From nobody Tue Apr 7 19:41:03 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=163.com ARC-Seal: i=1; a=rsa-sha256; t=1773320390; cv=none; d=zohomail.com; s=zohoarc; b=RbtORssOS3aWASCRJybGw4PwwsszWlZhp3IS3/9CuRCvBlCZIxTHZSFdYCKjN5wFmGyWhlYRXfSaC+MIC29lKtNZpQc6dKA5b7Oqik/ss2WooEDj5LrdaAqgAiUXiCfiCRpRfJ9FVqAeLDccigvKrCjb4UvmYQl7OC/M80J/Xls= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1773320390; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=eLLvSQHU8ehn2m+zChvE8FY6VFoeK0GfhtPDMCP2B5k=; b=FQh6bHepU8RxURvxpZslSnZQkVUq67M1vjQpGpBiE0EWWfF2D4/vPZJMrmLosNRClPbSgdUIW+jJwzsOE87GNf6In4eT3TEchjrLxCMdAK05PWfg3H23/xizj6u/XG0fMYWQ1OSTFdQWbDyAEjY69gF4K7B/LQwm9cC+drIzUpM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1773320390592425.4267030506427; Thu, 12 Mar 2026 05:59:50 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1w0fcu-0001XC-Cv; Thu, 12 Mar 2026 08:58:56 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1w0b0W-00048i-Lr; Thu, 12 Mar 2026 04:03:00 -0400 Received: from m16.mail.163.com ([117.135.210.3]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1w0b0T-00030A-9i; Thu, 12 Mar 2026 04:03:00 -0400 Received: from dt-VM.localdomain (unknown []) by gzga-smtp-mtada-g0-0 (Coremail) with SMTP id _____wBXHlMcc7JpkIIcAg--.55484S5; Thu, 12 Mar 2026 16:02:37 +0800 (CST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=163.com; s=s110527; h=From:To:Subject:Date:Message-ID:MIME-Version; bh=eL LvSQHU8ehn2m+zChvE8FY6VFoeK0GfhtPDMCP2B5k=; b=eJdSn0j7EVoA1lvxKv x86nafuApMyAtrgLki0JAQnlYya1yXem4PQYS3AxDt7Sy1vqjwzvkTXgyJxx5YKk zrxMIE/xq0pxUhYeptvAVFXmO3AooPwej2yiYL2NCErnKaO1Zp76XO31AhOIqUjo LGQt7yDz0WrvZcbWQUWzkcgEE= From: Tao Ding To: Peter Maydell , qemu-devel@nongnu.org Cc: qemu-arm@nongnu.org, Tao Ding Subject: [PATCH v1 3/3] The LLI of pl080 should be aligned with 4 bytes. Date: Thu, 12 Mar 2026 16:02:35 +0800 Message-ID: X-Mailer: git-send-email 2.43.0 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: _____wBXHlMcc7JpkIIcAg--.55484S5 X-Coremail-Antispam: 1Uf129KBjvJXoWxuF17XFyDKrykXw1UWF1rJFb_yoW5Xw15pF 9rJFsYgwsYkF15Z3W8XF10gr15XF4IyasI93y7Gr1qkrn5W343Kr1rCryxCrWjyrn7Ar4U tFyDJr4Fgrs8X3DanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDUYxBIdaVFxhVjvjDU0xZFpf9x07jcyCXUUUUU= X-Originating-IP: [175.152.130.74] X-CM-SenderInfo: pglqw3tdrqkjqq6rljoofrz/xtbC4R3qKWmycx3oXAAA3+ Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=117.135.210.3; envelope-from=dingtao0430@163.com; helo=m16.mail.163.com X-Spam_score_int: 0 X-Spam_score: -0.1 X-Spam_bar: / X-Spam_report: (-0.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.819, RCVD_IN_VALIDITY_SAFE_BLOCKED=0.903, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Thu, 12 Mar 2026 08:58:55 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @163.com) X-ZM-MESSAGEID: 1773320422252158500 Content-Type: text/plain; charset="utf-8" When the bit0 of the LLI register is configured as master 1,=20 it can cause incorrect data reading, and even lead to qemu crash. Constructed 1 LLI item. The initial LLI register points to the address of t= he LLI item. But the bit 0 of the LLI register is 1, which mean read from Master1 port. According to the description in the PL080 manual, the address for the next = LLI should be word aligned. Configuration ../configure --target-list=3Darm-softmmu --enable-debug Reproducer ./qemu-system-arm -M versatilepb -m 128M -nographic -S \ -device loader,addr=3D0x00002000,data=3D0x00000004,data-len=3D4 \ -device loader,addr=3D0x00002004,data=3D0x00001004,data-len=3D4 \ -device loader,addr=3D0x00002008,data=3D0x00000000,data-len=3D4 \ -device loader,addr=3D0x0000200c,data=3D0x9e4bf001,data-len=3D4 \ -device loader,addr=3D0x00000000,data=3D0x44332211,data-len=3D4 \ -device loader,addr=3D0x00000004,data=3D0x88776655,data-len=3D4 \ -device loader,addr=3D0x00001000,data=3D0x00000000,data-len=3D4 \ -device loader,addr=3D0x00001004,data=3D0x00000000,data-len=3D4 \ -device loader,addr=3D0x10130030,data=3D0x00000001,data-len=3D4 \ -device loader,addr=3D0x10130100,data=3D0x00000000,data-len=3D4 \ -device loader,addr=3D0x10130104,data=3D0x00001000,data-len=3D4 \ -device loader,addr=3D0x10130108,data=3D0x00002001,data-len=3D4 \ -device loader,addr=3D0x1013010C,data=3D0x1e4bf001,data-len=3D4 \ -device loader,addr=3D0x10130110,data=3D0x0000c001,data-len=3D4 =20 Qemu Crash. The result correctly after fixed (qemu) xp /1wx 0x00001000 00001000: 0x44332211 (qemu) xp /1wx 0x00001004 00001004: 0x88776655 Signed-off-by: Tao Ding Reviewed-by: Peter Maydell --- hw/dma/pl080.c | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/hw/dma/pl080.c b/hw/dma/pl080.c index 4f97943b28..4e24f6595a 100644 --- a/hw/dma/pl080.c +++ b/hw/dma/pl080.c @@ -102,6 +102,7 @@ static void pl080_run(PL080State *s) int size; uint8_t buff[4]; uint32_t req; + uint32_t next_lli; =20 s->tc_mask =3D 0; for (c =3D 0; c < s->nchannels; c++) { @@ -191,21 +192,22 @@ again: ch->ctrl =3D (ch->ctrl & 0xfffff000) | size; if (size =3D=3D 0) { /* Transfer complete. */ - if (ch->lli) { + next_lli =3D (ch->lli & ~3); + if (next_lli) { ch->src =3D address_space_ldl_le(&s->downstream_as, - ch->lli, + next_lli, MEMTXATTRS_UNSPECIFIED, NULL); ch->dest =3D address_space_ldl_le(&s->downstream_as, - ch->lli + 4, + next_lli + 4, MEMTXATTRS_UNSPECIFIED, NULL); ch->ctrl =3D address_space_ldl_le(&s->downstream_as, - ch->lli + 12, + next_lli + 12, MEMTXATTRS_UNSPECIFIED, NULL); ch->lli =3D address_space_ldl_le(&s->downstream_as, - ch->lli + 8, + next_lli + 8, MEMTXATTRS_UNSPECIFIED, NULL); } else { --=20 2.43.0