From nobody Sun Sep 27 23:50:08 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=oss.qualcomm.com ARC-Seal: i=1; a=rsa-sha256; t=1789425186; cv=none; d=zohomail.com; s=zohoarc; b=hknDASI1BCDkvPPiihit4GFTOOeagEHiuw/2WUblFwIGWmmNrkVpEpWmrrghTBmV52/lvD07aZxE3Y44a8pXHs63E1/j5RBL47Ze9LxQLDkIkLmErzmXXwAGiPDq39IfPLNIwyadIOQQVHHWCJPbXkfSK3sRXDgdRjqXt/GJ9zo= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789425186; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=XD4bk1vlqFkPULOSiPy9282jSdpZze/qiV59zoNxK8s=; b=GvYkWjl5PSble3RCQsjzs1qb0jhzh1/b17i4TWLmLap6o2zrE95Bv+9GbaW7msZ2qJjzMas6CcDf7WmHQCxBy9k/RC0Xzj4wvaWT+6DQGNCYzIAXPyOt4fcppzcKjKB6N0npEJCczCp7oJuz0QGl/HIQoVDHYv7WqLCy/iwL8aA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789425186470220.99540493842483; Mon, 14 Sep 2026 15:33:06 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x6FDs-0000fI-Bu; Mon, 14 Sep 2026 18:32:24 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x6FDb-0000dI-M5 for qemu-devel@nongnu.org; Mon, 14 Sep 2026 18:32:08 -0400 Received: from mx0a-0031df01.pphosted.com ([205.220.168.131]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x6FDZ-0006qQ-37 for qemu-devel@nongnu.org; Mon, 14 Sep 2026 18:32:07 -0400 Received: from pps.filterd (m0279866.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 68EJZ3uR772833 for ; Mon, 14 Sep 2026 22:32:03 GMT Received: from mail-pj1-f72.google.com (mail-pj1-f72.google.com [209.85.216.72]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4gpcjg3cax-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Mon, 14 Sep 2026 22:32:03 +0000 (GMT) Received: by mail-pj1-f72.google.com with SMTP id 98e67ed59e1d1-38f97b3f853so6509084a91.3 for ; Mon, 14 Sep 2026 15:32:03 -0700 (PDT) Received: from hu-bcain-lv.qualcomm.com (Global_NAT1.qualcomm.com. [129.46.96.20]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba7a9bb56sm30190753eec.31.2026.09.14.15.32.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 14 Sep 2026 15:32:01 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= XD4bk1vlqFkPULOSiPy9282jSdpZze/qiV59zoNxK8s=; b=D+1kyAfV/MwQ+LOT w22B+S11EiVfW3REJqprzjjUS0/1o9Tr8VcQc3rzWyWc1Evo7e9gKBy4GkEES6ST 3sWmiChVPjooGKbCL9GXPF5SonXRQmLZU//jExrRZXXfVmh/bXcQ7P/tRDWBOe4j c7gPQ4c8FkqTPf8NmyfJC4s8TDg0mdsDp3aqB/ysM6fPf8EKcu2MisPZ4kxN1Utt NfA5oElFIL0oWXF7uFBCI/2XLcv/mvGbCbSa1Ja5Lc4o0DsMUVpEj/BecE2BhtId afYoQ90BDPOEioCL1FZSqGzhY2ZVEZstv5sqRMavksA82QFE7NtU+nvZoh5DLJrH P7NUFQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1789425123; x=1790029923; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=XD4bk1vlqFkPULOSiPy9282jSdpZze/qiV59zoNxK8s=; b=ZTlzMvJtUIdPiwrZhE3xNe0rUcjq85Ibqv/a5G1ykkHQZJv/AdMmy7RmwFVr3KhRsv O7USGxGyQWuK+TaT28bPImS/8/DiisKULrCSOaIaaR217UCsd0lve4f4KaDKEvSK6D/c kCpMNiRB+hDgLelNii747XU9p0oxGPxopG1FIody0WvYZQCTMN9J9VFqlzVBBOYvVkY8 JrRgwvUrzwYn0ObjeizmM0d/ZsGGgbOBOL3BXqVT/af587GdNOR4IVVwxo7nIPTkSPri CjndP51aRIiHJDohcu2gmirSwsOHMPTreCpCEFUguNuV/H675cDqyRXuPQvVMZziNQl5 TMIA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789425123; x=1790029923; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=XD4bk1vlqFkPULOSiPy9282jSdpZze/qiV59zoNxK8s=; b=PbTRj7rTcbaetuGBWvUYJqJjPCvi+JLCUMNzwY5Ggpyl8C30cpyhDIQmBOkmM9q5zn uSgbqy0W9VfIyFvB8DBv9+UfNwi7FDGnYsN98kV79xOe/AxU2aBbLm95MBjbfSgskKxT tRLrgs8e3a3k/25Rq8UqAtS2y91N2KFqFp+R9NoGeW6hEKCjvR2SMk/Lv+jIQm9JNp7h ceHZ3Ri1Zu6vlgthdxNdklWE4I5VTQeiq24mtktqCkVJi4qlFSzueebE+3ToiQmvkeMq sU0S3j9gch9Z45r+cxFqxHq3bU3x6oc8CwLk1wzGXllQ9ktChzWP2MnKuJRkjNX6TFSB Ry9Q== X-Gm-Message-State: AFuF++murbiyXt/WaCIA9o/qt1iGu39RvnkAZhlFhcWXPry7cWcW9Zik JF9sSN1barwkLcdQ25GjISaCaz9fMQicZzswC8DYKMxLj3oNJ8moImWHsPtBUfMvUuAs/z6FTX6 +sdpGuHYEOnCB/n1YAZ1aVOqJ2zdCnLgATJ8Zsas8zdUCp/OhR8bF4RKxVOeC1bH3RA== X-Gm-Gg: AYBFou281VdP43JRzAQxS15Cz7b/HRPMnwNhRUEzeONoBdAwdN7o9/iDxVVHf4OI6q5 cYEMa67CUR5UzfKCHgAPTSilGEDiEAIlQlpBUWMG7ed5RWymXvBl1OJkY2XfVnJznCKP1AgIcZB eyYg+Dfz7YyXEeDCNy3zGAOBHLwpR5Qh81odgFqIVLk1nM4NxHFZuxGiosRXh+769h0F2OeSfxH NiPdNfENT4AMts5pdhs4ZrKu3VfTNKsADNRe0D+XKv+9nuloGnWtmdjlsR6bM9m3V62UlHTS+Xr R2Vk2EFTZXk4x12XHW3r6f+cwrVlGeR3BiaJyceczi7dWNPbAe05LiT9W5EaS2sv4mkbsJhK4TH aiCmzXrAuKgSVcz5dCJlKoawvdb/gxRkOM/Z6Gzef50mJYe5s X-Received: by 2002:a17:90b:39cc:b0:37f:c22a:c188 with SMTP id 98e67ed59e1d1-39debf5f2a2mr8990929a91.4.1789425122853; Mon, 14 Sep 2026 15:32:02 -0700 (PDT) X-Received: by 2002:a17:90b:39cc:b0:37f:c22a:c188 with SMTP id 98e67ed59e1d1-39debf5f2a2mr8990851a91.4.1789425122286; Mon, 14 Sep 2026 15:32:02 -0700 (PDT) From: Brian Cain To: qemu-devel@nongnu.org Cc: Brian Cain , Pierrick Bouvier , peter.maydell@linaro.org Subject: [PATCH v2 1/4] target/hexagon: fix semihosting OPEN filename handling Date: Mon, 14 Sep 2026 15:31:56 -0700 Message-Id: <20260914223159.2735262-2-brian.cain@oss.qualcomm.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260914223159.2735262-1-brian.cain@oss.qualcomm.com> References: <20260914223159.2735262-1-brian.cain@oss.qualcomm.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Authority-Analysis: v=2.4 cv=CKa/zhrD c=1 sm=1 tr=0 ts=6aa875e3 cx=c_pps a=RP+M6JBNLl+fLTcSJhASfg==:117 a=ouPCqIW2jiPt+lZRy3xVPw==:17 a=IkcTkHD0fZMA:10 a=VdqzKS8jKosA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=YMgV9FUhrdKAYTUUvYB2:22 a=VwQbUJbxAAAA:8 a=pGLkceISAAAA:8 a=KKAkSRfTAAAA:8 a=EUspDBNiAAAA:8 a=wfIhpZVs-6LWPqknoVUA:9 a=QEXdDO2ut3YA:10 a=iS9zxrgQBfv6-_F4QbHw:22 a=cvBusfyB2V15izCimMoJ:22 X-Proofpoint-ORIG-GUID: KK66kVsJytlCUo0Xp5QBPCkORulhGNAc X-Proofpoint-Spam-Info: AW1haW4tMjYwOTE0MDMyMiBTYWx0ZWRfX9ogISnx5TrNk mhOqD8LjQDh6ZQTrVu8l7akyx11I9o1pxjdLXvngoVxtgQkhXnpw7+Fr6N7xy7lTnR7DcrePj40 NGUhEHHl6aSYVuk5p3vGNo3Fij9WnRs= X-Proofpoint-GUID: KK66kVsJytlCUo0Xp5QBPCkORulhGNAc X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwOTE0MDMyMiBTYWx0ZWRfX3lXx3z9K1YQB y6Hyak4OBseO60NPnVSVoxxk15FtpPHE8FNoMylD7oodObBmbypDFxS++n19e/sUS6vRI6v7g86 zJgeLD77LORobaVjx1cXqKf2ybeaCZ2u+JR8qPPPOnL3hVLOSYEIE/hthaZFOK3b5Nl2lRd5t9s lGeL9XE0pkMea5avdfl8OIVhdokxy8YuXHHfZMI04RemVbKXM66L18Lw8/8/kjToNn5SMcFBdFB DnoK5adL6IM1jeU2V+8s8p4C/0j3gs2nN0RNxlPUWbZ1yPui5ch+LJRtlK3rNEM6AVWj1lYnR5U lt29LxDh17oQPzubucqCmmJAEV2X+aQWxwWc9DdpHASClM1siexNOqUpLZgAKHgU9nCsJlpJH6m BCgpy3n82WEbFArbUs2QYcr0/5Gk9Am+/X/S0PlWg+NQd6XmKflsUQNunwK6IRDzGENYGUNMGsC DPWATxcTN9A8OQdz5tA== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-09-14_04,2026-09-14_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 malwarescore=0 clxscore=1015 priorityscore=1501 impostorscore=0 spamscore=0 lowpriorityscore=0 phishscore=0 bulkscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2609040000 definitions=main-2609140322 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=205.220.168.131; envelope-from=brian.cain@oss.qualcomm.com; helo=mx0a-0031df01.pphosted.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @qualcomm.com) X-ZM-MESSAGEID: 1789425188246158500 HEX_SYS_OPEN copied guest bytes into a fixed-size buffer until it found a N= UL. A missing terminator could overrun that buffer. Use lock_user() with the ABI filename length and validate its terminating NUL before opening it. Fixes: 7711fdba88b ("target/hexagon: add main arch-specific semihosting ope= rations") Link: https://lore.kernel.org/all/CAFEAcA9MOs6VfHf2UHZ8z4cdvaB+7DY6hJb2emYZ= 2aLSe-t6iw@mail.gmail.com/ Suggested-by: Peter Maydell Signed-off-by: Brian Cain --- target/hexagon/hexswi.c | 34 ++++++++++++++++------------------ 1 file changed, 16 insertions(+), 18 deletions(-) diff --git a/target/hexagon/hexswi.c b/target/hexagon/hexswi.c index 4705e915aea..21e5d630a75 100644 --- a/target/hexagon/hexswi.c +++ b/target/hexagon/hexswi.c @@ -28,6 +28,7 @@ #include "semihosting/console.h" #include "semihosting/syscalls.h" #include "semihosting/guestfd.h" +#include "semihosting/uaccess.h" #include "system/runstate.h" =20 /* non-arm-compatible semihosting calls */ @@ -461,31 +462,17 @@ static void sim_handle_trap0(CPUHexagonState *env) =20 case HEX_SYS_OPEN: { - char filename[BUFSIZ]; + char *filename; target_ulong physical_filename_addr; unsigned int filemode; - int length; + uint32_t filename_len; + size_t filename_size; int real_openmode; int ret, err =3D 0; - int i =3D 0; =20 hexagon_read_memory(env, swi_info, 4, &physical_filename_addr, ret= addr); hexagon_read_memory(env, swi_info + 4, 4, &filemode, retaddr); - hexagon_read_memory(env, swi_info + 8, 4, &length, retaddr); - - if (length >=3D BUFSIZ) { - qemu_log_mask(LOG_GUEST_ERROR, - "%s: filename too large (%d)\n", - __func__, length); - semi_cb(cs, -1, ENAMETOOLONG); - break; - } - - do { - hexagon_read_memory(env, physical_filename_addr + i, 1, - &filename[i], retaddr); - i++; - } while (filename[i - 1]); + hexagon_read_memory(env, swi_info + 8, 4, &filename_len, retaddr); =20 /* convert ARM ANGEL filemode into host filemode */ if (filemode < ARRAY_SIZE(angel_to_host_filemode_table)) { @@ -498,6 +485,16 @@ static void sim_handle_trap0(CPUHexagonState *env) break; } =20 + /* The ABI length excludes the filename's terminating NUL. */ + filename_size =3D (size_t)filename_len + 1; + filename =3D lock_user(VERIFY_READ, physical_filename_addr, + filename_size, true); + if (!filename || filename[filename_len] !=3D '\0') { + unlock_user(filename, physical_filename_addr, 0); + semi_cb(cs, -1, EFAULT); + break; + } + if (strcmp(filename, ":tt") =3D=3D 0 && qemu_semihosting_console_has_chardev()) { ret =3D alloc_guestfd(); @@ -513,6 +510,7 @@ static void sim_handle_trap0(CPUHexagonState *env) ret =3D guestfd; } } + unlock_user(filename, physical_filename_addr, 0); semi_cb(cs, ret, err); } break; --=20 2.34.1 From nobody Sun Sep 27 23:50:08 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=oss.qualcomm.com ARC-Seal: i=1; a=rsa-sha256; t=1789425176; cv=none; d=zohomail.com; s=zohoarc; b=jV1IRdyFHXAn9tXQKtI5xvh05TydXrBLCgMKDdaQBo26L9YCQF3C/0Ea/hJXr3MWwqHdqmynR3jhptyWiVH8OWAwcs/yHnIBuvM8oi1Bo9vZTyif4MBTZRTFl1urdIH7vFRvADTUWSO2PSDLRIHfCmMhDcXijUAWCwNLJxjz+4c= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789425176; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=8ooTsCDYAQDQktBYGMxjuQ/5s/nm29muz942v31i4y8=; b=C51KTNiPjtBBpV1il2WdmJnowhuuGFnStOwtu5ZFeeB72rxkJO72QOJ5qTEi2cO6h3F0wcojWuDwZ+Sin9+qf/1x/zPOo5JLtm9CcUsIzPkTscipvJFkgwuE+qXV8Gme3pJDGMUp9/hMGLOIAZGeJJk5yvqcjZ1764QMAGtSZWM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789425175774332.8212681139445; Mon, 14 Sep 2026 15:32:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x6FDs-0000fp-Vv; Mon, 14 Sep 2026 18:32:25 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x6FDc-0000dM-QQ for qemu-devel@nongnu.org; Mon, 14 Sep 2026 18:32:14 -0400 Received: from mx0b-0031df01.pphosted.com ([205.220.180.131]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x6FDa-0006qV-UY for qemu-devel@nongnu.org; Mon, 14 Sep 2026 18:32:08 -0400 Received: from pps.filterd (m0279873.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 68EJYQJI1485156 for ; Mon, 14 Sep 2026 22:32:05 GMT Received: from mail-pl1-f198.google.com (mail-pl1-f198.google.com [209.85.214.198]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4gpg2ktjwv-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Mon, 14 Sep 2026 22:32:05 +0000 (GMT) Received: by mail-pl1-f198.google.com with SMTP id d9443c01a7336-2d94f086fedso51986605ad.1 for ; Mon, 14 Sep 2026 15:32:05 -0700 (PDT) Received: from hu-bcain-lv.qualcomm.com (Global_NAT1.qualcomm.com. [129.46.96.20]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba7a9bb56sm30190753eec.31.2026.09.14.15.32.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 14 Sep 2026 15:32:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= 8ooTsCDYAQDQktBYGMxjuQ/5s/nm29muz942v31i4y8=; b=IWP7+aS6IZQYNkqu S3RQIrFQ9/jGyUJiGK0pSJfsftlGzr5haw8s+AvPyDvXTomMWQCWH0pMNn3VY8OL wXRIdicfnItw4ArJLCgcShDZRejV2d3xmv7wQsZaGbnyOFeo0wFqMy50FxR2r9yI 0IHtSxHssurGE8JPrULv/DSUxNvz9LASgvV3X+dXiisA8y9jDqjmscTrD6nWvAaw 9XVr1T5Ty/TMeyZGTYHN7VckWFy0F1HOt+/eAYIcbif/TpQckGxHZ+AXhel9121D TvTkKQjRj3TfmEjggcReUr18eNWf90Y4tKBRazl2blQ4IE9BuhpX5adz/vDsgsod 533N4g== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1789425124; x=1790029924; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=8ooTsCDYAQDQktBYGMxjuQ/5s/nm29muz942v31i4y8=; b=J5mBXUuaHl6y6muhar+SkWkPiKj+yT9gElw+x0tLT3/Ilbl34949rBppWRSYnkVp9V FIuLXvoCPNe7Z6B/HMGTliXPmO5Nj3faUZyPBRpvnIZt/SLFK6XuACduBVysr1W0aJ/0 gjjitBTDUY61At97dcN93FudZ4m5ZVY9f9hlAlyVYmfi47zDXYfDOByChxuGOH00flaA 0zuQ9VuBW2vZD4KFJg/k9lACzukg7NIo/1PTdgiL3RwtityXR20YUCigfA0niV1tUmns dIzzD34Rqhn1SZOtIbH74WWiMTPx2OIzr+hXvSJ/ZoW3D499L0VigvkscEt+lGfWR2E5 3E6w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789425124; x=1790029924; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=8ooTsCDYAQDQktBYGMxjuQ/5s/nm29muz942v31i4y8=; b=h0XeF7hdqeKut+wHg6V187DnjjFae6sv4wUhTXZixCW5EeRPLW6P6lz0KOIsDdAQW+ 2Jx907whunIMWXXqoeHcoO+0XgUj9RuxzuhGsbQUIp/y/R9wl+b+vWMEgL7RvjiB4DE5 aCIB+OxLYDSNLz2SC7RTE7MhrE8TMy1Ng9QnG7zt/ekiKVOHiSgwRs6JrZr9mvL7OyOw nQLgdw7Ww4mqOUw3jHkrT6O5ynGUvh9UVwsTLMsZwDZHQPc2pu6vnifUrx+UQUlQT0+Y 9J2EUStoWg9J0GHzUh0ohQT8cMc7cbH6oC7txv52RSCSGlcDyc7mkwG2wCUQO7cO3XvF +s+w== X-Gm-Message-State: AFuF++mFl0levZrw5c644NFfnZ6FrJUG+DVaBzBlYCJebgL/TUyYEKMN znu+zcZMir4jsvVEbbX8kn6Dewb6Ae/pRbqR65KeW73cc4uViRl8LDFv7VqBpB0YuVqzZU+LvuQ 16LZpsezCjbpopy/MkKBXYPXehJNiupQ96g0t32P2jDnMy6OcNoGRhRz8729A7DAMHg== X-Gm-Gg: AYBFou2N2AMUWHkwYiD0+2JpdnD82BdKIZQqfFmEEpz0bwpd007ZoLtEsqvWP0cqsUd IIsJKlOh8Xe6p4ypDS8SbHYWpI8iWM2Dc05rAM4QepJ/B5jU209fVvTQl9rIO9GBt9v+AmcCPrj lERKiCiPxlUkR5oc5xgKJbHf53/tOGwxymfkl0mGHr3QBZmwwZlSCltULLPOIAf5BInlc2eom5H mkuQ0uvwaSX0X42Rk44e7vYqxxLfU4gkj12krEz5l/irrTyV8VjHUwU6R4FqzOdruR3kDiN/gNj H+LRWPO1nPpijg7893bhunWka5q/DGvBz948+tVEFci/W9ocdsQE0uCZy81GhIN2GizyGVgGWXD oopPWdIdCx09VSzAov1DdH+VV9cm+uXOO0z83m67VJqwkCiUb X-Received: by 2002:a17:902:fc44:b0:2da:e67a:87d4 with SMTP id d9443c01a7336-2dd6c75e064mr97760285ad.19.1789425124406; Mon, 14 Sep 2026 15:32:04 -0700 (PDT) X-Received: by 2002:a17:902:fc44:b0:2da:e67a:87d4 with SMTP id d9443c01a7336-2dd6c75e064mr97759535ad.19.1789425123861; Mon, 14 Sep 2026 15:32:03 -0700 (PDT) From: Brian Cain To: qemu-devel@nongnu.org Cc: Brian Cain , Pierrick Bouvier , peter.maydell@linaro.org Subject: [PATCH v2 2/4] target/hexagon: fix semihosting STAT filename handling Date: Mon, 14 Sep 2026 15:31:57 -0700 Message-Id: <20260914223159.2735262-3-brian.cain@oss.qualcomm.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260914223159.2735262-1-brian.cain@oss.qualcomm.com> References: <20260914223159.2735262-1-brian.cain@oss.qualcomm.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Proofpoint-ORIG-GUID: VmobspjDbRYP2Uhbpe8vfu57rRZw-d_k X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwOTE0MDMyMiBTYWx0ZWRfX56oV2jofnbiu GRJy+iw3jd59JA5kYvcPdnToDTR2+dfVmRTo7l+0RLLghjmDYpCrlAE6ADb8zEcse3N1zw8koab /uQpT5F7arY3+7vzev1Y+woILzXeoxAbxrJTDmN/XpjtIw0x0KY5AvswCb9JldwYPDC8nFfCRxI oCXkyYVRATjTYcqOIUITrsQV2CgcUBEdWQ9es63ebmn5YFTrDERb9n5zqtKfvV+Qiy28gZmeQEx 0/G4aQoXyeyvejnHSDDUsNX0pOQFb53todcjr12ox1ryTYh9JNdDj7uuiYfYe8Qr8U2GTFX0IHg 8Pffa3GfN/azX4KvaNzPDC/dxvwICVL/V6evZlS5BAV0og48rOhUsgaWEezVgFMjFp/DT3ALoZD aabn8TOJCm681Wm2pzx/zTJnvGjNG2RgbxWJFnppPnhiKEIAQBicweSm10trJSaEzx0KZIdrJlA 31vEcBhSqFXZA8ikfIg== X-Proofpoint-GUID: VmobspjDbRYP2Uhbpe8vfu57rRZw-d_k X-Authority-Analysis: v=2.4 cv=M7TYuCws c=1 sm=1 tr=0 ts=6aa875e5 cx=c_pps a=MTSHoo12Qbhz2p7MsH1ifg==:117 a=ouPCqIW2jiPt+lZRy3xVPw==:17 a=IkcTkHD0fZMA:10 a=VdqzKS8jKosA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=rJkE3RaqiGZ5pbrm-msn:22 a=VwQbUJbxAAAA:8 a=pGLkceISAAAA:8 a=KKAkSRfTAAAA:8 a=EUspDBNiAAAA:8 a=vVSmPHnlUJunR1QNDXkA:9 a=QEXdDO2ut3YA:10 a=GvdueXVYPmCkWapjIL-Q:22 a=cvBusfyB2V15izCimMoJ:22 X-Proofpoint-Spam-Info: AW1haW4tMjYwOTE0MDMyMiBTYWx0ZWRfX/qIsZN79esOG OgpHEF+MpzgADBlNv6jnuKIezTKWd5g4g2gVspDRna+IawH/2vj0mZiYkXDCH/ZiCu/Ab6qzQoK XhjQSFbjUUDzQZmDeuS2/XEXAwM0fho= X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-09-14_04,2026-09-14_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 clxscore=1015 bulkscore=0 impostorscore=0 suspectscore=0 malwarescore=0 adultscore=0 lowpriorityscore=0 spamscore=0 priorityscore=1501 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2609040000 definitions=main-2609140322 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=205.220.180.131; envelope-from=brian.cain@oss.qualcomm.com; helo=mx0b-0031df01.pphosted.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @qualcomm.com) X-ZM-MESSAGEID: 1789425178425158500 HEX_SYS_STAT could pass an unterminated local filename buffer to stat() when the guest string filled it. Use lock_user_string() to map the guest string safely. Fixes: 7711fdba88b ("target/hexagon: add main arch-specific semihosting ope= rations") Link: https://lore.kernel.org/all/CAFEAcA9MOs6VfHf2UHZ8z4cdvaB+7DY6hJb2emYZ= 2aLSe-t6iw@mail.gmail.com/ Suggested-by: Peter Maydell Reviewed-by: Peter Maydell Signed-off-by: Brian Cain --- target/hexagon/hexswi.c | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/target/hexagon/hexswi.c b/target/hexagon/hexswi.c index 21e5d630a75..d0ba1162a5d 100644 --- a/target/hexagon/hexswi.c +++ b/target/hexagon/hexswi.c @@ -551,20 +551,20 @@ static void sim_handle_trap0(CPUHexagonState *env) struct stat st_buf; uint8_t *st_bufptr =3D (uint8_t *)&sys_stat; int rc, err =3D 0; - char filename[BUFSIZ]; + char *filename; target_ulong physical_filename_addr; target_ulong statBufferAddr; hexagon_read_memory(env, swi_info, 4, &physical_filename_addr, ret= addr); =20 if (what_swi =3D=3D HEX_SYS_STAT) { - int i =3D 0; - do { - hexagon_read_memory(env, physical_filename_addr + i, 1, - &filename[i], retaddr); - i++; - } while ((i < BUFSIZ) && filename[i - 1]); + filename =3D lock_user_string(physical_filename_addr); + if (!filename) { + semi_cb(cs, -1, EFAULT); + break; + } rc =3D stat(filename, &st_buf); err =3D errno; + unlock_user(filename, physical_filename_addr, 0); } else { int fd =3D physical_filename_addr; GuestFD *gf =3D get_guestfd(fd); --=20 2.34.1 From nobody Sun Sep 27 23:50:08 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=oss.qualcomm.com ARC-Seal: i=1; a=rsa-sha256; t=1789425189; cv=none; d=zohomail.com; s=zohoarc; b=VOcr3I3k8TeIBTltxiI8VR9tovA+qRokIM9KDSoJp4K/VJTeb84OjzGPM2RKE4akozP1G+3K0WqsnIwAbJ3LlMF4h9nPmWQdEUFndF+Z+33woA+O7nQSo4fN6Es3Dk2rTiyf2DLI8z2D/zmjLLRf9ktW73T5uhnr4sxSBOSMuVM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789425189; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Fvdta/9nLk7vH6oi/7z0FBfPJxagNMCdZfN2FbXOnks=; b=arHjK9TwkSeRzUtrIMh8BMK8/evmU8ovczXVnze7aLlI6pOHF9QO/XOFxd5BJtaVgqeZu3TlpgR9+VvmVNfBylP6db9YvhXieACrxKZq33FmSh2N+crGlQ2trg0Sxa1Je8A6+S8iYF/TCUj4dyqB0VFm3tRuQmRFuh2qEZhgrvs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789425189146162.82236825936548; Mon, 14 Sep 2026 15:33:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x6FDu-0000gd-Vc; Mon, 14 Sep 2026 18:32:27 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x6FDf-0000dW-3t for qemu-devel@nongnu.org; Mon, 14 Sep 2026 18:32:14 -0400 Received: from mx0a-0031df01.pphosted.com ([205.220.168.131]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x6FDc-0006qf-AK for qemu-devel@nongnu.org; Mon, 14 Sep 2026 18:32:09 -0400 Received: from pps.filterd (m0279866.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 68EJYOf9771779 for ; Mon, 14 Sep 2026 22:32:06 GMT Received: from mail-pg1-f200.google.com (mail-pg1-f200.google.com [209.85.215.200]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4gpcjg3cb0-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Mon, 14 Sep 2026 22:32:06 +0000 (GMT) Received: by mail-pg1-f200.google.com with SMTP id 41be03b00d2f7-cc21bc2923fso3629532a12.2 for ; Mon, 14 Sep 2026 15:32:06 -0700 (PDT) Received: from hu-bcain-lv.qualcomm.com (Global_NAT1.qualcomm.com. [129.46.96.20]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba7a9bb56sm30190753eec.31.2026.09.14.15.32.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 14 Sep 2026 15:32:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= Fvdta/9nLk7vH6oi/7z0FBfPJxagNMCdZfN2FbXOnks=; b=oHvUy8myi2hUiXSG CRXF5VjwOSosZDYh1pvaoLxGo5YxCUJTNU6AB+bpB4IHowqkvd4aq9tjQzOMMEko G80aoLxDvt/Ehe/LlhgGnn+p/y2PVINVvZfPez7G/J5Nr461uL0N3MWDhH0ynvCN MebNrGvbAB5o/AX3ao1P5dxIpKlty8AC9YfAumfEkYUL/nU3ZTGiiisp6rvmyCe4 v8KuMsWpyFdefCAvV30k5G1K7fr7Ocsl/z4H0c9qYQa6vC3SAxKokPXYAp9WwpCk J4+/zgUTycM6xfXekJwmBuEMjLgAup1871hqyKvCSK5vcDOAo3s1sXNQcmviDThp wdiDlQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1789425126; x=1790029926; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=Fvdta/9nLk7vH6oi/7z0FBfPJxagNMCdZfN2FbXOnks=; b=MF9fgbhO8y4qUgGkxJPnPdAyDsErw/h19IQUGOD7KKPiA4UsQl+E5GzxFiKYUkgapi LuhWI5+1oiDUFMdpWPfDokwyuuBRpZ4O7eA1QBHp7Uokjs/jRNOeSYczVLk86ivT33TT AaiSz9oXibzZLbT+jCdQ7BD52DGqt3662V1he/bTJ2u+pP85XEXe3IIQ5Npg0TjTA2Aq e84n9kl42zpcdEhDS8s42EAxLzWhPt4Nw0Q2sGxr7Cf0jiPeUGW1AjudJjbD7Yq8JKGI SR8r2gnAtkRG6jUWOgTTOTfQ1OHdR0JN1SD2LFhtONTBqmXcSfp4xX6qyDl+zNjNOFJF zZQA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789425126; x=1790029926; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=Fvdta/9nLk7vH6oi/7z0FBfPJxagNMCdZfN2FbXOnks=; b=OhAtGNrNZNBUdKBiIpLL9DF4WoXjB7yFCKdZDdSAXkTUi0TP6oodl4eK9R4lsQkaHz G6aWp792aCGqjERP0siFazmwb5v0BTyDZFVJVAn1KPbr+kUxKxhjNYcKY03hGj4AkxhR /bL6brEEgTwC1irGR4w9NY79LDR8MuguIcTt2VtMuKOyVQsuRRUUVi47+ISPh3W8qVvP qlACmzPUnp0OBqaRu1AKv6fWcobcE2/BldLxCj3lD4DfAteLRw6TPDtRTM/1ETvvswn/ wHRXZ30vU43bWHXcS4XhrbAC5PtZr923WgaODNLOkRjb64ss9GhIQ/ekIjuuV/SjL+Ae eT8Q== X-Gm-Message-State: AFuF++kBOVUEHbnY+ZkoIOV/c9OW+XQ1hUcmYQlPJTjvOBiTbUD00HtI Dq7AAtkjT2Hu/5EJrhpPWn7xtCLIQECVGlI3f5ziEjKunoKJGHf+a/G57BETsQ+fXFLLYqzkan7 fSqmOdIP1j1i3iJpnYV6Vp9rVutNyTfe/UgmR5+KRVvhmuAxIKQMXBnvy8vw4e7OB5g== X-Gm-Gg: AYBFou2rPPCOErUTpNPplmYq+6btnQ9NzPNe/BRMuo2jRDj3di0rT+8GU1+ku+A1YOc vpyUCyvPfZYR6RjW0yJafv4EMURpN/m7JxGniw8B3NbJ5A06Wdh790SN9sy1/1eYa0An2MBVoZj Ctcg1HtKizgMcPXDnKucBIP1gtFdHmpkI4PGRtcPyaZz76uNEd/Is5b2TdtSAQUBDwYORhmQYTO pRV3xjRC/TSCNEzl6f26gOPDn3prYJsUnh0gbipLGi5kbt/OT9BuGkI7WmT8Sk292CW6U7SH+ZQ OTRf49Y8ZzuN6FerNzn6p6yyXV6tCb6YVH312GmUXLz3u+PsIKxvsklVWgiI2ei4CJ0JVXHeqiD p+yyJrFiYM5gAZwP3YXnKLBGj0+6ksMXkmdNHITrtmTQXCmYg X-Received: by 2002:a05:6a20:2446:b0:3d1:af47:5f80 with SMTP id adf61e73a8af0-3db404c4127mr9369425637.11.1789425125782; Mon, 14 Sep 2026 15:32:05 -0700 (PDT) X-Received: by 2002:a05:6a20:2446:b0:3d1:af47:5f80 with SMTP id adf61e73a8af0-3db404c4127mr9369387637.11.1789425125407; Mon, 14 Sep 2026 15:32:05 -0700 (PDT) From: Brian Cain To: qemu-devel@nongnu.org Cc: Brian Cain , Pierrick Bouvier , peter.maydell@linaro.org Subject: [PATCH v2 3/4] target/hexagon: fix semihosting ACCESS filename handling Date: Mon, 14 Sep 2026 15:31:58 -0700 Message-Id: <20260914223159.2735262-4-brian.cain@oss.qualcomm.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260914223159.2735262-1-brian.cain@oss.qualcomm.com> References: <20260914223159.2735262-1-brian.cain@oss.qualcomm.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Authority-Analysis: v=2.4 cv=CKa/zhrD c=1 sm=1 tr=0 ts=6aa875e6 cx=c_pps a=oF/VQ+ItUULfLr/lQ2/icg==:117 a=ouPCqIW2jiPt+lZRy3xVPw==:17 a=IkcTkHD0fZMA:10 a=VdqzKS8jKosA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=YMgV9FUhrdKAYTUUvYB2:22 a=VwQbUJbxAAAA:8 a=pGLkceISAAAA:8 a=KKAkSRfTAAAA:8 a=EUspDBNiAAAA:8 a=pS50CBgNNeok3lFgILkA:9 a=QEXdDO2ut3YA:10 a=3WC7DwWrALyhR5TkjVHa:22 a=cvBusfyB2V15izCimMoJ:22 X-Proofpoint-ORIG-GUID: 8vWCUsdaZpTB90jPxDF2sdL0WgCm5r7a X-Proofpoint-Spam-Info: AW1haW4tMjYwOTE0MDMyMiBTYWx0ZWRfX8S19MAXKB/KL fRjkpkKTa+FjGsdVIXT9LXEXOrbe4q8hpxo4lKkU207pHHiny8eAAlScSjY+4HAXWPJoyjvlYMp 5gbcpTK6JEghOkXjkbksIyD+rdmf++E= X-Proofpoint-GUID: 8vWCUsdaZpTB90jPxDF2sdL0WgCm5r7a X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwOTE0MDMyMiBTYWx0ZWRfX/YFQzy9BV/Qw 4DSqQyqHU1vcy3md1BhLAzq2pSnq1zV6WuwxYZ1b85/62vLMm39yR6TTt0vho0Fm3mWlicZYdJs hXoqsFMdQADF/yY/uoN46ybHVuFHOUzKt4fz8jl9lqpgXDNzUd1DKYJgSIjvRF4boL0P152izo/ cxtV8+8gJNHYy5i/V+f2GNNuYdR9bW4hvgclEKd6JIEePevHgHhHGKNaOtV87uD9V7tUKrJ7C6n ITLrhokmDWRzH8MyHUpO1I7748Vb9iDxBYwvPdPA1tZeGQ7O+DpyrvxkzOMTl/2VlRpNf88eNKr D3IKSWWNxwuX/PnpGeMlGrXbGrJwlH49K90FNBdtrppCZ0RHcc3o6a46tAY+DamTyqbHvvOXe4L mpB93LWmMukJW7RQIRxWyuTfRCD5ya0HkqgJXG0tvD16yzatu/Ri3io11h+5amKiKdNSEE2e6VU DKC2//n027YsCDPKJ5A== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-09-14_04,2026-09-14_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 malwarescore=0 clxscore=1015 priorityscore=1501 impostorscore=0 spamscore=0 lowpriorityscore=0 phishscore=0 bulkscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2609040000 definitions=main-2609140322 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=205.220.168.131; envelope-from=brian.cain@oss.qualcomm.com; helo=mx0a-0031df01.pphosted.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @qualcomm.com) X-ZM-MESSAGEID: 1789425190038158500 HEX_SYS_ACCESS wrote a NUL byte past its fixed-size filename buffer when the guest string filled it. Use lock_user_string() to avoid the out-of-boun= ds write. Fixes: 7711fdba88b ("target/hexagon: add main arch-specific semihosting ope= rations") Resolves: Coverity CID 1685942 Link: https://lore.kernel.org/all/CAFEAcA9MOs6VfHf2UHZ8z4cdvaB+7DY6hJb2emYZ= 2aLSe-t6iw@mail.gmail.com/ Suggested-by: Peter Maydell Reviewed-by: Peter Maydell Signed-off-by: Brian Cain --- target/hexagon/hexswi.c | 21 ++++++++++----------- 1 file changed, 10 insertions(+), 11 deletions(-) diff --git a/target/hexagon/hexswi.c b/target/hexagon/hexswi.c index d0ba1162a5d..e56a60f2f06 100644 --- a/target/hexagon/hexswi.c +++ b/target/hexagon/hexswi.c @@ -610,25 +610,24 @@ static void sim_handle_trap0(CPUHexagonState *env) =20 case HEX_SYS_ACCESS: { - char filename[BUFSIZ]; + char *filename; uint32_t FileNameAddr; uint32_t BufferMode; - int rc; - - int i =3D 0; + int rc, err; =20 hexagon_read_memory(env, swi_info, 4, &FileNameAddr, retaddr); - do { - hexagon_read_memory(env, FileNameAddr + i, 1, &filename[i], - retaddr); - i++; - } while ((i < BUFSIZ) && (filename[i - 1])); - filename[i] =3D 0; + filename =3D lock_user_string(FileNameAddr); + if (!filename) { + semi_cb(cs, -1, EFAULT); + break; + } =20 hexagon_read_memory(env, swi_info + 4, 4, &BufferMode, retaddr); =20 rc =3D access(filename, BufferMode); - semi_cb(cs, rc, rc =3D=3D 0 ? 0 : errno); + err =3D errno; + unlock_user(filename, FileNameAddr, 0); + semi_cb(cs, rc, rc =3D=3D 0 ? 0 : err); } break; =20 --=20 2.34.1 From nobody Sun Sep 27 23:50:08 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=oss.qualcomm.com ARC-Seal: i=1; a=rsa-sha256; t=1789425189; cv=none; d=zohomail.com; s=zohoarc; b=DEJS1FY2gvsqVcoCE9NKTMJYypOLunntvWRva7nsISUDL5CXf12giEHgBSbGEmGCjbL0e2HTv3Dm+lOPie5Ytl2ElPWziATsyUcz+TLkjRq8mwEWoc+WMk0vCkvjWO6cL2GBZx2UHsTjNbzy+hrGweFiPg4a2S+QPwKQgERnBDM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1789425189; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=khkDcAsBQw8rtOAWG3gTgC9EzYv/Lss3tm3hotvMzlQ=; b=jum4QmypqAeFC4SfS+G7r9vxag5zp2h5chk/gPdZS4K+K8UDeOJskVtTmhQVCE//p15qrrWJtc6ir9LtiSGDO9rQrCfRPJzzv21T/u02XHO1Iq+X1RpGbsgu+2lHU8BMGUzbf9GJO3VK34wcnbi3ibCZkJ4Mt9u5HvMY82hHAPI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1789425189128571.2283822333416; Mon, 14 Sep 2026 15:33:09 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x6FDt-0000g7-GF; Mon, 14 Sep 2026 18:32:25 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x6FDi-0000dp-OM for qemu-devel@nongnu.org; Mon, 14 Sep 2026 18:32:19 -0400 Received: from mx0a-0031df01.pphosted.com ([205.220.168.131]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x6FDe-0006qx-Ok for qemu-devel@nongnu.org; Mon, 14 Sep 2026 18:32:13 -0400 Received: from pps.filterd (m0279866.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 68EJYmtn772071 for ; Mon, 14 Sep 2026 22:32:08 GMT Received: from mail-pj1-f69.google.com (mail-pj1-f69.google.com [209.85.216.69]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4gpcjg3cb3-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Mon, 14 Sep 2026 22:32:08 +0000 (GMT) Received: by mail-pj1-f69.google.com with SMTP id 98e67ed59e1d1-398dc3d8f0fso305749a91.0 for ; Mon, 14 Sep 2026 15:32:08 -0700 (PDT) Received: from hu-bcain-lv.qualcomm.com (Global_NAT1.qualcomm.com. [129.46.96.20]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-33ba7a9bb56sm30190753eec.31.2026.09.14.15.32.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 14 Sep 2026 15:32:05 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= khkDcAsBQw8rtOAWG3gTgC9EzYv/Lss3tm3hotvMzlQ=; b=Co0e5KkaEfvzkdR1 mf712+Mpuao0gEhQ2whnVguR26D2CF8SDn5UcO1jFYVJlxkaAqWjY4d2hrI21quV uDQTYV1jbvn7NDefKKzMhcz5Yg8PwR9goe7VkgTORBkY372gjitX85oENhwHmg2E rx3TgFuvQWaD14PFDcSkh2DUBZ4GAUP4RA3dZAA0oZcfsPHIoY8t9Q2q6Zq7MOjg 79d54kpqdk0L6GAtuYLeE9g+phAgfJN8wYdCi+O3yAiNzQxb4TrtyvAlU/W2jbem 3bkPpzT0z/vL1muTa47opQEkcMCYAgQViOhTxXVHvYga9QybtK6KCP82SyHGewRd 8sj3ZA== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1789425128; x=1790029928; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=khkDcAsBQw8rtOAWG3gTgC9EzYv/Lss3tm3hotvMzlQ=; b=Qws1a78jMPRnRp50J3Do1KkihFjz+J5YTuc5QRiST3sc2qFwIi/dQorW1/StB39zbm ZkeqiadhkuWsu4H0n4iZ5MyvMclVT1Syyn9ZFEyzRUHsJ1+JhFHZWH4FAjrzXDhvZTGG pYefh3mYQCtb4IWa9f1aSo7SwO1MuJjkKjty9v+uBLWZeunbYkCoAuj893eTS1zMi5Q6 BwwtJ3RH+WzIs7LeO3X8sknBbIOHbxtQIM6mtHbjpLtuQhWDPc1uo7+xbnMYhBscVDjq xnitS8HO06nZctRVAGYHsfRwAEc52UBpHCZJLT7xrykjokbYN0jw4LotH0IYKvA5WsN9 ulvg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789425128; x=1790029928; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=khkDcAsBQw8rtOAWG3gTgC9EzYv/Lss3tm3hotvMzlQ=; b=XJBlBEI7UORAUZwdjIW5uS3y/vfqoXhihT99s9xBq5kB14cpaNKe7hxDb1HeQ7N3bB dj84InF9XrDQwmZMqGnktgGDg0SyD9z3saXUonuV9sQN4XuMQ0PllCUznjFUReJocis/ HnL9zQZ5LqaWv7SjWkRhuC3Slr04QNiccA0nQL5qFBqtLewr2SCQAmrcx9+Bc4EmcPFc oSPlIILw6eAnbiktEU1NA7QADsy42aZfVVs/5GqAfRLqbpFEGdRAkvZOhTF29vpYuz/c Px0qpJzmQQ7qVL9q6gkHIUVPXUa/0RC7Ur9volhNf2cW/+afJ/EskLGXQQoKzMpiQbaU NG6w== X-Gm-Message-State: AFuF++nXbMPU4Q+9thylcsU7a9XL2/LbaWcKKaykFpgKMRlmgyp2Lwrr UYyu9ll2XsLkKt6JTV28Waip+ELNh/WkYOK7YrD6EZPSmlMb7b8n37SghwoJyLrOG648Lhh9cPU G5nIAnib1xEdE/mmS0H8LTjtJFAdFDdOlGZFhfJZkgRTC2qTc/mnS1FQmAbjzN2dEpw== X-Gm-Gg: AYBFou3GVG2Jrf10TfJ+llabaqNSbFN33wAacjZ+vwTjtG9X06DWDt3qohwQuIgaaYF qYQI0L1we07g0F+GQKGJsWXjznz4AyCVgv7ixI5XXTSqp7pK9zBBjptvQrUjc38XSn2xpecty40 pIAS5uri0o7GxtYV5VZmN9Byi4An9Z5qi4VPTqHajlL8oriWWGQdECrz4yogunv81VcUCR6zBdr LXqLmjfn/5Hs39xiEw25ZbW95w91waTR8OHy232dlDxRE1/+vekszqVRhGx025prTGvrjROt4Nu 8LdHweHOEjDmlrHx6ZlCVWt9cqqasKTJQ3ph4EsG/Q4MHI3eR4T5yiTul56/Rcoipk2L2WdOe+q wp1+jNb85yUgYCPWyGnIGWDnOcmaQ633qP22o3gUwzaCE0pe0 X-Received: by 2002:a17:90b:398d:b0:39d:ec1f:b3fd with SMTP id 98e67ed59e1d1-39dfe036be1mr1786065a91.8.1789425127509; Mon, 14 Sep 2026 15:32:07 -0700 (PDT) X-Received: by 2002:a17:90b:398d:b0:39d:ec1f:b3fd with SMTP id 98e67ed59e1d1-39dfe036be1mr1786011a91.8.1789425126869; Mon, 14 Sep 2026 15:32:06 -0700 (PDT) From: Brian Cain To: qemu-devel@nongnu.org Cc: Brian Cain , Pierrick Bouvier , peter.maydell@linaro.org, Matheus Tavares Bernardino Subject: [PATCH v2 4/4] target/hexagon: add directory semihosting operations Date: Mon, 14 Sep 2026 15:31:59 -0700 Message-Id: <20260914223159.2735262-5-brian.cain@oss.qualcomm.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20260914223159.2735262-1-brian.cain@oss.qualcomm.com> References: <20260914223159.2735262-1-brian.cain@oss.qualcomm.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Authority-Analysis: v=2.4 cv=CKa/zhrD c=1 sm=1 tr=0 ts=6aa875e8 cx=c_pps a=vVfyC5vLCtgYJKYeQD43oA==:117 a=ouPCqIW2jiPt+lZRy3xVPw==:17 a=IkcTkHD0fZMA:10 a=VdqzKS8jKosA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=YMgV9FUhrdKAYTUUvYB2:22 a=EUspDBNiAAAA:8 a=JARE-9YbG5QTd34tVfMA:9 a=QEXdDO2ut3YA:10 a=rl5im9kqc5Lf4LNbBjHf:22 X-Proofpoint-ORIG-GUID: xXbV6znn29t8BGO2pEdpeLSQTaBoQ3wU X-Proofpoint-Spam-Info: AW1haW4tMjYwOTE0MDMyMiBTYWx0ZWRfXy1eHmX4aU8bl Ywu6PLlf8VVA7oqAtO7ptOjXHMjjyY4Il1nvBOaHE7FcsLASJ6FKZSUQCxXsHV79vRmX2XptIdD k3E2oKybehCxGx6hsSEIQifK2/qNkks= X-Proofpoint-GUID: xXbV6znn29t8BGO2pEdpeLSQTaBoQ3wU X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwOTE0MDMyMiBTYWx0ZWRfX/PycGHBPUKiz TUtOMrJ2V8/4MjanMXHi5Xh6S0LtXlqZ4vnj3tezDwpIisJeRAGgXJCt5+nnVlpQMEjvOVhc9qB vYxgtAkOPkQuR+HJGcMLPlvoZxaNF3MkwvDVy9BS6+1jzVA1Ez3GlOe7uC2W9AmVMhQmmfJ/+6C b/K+D7LyH4yWA9qmtJm5JoixUov4yp4r7UZaORNjM0I1zO9Lv+3eKc+ttHTu9K31E7w4Zs173YY 8UYxa+KJUbDAqKPjupSj6MZoE4tbHaXMahACXMfu3yyBO/5dRJI2pDz/LZHGrFyuhczmWDhjyf2 bpMxG+zK9Tm5De90HhZrIG57NptqgQbo9WhnZeYJq4M//u74AL15YDES4FMZc4KdNbgAMxKfyRk lElzTggHrIxnLEW0EEXSMQaRDzZggbGBN3W9IvSjx4Tjw+q8h7nlrOirxv+j5XwM1H603fXlRkt +rnvN1m31h+lxBe1+ww== X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1176,Hydra:6.1.134,FMLib:17.12.100.49 definitions=2026-09-14_04,2026-09-14_02,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 adultscore=0 malwarescore=0 clxscore=1015 priorityscore=1501 impostorscore=0 spamscore=0 lowpriorityscore=0 phishscore=0 bulkscore=0 suspectscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2609040000 definitions=main-2609140322 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=205.220.168.131; envelope-from=brian.cain@oss.qualcomm.com; helo=mx0a-0031df01.pphosted.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @qualcomm.com) X-ZM-MESSAGEID: 1789425190130158500 From: Matheus Tavares Bernardino Bare-metal Hexagon programs use OPENDIR, READDIR, and CLOSEDIR semihosting calls to enumerate host directories. Directory handles are shar= ed by CPUs in a cluster, allowing guest indices to resolve across calls. Use lock_user_string()/unlock_user() to read the OPENDIR path from guest memory instead of copying it into a fixed-size buffer. CLOSEDIR clears its slot in the directory list, so a stale index reports EBADF instead of dereferencing a freed pointer. Also add a functional test for the new semihosting operations. Signed-off-by: Matheus Tavares Bernardino Signed-off-by: Brian Cain --- include/hw/hexagon/hexagon.h | 14 ++- hw/hexagon/hex-subsys.c | 32 ++++--- target/hexagon/hexswi.c | 108 ++++++++++++++++++++++ tests/functional/hexagon/test_systests.py | 11 +++ 4 files changed, 153 insertions(+), 12 deletions(-) diff --git a/include/hw/hexagon/hexagon.h b/include/hw/hexagon/hexagon.h index 62398eeb359..58bdcabe87e 100644 --- a/include/hw/hexagon/hexagon.h +++ b/include/hw/hexagon/hexagon.h @@ -11,6 +11,7 @@ =20 #include "system/memory.h" #include "hw/core/boards.h" +#include "hw/cpu/cluster.h" =20 struct hexagon_board_boot_info { uint64_t ram_size; @@ -159,6 +160,17 @@ struct hexagon_machine_config { union hexagon_config_table cfgtable; }; =20 +#define TYPE_HEXAGON_CLUSTER_STATE "hexagon-cluster-state" +OBJECT_DECLARE_SIMPLE_TYPE(HexagonClusterState, HEXAGON_CLUSTER_STATE) + +struct HexagonClusterState { + CPUClusterState parent_obj; + + struct { + GList *dir_list; + } semihosting; +}; + #define TYPE_HEXAGON_COMMON_MACHINE "hexagon-common-machine" OBJECT_DECLARE_SIMPLE_TYPE(HexagonCommonMachineState, HEXAGON_COMMON_MACHI= NE) =20 @@ -168,7 +180,7 @@ struct HexagonCommonMachineState { MemoryRegion ram; MemoryRegion cfgtable_rom; MemoryRegion vtcm; - DeviceState *cluster; + HexagonClusterState cluster; DeviceState *l2vic; DeviceState *qtimer; DeviceState *glob_regs; diff --git a/hw/hexagon/hex-subsys.c b/hw/hexagon/hex-subsys.c index 4e3a418340e..f76f803dfb0 100644 --- a/hw/hexagon/hex-subsys.c +++ b/hw/hexagon/hex-subsys.c @@ -98,14 +98,11 @@ static DeviceState *tlb_create(HexagonCommonMachineStat= e *hms, return tlb; } =20 -static DeviceState *cluster_create(HexagonCommonMachineState *hms) +static void cluster_create(HexagonCommonMachineState *hms) { - DeviceState *cluster =3D qdev_new(TYPE_CPU_CLUSTER); - - object_property_add_child(OBJECT(hms), "cluster", OBJECT(cluster)); - qdev_prop_set_uint32(cluster, "cluster-id", 0); - - return cluster; + object_initialize_child(OBJECT(hms), "cluster", &hms->cluster, + TYPE_HEXAGON_CLUSTER_STATE); + qdev_prop_set_uint32(DEVICE(&hms->cluster), "cluster-id", 0); } =20 void hex_subsys_create(HexagonCommonMachineState *hms, @@ -135,7 +132,7 @@ void hex_subsys_create(HexagonCommonMachineState *hms, &hms->vtcm); } =20 - hms->cluster =3D cluster_create(hms); + cluster_create(hms); hms->l2vic =3D l2vic_create(hms, m_cfg); hms->qtimer =3D qtimer_create(hms, m_cfg); hms->glob_regs =3D globalreg_create(hms, m_cfg, rev); @@ -144,7 +141,7 @@ void hex_subsys_create(HexagonCommonMachineState *hms, =20 void hex_subsys_add_cpu(HexagonCommonMachineState *hms, DeviceState *cpu) { - object_property_add_child(OBJECT(hms->cluster), "cpu[*]", OBJECT(cpu)); + object_property_add_child(OBJECT(&hms->cluster), "cpu[*]", OBJECT(cpu)= ); object_property_set_link(OBJECT(cpu), "global-regs", OBJECT(hms->glob_regs), &error_fatal); object_property_set_link(OBJECT(cpu), "tlb", OBJECT(hms->tlb), @@ -158,10 +155,10 @@ void hex_subsys_realize_cluster(HexagonCommonMachineS= tate *hms) /* * The cluster must be realized after its CPUs have been parented into= it * (see hex_subsys_add_cpu()) but before any CPU is itself realized, s= ince - * qdev_realize_and_unref() on a CPU latches cluster_index into the TCG + * qdev_realize() on a CPU latches cluster_index into the TCG * cflags at that point. */ - qdev_realize_and_unref(hms->cluster, NULL, &error_fatal); + qdev_realize(DEVICE(&hms->cluster), NULL, &error_fatal); } =20 void hex_subsys_realize_cpu(HexagonCommonMachineState *hms, DeviceState *c= pu, @@ -173,3 +170,16 @@ void hex_subsys_realize_cpu(HexagonCommonMachineState = *hms, DeviceState *cpu, l2vic_connect_cpu(hms->l2vic, cpu); } } + +static const TypeInfo hexagon_cluster_type_info =3D { + .name =3D TYPE_HEXAGON_CLUSTER_STATE, + .parent =3D TYPE_CPU_CLUSTER, + .instance_size =3D sizeof(HexagonClusterState), +}; + +static void hexagon_cluster_register_types(void) +{ + type_register_static(&hexagon_cluster_type_info); +} + +type_init(hexagon_cluster_register_types) diff --git a/target/hexagon/hexswi.c b/target/hexagon/hexswi.c index e56a60f2f06..ddea881de99 100644 --- a/target/hexagon/hexswi.c +++ b/target/hexagon/hexswi.c @@ -19,6 +19,7 @@ #include "hex_mmu.h" #include "hexswi.h" #include "hw/hexagon/hexagon_globalreg.h" +#include "hw/hexagon/hexagon.h" =20 #ifdef CONFIG_USER_ONLY #error "This file is only used in system emulation" @@ -31,6 +32,18 @@ #include "semihosting/uaccess.h" #include "system/runstate.h" =20 +/* We start from 1 as 0 is used to signal an error from g_dir_open(). */ +static const int DIR_INDEX_OFFSET =3D 1; + +/* + * GDir does not surface "." and ".." itself, so we track how many of + * those synthetic entries have been served for this handle so far. + */ +typedef struct { + GDir *dir; + unsigned int dot_entries; +} SemihostingDir; + /* non-arm-compatible semihosting calls */ #define HEXAGON_SPECIFIC_SWI_FLAGS \ DEF_SWI_FLAG(OPEN, 0x01) \ @@ -401,6 +414,13 @@ static void coredump(CPUHexagonState *env) qemu_log_unlock(f); } =20 +static GList **hex_semihosting_dir_list(CPUHexagonState *env) +{ + HexagonCPU *cpu =3D env_archcpu(env); + HexagonClusterState *cluster =3D HEXAGON_CLUSTER_STATE(OBJECT(cpu)->pa= rent); + return &cluster->semihosting.dir_list; +} + static void sim_handle_trap0(CPUHexagonState *env) { target_ulong what_swi, swi_info; @@ -666,6 +686,94 @@ static void sim_handle_trap0(CPUHexagonState *env) } break; =20 + case HEX_SYS_OPENDIR: + { + GDir *dir; + SemihostingDir *semidir; + char *buf; + int rc =3D 0, err =3D 0; + + buf =3D lock_user_string(swi_info); + if (!buf) { + common_semi_cb(cs, -1, EFAULT); + break; + } + + GList **dir_list =3D hex_semihosting_dir_list(env); + dir =3D g_dir_open(buf, 0, NULL); + if (dir !=3D NULL) { + semidir =3D g_new(SemihostingDir, 1); + semidir->dir =3D dir; + semidir->dot_entries =3D 0; + *dir_list =3D g_list_append(*dir_list, semidir); + rc =3D g_list_index(*dir_list, semidir) + DIR_INDEX_OFFSET; + } else { + err =3D errno; + } + unlock_user(buf, swi_info, 0); + common_semi_cb(cs, rc, rc !=3D 0 ? 0 : err); + break; + } + + case HEX_SYS_READDIR: + { + const char *host_dir_entry =3D NULL; + int dir_index =3D swi_info - DIR_INDEX_OFFSET; + GList **dir_list =3D hex_semihosting_dir_list(env); + SemihostingDir *dir =3D g_list_nth_data(*dir_list, dir_index); + uint32_t rc =3D 0, err =3D 0; + size_t i, name_len; + + if (dir) { + if (dir->dot_entries < 2) { + host_dir_entry =3D dir->dot_entries++ ? ".." : "."; + } else { + errno =3D 0; + host_dir_entry =3D g_dir_read_name(dir->dir); + if (host_dir_entry =3D=3D NULL) { + err =3D errno; + } + } + } else { + err =3D EBADF; + } + + if (host_dir_entry) { + uint32_t guest_dir_entry =3D env->gpr[HEX_REG_R02]; + /* GDir does not provide a portable inode number. */ + hexagon_write_memory(env, guest_dir_entry, 4, 0, retaddr); + name_len =3D MIN(strlen(host_dir_entry), 254); + for (i =3D 0; i <=3D name_len; i++) { + hexagon_write_memory(env, guest_dir_entry + 4 + i, 1, + host_dir_entry[i], retaddr); + } + rc =3D guest_dir_entry; + } + common_semi_cb(cs, rc, err); + break; + } + + case HEX_SYS_CLOSEDIR: + { + SemihostingDir *dir; + int ret =3D -1, err =3D 0; + int dir_index =3D swi_info - DIR_INDEX_OFFSET; + GList **dir_list =3D hex_semihosting_dir_list(env); + GList *node =3D g_list_nth(*dir_list, dir_index); + + dir =3D node ? node->data : NULL; + if (dir !=3D NULL) { + g_dir_close(dir->dir); + g_free(dir); + ret =3D 0; + node->data =3D NULL; + } else { + err =3D EBADF; + } + common_semi_cb(cs, ret, ret =3D=3D 0 ? 0 : err); + break; + } + case HEX_SYS_COREDUMP: coredump(env); break; diff --git a/tests/functional/hexagon/test_systests.py b/tests/functional/h= exagon/test_systests.py index 2779efa9172..a1080f7b974 100755 --- a/tests/functional/hexagon/test_systests.py +++ b/tests/functional/hexagon/test_systests.py @@ -7,6 +7,7 @@ import re import time import unittest +from pathlib import Path =20 from qemu_test import QemuSystemTest, Asset, wait_for_console_pattern =20 @@ -99,5 +100,15 @@ def test_mmu_multi_tlb(self): def test_timer_reg(self): self.run_exit_zero("timer_reg") =20 + def test_dirent(self): + testdir =3D Path(self.scratch_file("_testdir_dirent")) + testdir.mkdir() + files =3D ["file1", "file2"] + for f in files: + testdir.joinpath(f).touch() + expected =3D ". .. " + " ".join(files) + self.run_console_pattern("dirent", expected, "-append", + str(testdir)) + if __name__ =3D=3D "__main__": QemuSystemTest.main() --=20 2.34.1