVmhZ+W Z4Nb4Iuhmm44v7XDXSi+yjObdl4cD9BIXXMh9v1cO5cLAyK9ShTPrc1+wEW4Vu6Q91WmEKoWDdZ ErtOynxMlweWv97rwoi/fEjUxs5EDb6Sbe+2LbOuCEAirdA/7obbGQqhXR0T24ClALLWfFkv6Wn XdBCUCCzBXkvQFMNceF/zGCg7cEEoPI+x/sDOtf/x47F2SHBCnh9ZSeGNzo4Azsh0D4zgT/6SCw 6zIHmiq91mGPkP+hrQdGulPT0EQ/Uc0+DWdowvhPDUkj4yg6y4uifqOyoH8r1j2SQIYseG9d63G fawYwrHreMJVra7mbI8cD05ajvoyZzDu+6JDZDl1mdbdgoPJro5C1KNc0YKn+99dDDw6zDYzm+/ MWdgrD+KPPupYz7FWjr7TBxMDw2V6Yv X-Received: by 2002:a05:600c:56c2:b0:493:d0b2:bc46 with SMTP id 5b1f17b1804b1-493df0786dfmr13669655e9.28.1783359209020; Mon, 06 Jul 2026 10:33:29 -0700 (PDT) From: Peter Maydell To: qemu-arm@nongnu.org, qemu-devel@nongnu.org Subject: [PATCH 2/3] hw/display/exynos4210_fimd: Pass width to draw_line functions Date: Mon, 6 Jul 2026 18:33:23 +0100 Message-ID: <20260706173324.804340-3-peter.maydell@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706173324.804340-1-peter.maydell@linaro.org> References: <20260706173324.804340-1-peter.maydell@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:20::32e; envelope-from=peter.maydell@linaro.org; helo=mail-wm1-x32e.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1783359271399158500 Content-Type: text/plain; charset="utf-8" The draw_line functions currently assume the width of the line they need to draw is w->rightbot_x - w->lefttop_x + 1, i.e. the full width of the guest-programmed window. We want to be able to clamp this to the overall screen size, which we can calculate in the calling function. Refactor to do this calculation in the caller and pass the width as an argument to the draw_line functions. Stable CC because this is a prerequisite for an upcoming bugfix commit. Cc: qemu-stable@nongnu.org Signed-off-by: Peter Maydell --- hw/display/exynos4210_fimd.c | 18 ++++++++++-------- 1 file changed, 10 insertions(+), 8 deletions(-) diff --git a/hw/display/exynos4210_fimd.c b/hw/display/exynos4210_fimd.c index 43ad5fa0b4..52f2285cf5 100644 --- a/hw/display/exynos4210_fimd.c +++ b/hw/display/exynos4210_fimd.c @@ -282,7 +282,7 @@ struct Exynos4210fimdWindow { =20 pixel_to_rgb_func *pixel_to_rgb; void (*draw_line)(Exynos4210fimdWindow *w, uint8_t *src, uint8_t *dst, - bool blend); + uint32_t width, bool blend); uint32_t (*get_alpha)(Exynos4210fimdWindow *w, uint32_t pix_a); uint16_t lefttop_x, lefttop_y; /* VIDOSD0 register */ uint16_t rightbot_x, rightbot_y; /* VIDOSD1 register */ @@ -784,9 +784,9 @@ exynos4210_fimd_blend_pixel(Exynos4210fimdWindow *w, rg= ba p_bg, rgba *ret) /* Draw line with index in palette table in RAM frame buffer data */ #define DEF_DRAW_LINE_PALETTE(N) \ static void glue(draw_line_palette_, N)(Exynos4210fimdWindow *w, uint8_t *= src, \ - uint8_t *dst, bool blend) \ + uint8_t *dst, uint32_t width, \ + bool blend) \ { \ - int width =3D w->rightbot_x - w->lefttop_x + 1; \ uint8_t *ifb =3D dst; \ uint8_t swap =3D (w->wincon & FIMD_WINCON_SWAP) >> FIMD_WINCON_SWAP_SH= IFT; \ uint64_t data; \ @@ -813,9 +813,8 @@ static void glue(draw_line_palette_, N)(Exynos4210fimdW= indow *w, uint8_t *src, \ /* Draw line with direct color value in RAM frame buffer data */ #define DEF_DRAW_LINE_NOPALETTE(N) \ static void glue(draw_line_, N)(Exynos4210fimdWindow *w, uint8_t *src, \ - uint8_t *dst, bool blend) \ + uint8_t *dst, uint32_t width, bool blend) \ { \ - int width =3D w->rightbot_x - w->lefttop_x + 1; \ uint8_t *ifb =3D dst; \ uint8_t swap =3D (w->wincon & FIMD_WINCON_SWAP) >> FIMD_WINCON_SWAP_SH= IFT; \ uint64_t data; \ @@ -848,11 +847,10 @@ DEF_DRAW_LINE_NOPALETTE(32) =20 /* Special draw line routine for window color map case */ static void draw_line_mapcolor(Exynos4210fimdWindow *w, uint8_t *src, - uint8_t *dst, bool blend) + uint8_t *dst, uint32_t width, bool blend) { rgba p, p_old; uint8_t *ifb =3D dst; - int width =3D w->rightbot_x - w->lefttop_x + 1; uint32_t map_color =3D w->winmap & FIMD_WINMAP_COLOR_MASK; =20 do { @@ -1240,6 +1238,7 @@ static bool exynos4210_fimd_update(void *opaque) uint8_t *host_fb_addr; bool is_dirty =3D false; uint32_t global_width; + uint32_t window_width; =20 if (!s || !s->console || !s->enabled || surface_bits_per_pixel(qemu_console_surface(s->console)) =3D=3D 0)= { @@ -1255,6 +1254,8 @@ static bool exynos4210_fimd_update(void *opaque) if ((w->wincon & FIMD_WINCON_ENWIN) && w->host_fb_addr) { scrn_height =3D w->rightbot_y - w->lefttop_y + 1; scrn_width =3D w->virtpage_width; + /* Number of bytes to actually draw */ + window_width =3D w->rightbot_x - w->lefttop_x + 1; /* Total width of virtual screen page in bytes */ inc_size =3D scrn_width + w->virtpage_offsize; host_fb_addr =3D w->host_fb_addr; @@ -1273,7 +1274,8 @@ static bool exynos4210_fimd_update(void *opaque) last_line =3D line; w->draw_line(w, host_fb_addr, s->ifb + w->lefttop_x * RGBA_SIZE + (w->lefttop_y + line) * - global_width * RGBA_SIZE, blend); + global_width * RGBA_SIZE, + window_width, blend); } host_fb_addr +=3D inc_size; fb_line_addr +=3D inc_size; --=20 2.43.0 From nobody Sun Jul 26 11:03:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1783359256; cv=none; d=zohomail.com; s=zohoarc; b=m3D2UlS8yFT/n5VPDX9ViLz1/0JikcoATYwb1QGz5Imx5I9qnIUDQxRpZq5oV/lNJOkpyQiD6+nU/S/LUgbonapSS3v6MPJNMsFNIob/GbfVm1K9Lhhjh0tCnKnniuiQPUSLyJ4WLtSoR5N3TjKeSZqCzUSM5DfgtehJ2a31E/w= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783359256; h=Content-Transfer-Encoding:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To:Cc; bh=Pybcs5s0EJoZh0aRLv5GD/xzxrXejiSNkABytqAQThk=; b=d443iJmJOpf7KPdjwdixKHisYMJbBz0COUaMZaWu1bWc5LiFi+RUxKu7PTpFC/8+kTyvTD4VBI2BN6tX/IyzFqM/deN/wLlxzxbPiobedKRf8spmpJfTfpojykId2YhRijfrb49xHVCV6gYQvJ2AYcGS2XFqRf1dZ18le5Hrf4U= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783359256638870.2102669170238; Mon, 6 Jul 2026 10:34:16 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wgnCT-0007GP-8S; Mon, 06 Jul 2026 13:33:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wgnCI-0007E6-Cd for qemu-devel@nongnu.org; Mon, 06 Jul 2026 13:33:34 -0400 Received: from mail-wm2-x01.google.com ([2a00:1450:4864:31::1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wgnCF-00046B-Ec for qemu-devel@nongnu.org; Mon, 06 Jul 2026 13:33:34 -0400 Received: by mail-wm2-x01.google.com with SMTP id 5b1f17b1804b1-493b567a019so5406475e9.1 for ; Mon, 06 Jul 2026 10:33:30 -0700 (PDT) Received: from lanath.. (wildly.archaic.org.uk. [81.2.115.145]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-493e006b6besm467365e9.2.2026.07.06.10.33.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 06 Jul 2026 10:33:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1783359210; x=1783964010; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:from:to:cc:subject:date:message-id :reply-to; bh=Pybcs5s0EJoZh0aRLv5GD/xzxrXejiSNkABytqAQThk=; b=pHs90fLrDAUlNQf8H/A88LkFz/ZJl0ZnSGEx5Ckma3XxnzN9syvTQQ0vDDW/IiVWTH 1COjk9aZLNy+6AsipDPH5cL5OZBYpLHW6yPeVvC8dds+h5AsmVXh6exbBkAj2KbIqMoi SuIlFJ79jCR3UKvy2RMDQNubNHyyQmJst2V7G7wptRaBJb/Fv0YA4uRjK1PUEVeKUd7o H11e80Ca0sFkBcnp4FWOz0dEavkqBXVuCQoX2SCLewARUGh+LQ++xM/Ms+x5eZA7LVIJ ZT87CSVKBYUvYxmgmpTYy3ISx57zc3OeWytmJ6W/AivD1oCYpTk2mZzzp9LSMu1llmDQ jyGw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783359210; x=1783964010; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to; bh=Pybcs5s0EJoZh0aRLv5GD/xzxrXejiSNkABytqAQThk=; b=kVYWMPWiLo3b5h/ba1xSVaqgidW2206fXxjLcWQEiTwv7A3mSxbk4wr9MZFxHuE6az dElLUcn2iGGTLS/9N7BnzaRD/WTwGrkur1sb+yG3x/ZzX6AbI+I+ojVeQ7Ln2r5B+aBD 6kpaggeG1nte54NL226OEAZY77yg1Usk+3mYb8a6RvT3u8XCtpJW29U5XPxKxDIAVCTH iJ7fTqOYP9NbZbc9YKgLhPVrNSSqjreScrx9mTBZrkGhZemRv4o3ZDNdLp5vxCL0/D9f CQe1pbY5Ia1Xgl9CMl0lq5zfksqktzXOG15xyx5cPf+Aby0BDkdPE3WFBUH3c5w0t9BG cw0Q== X-Forwarded-Encrypted: i=1; AHgh+RoxnUclL5BjZ4Lk8QqqDs+HseHJrI0CwPUE+YhXdyFWIqA6pbq2OPj3Dwpb/83DaVZn7hHtgRgRzM0C@nongnu.org X-Gm-Message-State: AOJu0YwvPdfpcRLydUKXwCTPEEks5UdBaP8cA3qz1YLvY9z0cq4f7dmc 9trx9mdr5UiVNC1lgtO9o8q1x7tREyONOy1FDfX2rLIc4q17IhyFtn7NQdLS4M2I4pgDGzXGQZn dgpK/THRWmB2S X-Gm-Gg: AfdE7ckhY8Dxg+A0UXxJX9v1XnkYwFqXrCQ2DW2myfbMpbKdtVf52Q6kzq/VeCq2mCw eZEs68QfB211xnp5cG7YHfvkfek+RFp085RKbcyl0nl0nuacbM0srOLbGIka3zXtzVPZxKvmq0j fcgmCqHUD87oEqXppY+2QlTIkA5yFWYAYLSRKrS2q6FOO1Ng9sH5QeFObxLQtvYv66EPaGIUDxE 1NCp1v5AMB8xgOyWdemQa/CUWaWZ7eMPwuThFu82oZLuftcznWLBdzJYX8DH3G9nx/DINwlua30 BcDrSY7sWaeu1hck1GFlJW5c2rgQhVW+//hfCW6VepCY0NYFu9KlLNJKStWQyD2Fp3THFmqo/6D 9P6drmy15ATeOYx/iI3lKcslOCPcRl1eO73YBpAT98+YOIQ0KFbCs9cijwM8tC6g+WX+UGN7Gug 4jGHj7FPzo1vTRxGhFgZh+l/u7zCJ3i7eZmBPrqngH3HvIMFyZwxDOt73Hb/9Xb8maG3ewTlca6 cphmhAcitVhjp+jgkeG5g== X-Received: by 2002:a05:600c:3f14:b0:493:ad1b:b38d with SMTP id 5b1f17b1804b1-493df0a0891mr16650575e9.37.1783359209871; Mon, 06 Jul 2026 10:33:29 -0700 (PDT) From: Peter Maydell To: qemu-arm@nongnu.org, qemu-devel@nongnu.org Subject: [PATCH 3/3] hw/display/exynos4210_fimd: Clamp windows to screen size Date: Mon, 6 Jul 2026 18:33:24 +0100 Message-ID: <20260706173324.804340-4-peter.maydell@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260706173324.804340-1-peter.maydell@linaro.org> References: <20260706173324.804340-1-peter.maydell@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:31::1; envelope-from=peter.maydell@linaro.org; helo=mail-wm2-x01.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1783359257502158500 Content-Type: text/plain; charset="utf-8" In exynos4210_fimd_update(), we iterate through the enabled windows, blitting them to the screen. We assume here that the guest has not programmed the window's coordinates to be outside the overall LCD screen resulation, but we never check this. This can result in the guest being able to cause us to access outside our allocated framebuffer backing memory. Since all the coordinates here are unsigned, they can't be off the left/top side of the screen, only the bottom/right. If the top left corner of the window is out of bounds, the whole window is invisible and we can skip it. If the bottom right corner is out of bounds, we clamp it to the screen size so that we only draw the visible part. Cc: qemu-stable@nongnu.org Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3795 Signed-off-by: Peter Maydell --- hw/display/exynos4210_fimd.c | 18 +++++++++++++++--- 1 file changed, 15 insertions(+), 3 deletions(-) diff --git a/hw/display/exynos4210_fimd.c b/hw/display/exynos4210_fimd.c index 52f2285cf5..6c062a28c0 100644 --- a/hw/display/exynos4210_fimd.c +++ b/hw/display/exynos4210_fimd.c @@ -1237,7 +1237,7 @@ static bool exynos4210_fimd_update(void *opaque) bool blend =3D false; uint8_t *host_fb_addr; bool is_dirty =3D false; - uint32_t global_width; + uint32_t global_width, global_height; uint32_t window_width; =20 if (!s || !s->console || !s->enabled || @@ -1246,16 +1246,28 @@ static bool exynos4210_fimd_update(void *opaque) } =20 global_width =3D exynos4210_fimd_global_width(s); + global_height =3D exynos4210_fimd_global_height(s); exynos4210_update_resolution(s); surface =3D qemu_console_surface(s->console); =20 for (i =3D 0; i < NUM_OF_WINDOWS; i++) { w =3D &s->window[i]; if ((w->wincon & FIMD_WINCON_ENWIN) && w->host_fb_addr) { - scrn_height =3D w->rightbot_y - w->lefttop_y + 1; + uint32_t rightbot_x, rightbot_y; + + if (w->lefttop_x >=3D global_width || + w->lefttop_y >=3D global_height) { + /* Guest has put the window entirely offscreen: ignore */ + continue; + } + + /* Clamp right corner coords to be within the screen */ + rightbot_x =3D MIN(w->rightbot_x, global_width - 1); + rightbot_y =3D MIN(w->rightbot_y, global_height - 1); + scrn_height =3D rightbot_y - w->lefttop_y + 1; scrn_width =3D w->virtpage_width; /* Number of bytes to actually draw */ - window_width =3D w->rightbot_x - w->lefttop_x + 1; + window_width =3D rightbot_x - w->lefttop_x + 1; /* Total width of virtual screen page in bytes */ inc_size =3D scrn_width + w->virtpage_offsize; host_fb_addr =3D w->host_fb_addr; --=20 2.43.0