From nobody Mon Jul 27 12:12:24 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1783437011; cv=none; d=zohomail.com; s=zohoarc; b=KYjP8ywbLsh/R6sZJJiqiMDay9WtvPjDtyhbI+fyjpeNnYaowsfSZC2DfGOWWY0TwiLo44emnWUyF8pHtskVaZsME/wrYPHzHCfUtpl0R0Nxu267BqxkR6o7vlPDlZP7ojTx3GwyeNeSt8jDSyjCIrL0QKCO+ALty5mSaM/RFyk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783437011; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=aqUPZZYFcVjX8PACbAJKRitHki4Sln9thZIkfpQ+s28=; b=gw+CqOJ5x42qw7LIAjk5qtMQf3RAEg+dOgpBRiDDwP0M/DgBNn7aZZOSkM6TXWlpuJZgwSS77DR3DgROy6Ymys7+EPWhR3WK0SXn6sJmUu/14/P0oyW5bM4H6u9IZxtU5wvHrDCI9wzArxrcdvYA48HEvF1K1WQ00Zr/HRPB9e4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783437011503358.11534834913857; Tue, 7 Jul 2026 08:10:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wh7Qc-0005QK-4b; Tue, 07 Jul 2026 11:09:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wh7Qa-0005Pb-31 for qemu-devel@nongnu.org; Tue, 07 Jul 2026 11:09:40 -0400 Received: from mail-wr2-x00.google.com ([2a00:1450:4864:30::]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wh7QY-0006OS-6t for qemu-devel@nongnu.org; Tue, 07 Jul 2026 11:09:39 -0400 Received: by mail-wr2-x00.google.com with SMTP id ffacd0b85a97d-46e260f9e57so686709f8f.0 for ; Tue, 07 Jul 2026 08:09:37 -0700 (PDT) Received: from lanath.. (wildly.archaic.org.uk. [81.2.115.145]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47a9de1e785sm34181813f8f.8.2026.07.07.08.09.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 07 Jul 2026 08:09:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1783436977; x=1784041777; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=aqUPZZYFcVjX8PACbAJKRitHki4Sln9thZIkfpQ+s28=; b=n1xGn+v10YeEK7OthbDMPzwbhE+MsY6+WykaNbROoD5Ptrzj+VDkgwLu3MBCThe84S cJn8x2KLbF7RcCsaku6gLdYELPrzMrZ9xif7cryB/AGOMRKaJGdKHx8wd0xuNuGqrVOl JDB9oHqcJBN7ZmoqRj1KpTi16yJ2u5a37gx+tyz5Bkz53AdMMP+QZb54qLWZy4dYswOg NErLZ+WDr2Le5ft89bxvRVWvEhOjP12F57PTyavqUQY5winSTdoxx6/rOSzbxUT1mSo/ HIeeOgQF7yUAjvSWnba6N1menVkf2V3Le8Dh/XPqFpQLPyx63fKB1N+MU603aE2T1g9C /NpQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783436977; x=1784041777; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=aqUPZZYFcVjX8PACbAJKRitHki4Sln9thZIkfpQ+s28=; b=NZgtk36rpOyiCXs2qmUDkIuhnU9zY2yI1M20SHw+reJT6wSB6uljkhZTpW/m1dx4Rg 2HaB9EV89WnZfwUbo7RJI5eKU4X8lC49D4AWj6p5ANJFNq64h/RQdGfYFqd1/QXARBwT 1yCZFy1dakhoH+QZhcD7ikolv9iTMZpriyMYKPAtsf+JHsLH4oLuA0GrgrcFZPE+zvrk 1pB+b4uvCpicpFoAtVYqNXkXuz8zDV1uWucPuLUtw//mX78GjfUG7grum+HDshh33ofe 43xQNjdoGo5YYEfWH9xmdsd9K/nQV65EwKBFxvjWLMmbmwVqWFFsyTwrVdITeHpjHe0T gaLA== X-Gm-Message-State: AOJu0YxTOBiuoKKdvSNILtjykp61IHKRb2GgPQBTgxs0xUCaWQ32pDVw GLsoZ7VupqUWUOX1Ab5Nd/3d/Z6Vr1ZVyvvoc9O4eKFj/iWO6FnfO84Wg2HUPsg6YFmnNPgaqB7 OrZW1AWdFD/Xc X-Gm-Gg: AfdE7ckjYBZT4kLMeDYyft9a86ZjFgfjh5tnEiwdmn8fvDTK750Z+/uzWx6TujI+N73 NqIza6zWuEgJII/akwxveVZQvXZKnEynmcJup3YgrGrgyzQoFQc8DDb1C+61I9RG/jngY6CX8lJ H4qIn0KN3/o1n2kpi3oov9+IKhmlH98fKUQIA8SLhI5hQcMOJT/dcOTvhDv1zrVAcc1T97cd5uq luExRrUNgGFmRjqxjEOQrUldNkTREBeHfbMm6rooJ32lo3WW0pDfGgWph1Zrelad55yl0x0TjM5 K6OokwOSQ4DTVeCdTlGRor1HWHwv5oDT4LAeqSHkaToa8atS6yImgh4ViCtz31/A5K8a4NmthmI 6Y3DzaEy6EF4U4F4Thdrdr7UMDwtkHKF0D2bqwrnRCKqQkZWxPEoFccF+XMX3KrAxuJSy1yS/p7 jcUmz/1SwKODvprg+omLcaMC0A6G1J0NJgh8XapjXnd9BgR6Uh8HGXWqdNrY6ASSZ8UR5xUud4s yCb/wqiO3vRUjpervpTxg== X-Received: by 2002:a5d:4289:0:b0:46d:d6c1:8383 with SMTP id ffacd0b85a97d-47de66dd473mr5105483f8f.44.1783436976654; Tue, 07 Jul 2026 08:09:36 -0700 (PDT) From: Peter Maydell To: qemu-devel@nongnu.org Cc: qemu-ppc@nongnu.org, BALATON Zoltan Subject: [PATCH 1/3] hw/display/sm501: Catch bad coordinates for RTL operations Date: Tue, 7 Jul 2026 16:09:31 +0100 Message-ID: <20260707150933.1410507-2-peter.maydell@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260707150933.1410507-1-peter.maydell@linaro.org> References: <20260707150933.1410507-1-peter.maydell@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:30::; envelope-from=peter.maydell@linaro.org; helo=mail-wr2-x00.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1783437014012158501 Content-Type: text/plain; charset="utf-8" The sm501 code doesn't check whether a right-to-left operation has specified a width greater than the x-coordinate (which would make it extend off the left edge of the screen), or similarly a height greater than the y-coordinate. This means the guest can misprogram the device so that we underflow when calculating the address of the top left pixel, which might result in accessing out of bounds memory. Catch this as a guest error and ignore the operation. Reported-by: Yannick Wang Cc: qemu-stable@nongnu.org Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3920 Signed-off-by: Peter Maydell Reviewed-by: BALATON Zoltan Tested-by: BALATON Zoltan --- hw/display/sm501.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/hw/display/sm501.c b/hw/display/sm501.c index af87004837..0da25477bc 100644 --- a/hw/display/sm501.c +++ b/hw/display/sm501.c @@ -723,6 +723,10 @@ static void sm501_2d_operation(SM501State *s) } =20 if (rtl) { + if (dst_x < (width - 1) || dst_y < (height - 1)) { + qemu_log_mask(LOG_GUEST_ERROR, "sm501: RTL op out of bounds\n"= ); + return; + } dst_x -=3D width - 1; dst_y -=3D height - 1; } @@ -748,6 +752,10 @@ static void sm501_2d_operation(SM501State *s) } =20 if (rtl) { + if (src_x < (width - 1) || src_y < (height - 1)) { + qemu_log_mask(LOG_GUEST_ERROR, "sm501: RTL op out of bound= s\n"); + return; + } src_x -=3D width - 1; src_y -=3D height - 1; } --=20 2.43.0 From nobody Mon Jul 27 12:12:24 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1783437020; cv=none; d=zohomail.com; s=zohoarc; b=DNmyd16qOumyWlgRHh7j34FuoYXgypj8i+TnLLfy1UcUgOdtJm/q16x+t34CvpkbxGVsHEdN4FA4YpEyvX27ixohgH3FpQEeDBe+5QroCZuEyGxBYS8ZX5t3zpmtVnqyuEJp19alzYEC/uL3QNWD80V6rmIlUd06wsKAamYpa9o= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783437020; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=xBb3xLV/5YedzzzrUj5U071p8Cemdeb+/y1/TOle2Oo=; b=Q4cxC88Vc/kflRNGl7zJhTJSp5M9dyYQwlbvVCrwOt3/rDifjYWs2N65CnU5GOjGRl8DVzuL+qORG5+OfFBGQ1hDccS+5XqGotl0i7CNDT6LMxvs2hdL6fIMqAn8YY/l40gNCTO0mTKKcaaI058zyx4LgZJxChZ2f+hCJqaU+ZQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783437020679917.0854606323707; Tue, 7 Jul 2026 08:10:20 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wh7Qe-0005RS-4d; Tue, 07 Jul 2026 11:09:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wh7Qb-0005Q3-Hc for qemu-devel@nongnu.org; Tue, 07 Jul 2026 11:09:41 -0400 Received: from mail-wm2-x02.google.com ([2a00:1450:4864:31::2]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wh7QZ-0006Od-60 for qemu-devel@nongnu.org; Tue, 07 Jul 2026 11:09:41 -0400 Received: by mail-wm2-x02.google.com with SMTP id 5b1f17b1804b1-493b9643ab5so3479245e9.1 for ; Tue, 07 Jul 2026 08:09:38 -0700 (PDT) Received: from lanath.. (wildly.archaic.org.uk. [81.2.115.145]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47a9de1e785sm34181813f8f.8.2026.07.07.08.09.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 07 Jul 2026 08:09:36 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1783436978; x=1784041778; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=xBb3xLV/5YedzzzrUj5U071p8Cemdeb+/y1/TOle2Oo=; b=C3ufMsd8/CsRHuZeJD24vErkN8EMkimaBv3K3XZ+N2qC/zajwFcf+hpsEp2g7yDPQZ gVtLPJ0KS+B5CgDmQakd8J4K9rcJOsGRhO6w2D+h5JuGlamoMBQ5kq16sxeD2oSTkruW Io66Rw/HT1JRARDN8qaX+3L2Zxq4rhQhjL6IELPxBSwt+VUKw7IJlteLUIq2U/iJvqRT anDcwI+V90LDEWAY0Wki9DjCRhSUv5oY5R6iPHSSDco7A986kY+KtbNb+1Jja2glgZAh O6HzF4ZcVB4aaVUlGdaJAkn4sDyfV1fAbdPaS2P7K6tpDwSq9hHFJP4IlBRhlA2c8Tjg 5x9A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783436978; x=1784041778; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=xBb3xLV/5YedzzzrUj5U071p8Cemdeb+/y1/TOle2Oo=; b=LsDh03XmX9AHyNwJCky/cLdKGqS2jzcwdG5/MyS2usX4shlMiioHxlBNjELDWI7uYW yohsp8CGwyLsjQdvtkzdBpQy+o/KStXH2cmHy/FRDrUx0EqDhazG2eqx2S52I3Sb8bqN rjar7SWKYmcCSBNLjEwZKwj8TXiE7kyKsgZEQfPR3mvzDyCdBVQyUb1iYXjZQDEcuY95 Lk/lyftu+8LAkbrDIBf81bS/R1IjvUxC2rgO1851JUcrYCvX4oJviJlGLd66lLeldlvO TgwFecuZjawgIEU+lZM4fRiOJ8k2QIQ1BB8mkE2STFZQLJ6Erp3Pve2nykfzLUCYfWD7 tRPg== X-Gm-Message-State: AOJu0YyT/w+rMpCyuvjGmzFGZ4OGDM3gEeII6pRx/2Wj+Sr6CKzEI4cY sQ+fQe1Ehl+lM4jHmIALcZ+d0vGlWdJbgm+OrsAKPh0Rv6b2pVCsHuwb38QeNIVhe7bxgqsbq7p +mXwvNxdDKuJi X-Gm-Gg: AfdE7cl3f8qIhuuYmdJxOtcnE6k9QlYTA2OfRLhxmxJTK7ZNnV2m+FO0rdwTyQJoUxc AlhVsncNmTWXHO+35px+HS7iDpPFK66zlbO7m2N2k3d1B/Qh5s5Z7MUTq/1tcUYU7ZcMtuFv0ov WaeRJOPvR4TlYAaMOAPNt+LJXoptOW03r5ffJSeLAHqFOrjOf779o4b+Ysp4BTA6XOF2YUPYtWu MrWVXgPOKslVIBlzRv6eGjaRysss+oNXwcRCM6/FXh4qZxzWA5ErLJysc0E4fhANesJ51JPs/ew z7Ez02bG47aZeCB+Ur8aKEUEJywRyzfoaY6bW43I7gI8PvWk5JfZYtOrkyswyU/YcWHajrRwaTg NBhSG6pQAGPBnAePWdu5qOLkhOegPerTdGlT3leAMFz8FSfaIQDOAjRe+Wze+h+UEFGCo8ksnXy SSK+sYuCCLegfoaG6L2CjSM+iJjw89uFtwxpcotKzH0cLwjixcURGAWCU0yYPZCKws97hIOoaq1 8RoeCuXHcmTC3NCMhOh/g== X-Received: by 2002:a5d:518b:0:b0:476:dd2b:611 with SMTP id ffacd0b85a97d-47de668ef11mr5072409f8f.3.1783436977617; Tue, 07 Jul 2026 08:09:37 -0700 (PDT) From: Peter Maydell To: qemu-devel@nongnu.org Cc: qemu-ppc@nongnu.org, BALATON Zoltan Subject: [PATCH 2/3] hw/display/sm501: Avoid overflow problems in bounds check calculations Date: Tue, 7 Jul 2026 16:09:32 +0100 Message-ID: <20260707150933.1410507-3-peter.maydell@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260707150933.1410507-1-peter.maydell@linaro.org> References: <20260707150933.1410507-1-peter.maydell@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:31::2; envelope-from=peter.maydell@linaro.org; helo=mail-wm2-x02.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1783437021903158500 Content-Type: text/plain; charset="utf-8" When we check that a 2D rectangle operation isn't going to run off the end of video RAM, we do the calculations as 32 bit arithmetic. This means that carefully chosen guest register values can cause an overflow so we don't detect that the operation is going to go outside video memory. Abstract the check out into a function, do the calculations as 64-bit arithmetic, and add assertions about the ranges of the inputs. Cc: qemu-stable@nongnu.org Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3920 Signed-off-by: Peter Maydell Reviewed-by: BALATON Zoltan Tested-by: BALATON Zoltan --- hw/display/sm501.c | 32 ++++++++++++++++++++++++++------ 1 file changed, 26 insertions(+), 6 deletions(-) diff --git a/hw/display/sm501.c b/hw/display/sm501.c index 0da25477bc..d5e165daef 100644 --- a/hw/display/sm501.c +++ b/hw/display/sm501.c @@ -682,6 +682,28 @@ static inline void hwc_invalidate(SM501State *s, int c= rt) get_fb_addr(s, crt) + start, end - start); } =20 +static bool sm501_rect_outside_vram(SM501State *s, uint32_t base, + uint32_t x, uint32_t y, + uint32_t width, uint32_t height, + uint32_t pitch, uint32_t bypp) +{ + /* + * Return true if the 2D area specified by the arguments is + * partially or completely outside the VRAM (a guest error) + * + * Limits on the input sizes mean we can't overflow as long as + * we do all the arithmetic at 64 bits. + */ + uint64_t rect_size, last_addr; + + assert(x <=3D UINT16_MAX && y <=3D UINT16_MAX && height <=3D UINT16_MA= X && + pitch <=3D UINT16_MAX && bypp <=3D 8); + rect_size =3D (((uint64_t)y + height) * pitch + x + width) * bypp; + last_addr =3D base + rect_size; + + return last_addr >=3D get_local_mem_size(s); +} + static void sm501_2d_operation(SM501State *s) { int cmd =3D (s->twoD_control >> 16) & 0x1F; @@ -731,9 +753,8 @@ static void sm501_2d_operation(SM501State *s) dst_y -=3D height - 1; } =20 - if (dst_base >=3D get_local_mem_size(s) || - dst_base + (dst_x + width + (dst_y + height) * dst_pitch) * bypp >= =3D - get_local_mem_size(s)) { + if (sm501_rect_outside_vram(s, dst_base, dst_x, dst_y, width, height, + dst_pitch, bypp)) { qemu_log_mask(LOG_GUEST_ERROR, "sm501: 2D op dest is outside vram.= \n"); return; } @@ -760,9 +781,8 @@ static void sm501_2d_operation(SM501State *s) src_y -=3D height - 1; } =20 - if (src_base >=3D get_local_mem_size(s) || - src_base + (src_x + width + (src_y + height) * src_pitch) * by= pp >=3D - get_local_mem_size(s)) { + if (sm501_rect_outside_vram(s, src_base, src_x, src_y, width, heig= ht, + src_pitch, bypp)) { qemu_log_mask(LOG_GUEST_ERROR, "sm501: 2D op src is outside vram.\n"); return; --=20 2.43.0 From nobody Mon Jul 27 12:12:24 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=linaro.org ARC-Seal: i=1; a=rsa-sha256; t=1783437011; cv=none; d=zohomail.com; s=zohoarc; b=Ufj4bKluWdTg5rWON5CxLaOcCbomM3F2Ysizw2g3WEmgBVeJEbAH/bJhlGZp65lZ2Qf9pSeKXcFx4VV7suaExjsCnlF/IuezpS/ynRCU8RZPgohfHYYbyQ2qAIHRk+nPJVYRiOvsOLMcEXv2rCPuysj5nwXT8knZcPnJqtPxcVM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783437011; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=BNyCnYjc9gI/MdleLfh7mXv3shlCrWbZOFKPeIq3AKk=; b=PWGNALxwYm611Jg1VtB51BNMAU3jYN32qiWQxGnksKbeGaxlG5opzqqH/BxWESB3dEIFjv6WEVDbhV2Xj2IKfqWrVb1bNkkHu7ArRLVoRxYYLwt3Bo9pbmh8rhSj0kIIGLsl7F68OL8ZMN61ouUBji4Ui0BTN9M7i7mahZYu9kk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783437011499251.94428822907037; Tue, 7 Jul 2026 08:10:11 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wh7Qe-0005RV-HP; Tue, 07 Jul 2026 11:09:44 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wh7Qc-0005Qq-MX for qemu-devel@nongnu.org; Tue, 07 Jul 2026 11:09:42 -0400 Received: from mail-wm2-x01.google.com ([2a00:1450:4864:31::1]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1wh7Qa-0006PB-TO for qemu-devel@nongnu.org; Tue, 07 Jul 2026 11:09:42 -0400 Received: by mail-wm2-x01.google.com with SMTP id 5b1f17b1804b1-493b567a019so10608735e9.1 for ; Tue, 07 Jul 2026 08:09:40 -0700 (PDT) Received: from lanath.. (wildly.archaic.org.uk. [81.2.115.145]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47a9de1e785sm34181813f8f.8.2026.07.07.08.09.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 07 Jul 2026 08:09:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1783436979; x=1784041779; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=BNyCnYjc9gI/MdleLfh7mXv3shlCrWbZOFKPeIq3AKk=; b=rHQTXxZfVS5svoa41w6UqYmQFtc9mYqBXVLPJu6mmeCbVqa5CCRa1CWUD9ncXzEOd1 jsein7mf3KEprJhckOSsudBVcCieBhEhjJJq9IGCU8+es4zKxok+HH/aumAKcEdxUTHp aumnZx98zR2/iwKLr9VFRavc8bULLVNH5skQ5S2nNFaO2xJ8M5kGbuIeWvQhzp4f5jSH j66+W3jVqLmFeJf5IYO5mJjIkUh6GKKKvISz2smsVlu31p4fGLpeAuPM3+3VD1QG+dg/ oL0Z94kuWSlrTzfn5ZRelaQ4uFmIfJ477vjZsxY/Ruc18wku3rBo1sTfmObGO8hHsMuG UGNA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783436979; x=1784041779; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=BNyCnYjc9gI/MdleLfh7mXv3shlCrWbZOFKPeIq3AKk=; b=Ffzcr4jw1rFT76OLotYBamdU5rdfSUaHa86O2E5Io+6MuaEYssggpCJBzYh4Nbmojx GqLJv6JcOzC2lJP+E4PKsCROUtVnLIlYqcdLDSjIZQnH8b7G7A9i2AlnYA8/yDYSiZBw yPuwk5UWpwMJ7fUMd46F4PVPuvBNUVIGXb/xGnEGP9ETWrUtOxPV43YXzdWZc7DHoj4E reQJwkoRPiX4Bb+vPfkhITqb1YGQwEyon99MvhxZo/Djj0hgnrTeY5NCtNh77BSFiHa7 J+CmsZhbSRkbn1OFQHzrElP1WdCYcMqYsZBjIAWvI9yjp/asArlCJJPQooTdES5C7Q2k 0SVw== X-Gm-Message-State: AOJu0Yzbz6f0NlMUAfRiHqqNlilRaM3aaeGFev1rNmql4GuBlyg7ra97 Y7P7YLnvwJk0trZdwUto4JWc/9EvmZ+yQia2VhXfefEst6yRkqcg3T7/nRiSgUhEE9+vO1GVnES cCzzYG+ue5LOV X-Gm-Gg: AfdE7ckS/3kuzoT6p9BTSSVIZRaXcwzfuMGO9I4lSBNHxRPOsC2q2CK0RS8occxKE7N QiBqb40A95c+knLLaumcRI4F/zpxtXimnoT+2Ig9I1ksCxTkW1H026hYJ8YL+2r/hJ2i9us3SkQ /smnyO3wDXziNJAh3Ckh0L2iIlXSbluyKiPPeYD/arlgSPsjjCZB42DnCwr7ViT+juwXSn9F3XF hARpnD2jHsOZEozp9oUY57mLlup6Cs+IMzefPfnSMHm0wbkCZ50bmgi23G6KBxS3IpLbi/zDD+0 7mO/c4EKjAqR/k0JK3OJyJNENL3wtUzYetB7ILMW4RxpoGuoxxBqrGXJyXS2+UIf+7jbhuxvAat IvhG86u2hmz17G5c/NlAZwH1+VIip+16ZMYWPHcANEM8rwuqc4j1lstJ1zCI/YeA3qDzVdlp8UH EkWAd88Z3cyPJoSLkvtBFVEFCH32zBD6avGJMSE7ualjBy1LJiIhge4GyajaoMycUruFS/6EBWp xkNCogBGnG2YVpn/4ZOHw== X-Received: by 2002:a05:600c:3b9d:b0:493:e311:5f10 with SMTP id 5b1f17b1804b1-493e3af1279mr28652685e9.10.1783436979277; Tue, 07 Jul 2026 08:09:39 -0700 (PDT) From: Peter Maydell To: qemu-devel@nongnu.org Cc: qemu-ppc@nongnu.org, BALATON Zoltan Subject: [PATCH 3/3] hw/display/sm501: Don't allow guest to set ram size larger than it is Date: Tue, 7 Jul 2026 16:09:33 +0100 Message-ID: <20260707150933.1410507-4-peter.maydell@linaro.org> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260707150933.1410507-1-peter.maydell@linaro.org> References: <20260707150933.1410507-1-peter.maydell@linaro.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2a00:1450:4864:31::1; envelope-from=peter.maydell@linaro.org; helo=mail-wm2-x01.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @linaro.org) X-ZM-MESSAGEID: 1783437014035158500 Content-Type: text/plain; charset="utf-8" The SM501 DRAM_CONTROL register has a 7 bit Size field which allows the guest to change the local memory size. We use the local memory size in bounds checks calculations for 2D operations. Currently we have no check on the validity of the value the guest programs to this field, which means that the guest can: - set it to a reserved value (6 or 7) which will cause get_local_mem_size() to read outside sm501_mem_local_size[] - set it to a value corresponding to more RAM than the card was created with, so that the 2D bounds check will let 2D operations access off the end of the memory region Fix this by decoupling the value the guest reads and writes to this field from the internal size we consider the local memory to have. We validate changes and ignore them except for readback if they would be reserved values or values for more memory than the card has. Cc: qemu-stable@nongnu.org Reported-by: Heechan Kang Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3811 Signed-off-by: Peter Maydell Reviewed-by: BALATON Zoltan Tested-by: BALATON Zoltan --- hw/display/sm501.c | 24 +++++++++++++++++++++--- 1 file changed, 21 insertions(+), 3 deletions(-) diff --git a/hw/display/sm501.c b/hw/display/sm501.c index d5e165daef..cacb6c87ec 100644 --- a/hw/display/sm501.c +++ b/hw/display/sm501.c @@ -571,6 +571,25 @@ static uint32_t get_local_mem_size_index(uint32_t size) return index; } =20 +static void set_new_local_mem_size_index(SM501State *s, uint32_t idx) +{ + /* + * Update local_mem_size_index on guest write. We don't allow this + * to be set to larger than the actual RAM size. (The guest will + * still read back the SYSTEM_CONTROL.Size bits that it wrote.) + */ + if (idx < ARRAY_SIZE(sm501_mem_local_size) && + sm501_mem_local_size[idx] <=3D memory_region_size(&s->local_mem_re= gion)) { + s->local_mem_size_index =3D idx; + return; + } + qemu_log_mask(LOG_GUEST_ERROR, + "sm501: Guest set DRAM_CONTROL.Size to 0x%x but " + "local memory is not that large\n", + idx); + /* Don't change the effective size, leave it as whatever it was */ +} + static ram_addr_t get_fb_addr(SM501State *s, int crt) { return (crt ? s->dc_crt_fb_addr : s->dc_panel_fb_addr) & 0x3FFFFF0; @@ -990,7 +1009,7 @@ static uint64_t sm501_system_config_read(void *opaque,= hwaddr addr, ret =3D 0x050100A0; break; case SM501_DRAM_CONTROL: - ret =3D (s->dram_control & 0x07F107C0) | s->local_mem_size_index <= < 13; + ret =3D (s->dram_control & 0x07F1E7C0); break; case SM501_ARBTRTN_CONTROL: ret =3D s->arbitration_control; @@ -1049,8 +1068,7 @@ static void sm501_system_config_write(void *opaque, h= waddr addr, s->gpio_63_32_control =3D value & 0xFF80FFFF; break; case SM501_DRAM_CONTROL: - s->local_mem_size_index =3D (value >> 13) & 0x7; - /* TODO : check validity of size change */ + set_new_local_mem_size_index(s, (value >> 13) & 0x7); s->dram_control &=3D 0x80000000; s->dram_control |=3D value & 0x7FFFFFC3; break; --=20 2.43.0