From patchwork Tue Jun 16 14:15:32 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Michael Roth X-Patchwork-Id: 188045 Delivered-To: patch@linaro.org Received: by 2002:a92:cf06:0:0:0:0:0 with SMTP id c6csp3720774ilo; Tue, 16 Jun 2020 07:51:20 -0700 (PDT) X-Google-Smtp-Source: ABdhPJzgku/khq4KX1//ZarAixrDGtbkvbpKRsilzsf1h1ky++469BzKMUwu0aij6/CCeBPUCjqg X-Received: by 2002:a25:3bd8:: with SMTP id i207mr4639600yba.167.1592319080788; Tue, 16 Jun 2020 07:51:20 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1592319080; cv=none; d=google.com; s=arc-20160816; b=eoeTvKCdzfekKSY1QQZYIsNoApKOdwITOhNroKeslRmgte1MVYBw1gkxv4LSVer9CZ CWZ4uwRasTdqVu1Mq6os/c32Le1snosPU3+shh55u/xKEGV5oZ+okoiGhhYdIDkgDuvC Sd9iKxOdi9jgecQ5bL3rKjqPjQxMvNhtKzmEUZGTk6R/1BU4uOWM5g3IW4CC4mxINHiH LOoKk6+okkv05ehlfF4bdFB1Dy4rNJHUUFmfW44Nj3DzrkzuEbdFRzUu22T3yRlCnbrp 2709UUuWbttQKSrAqoqkj+AjpgkTi/MfTs95TNZ3FvyCJJJ1SOyyeMlbXCRYlyOBK5lr Kd2A== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:cc:list-subscribe:list-help:list-post:list-archive :list-unsubscribe:list-id:precedence:references:in-reply-to :message-id:date:subject:to:from:dkim-signature; bh=rOQwJDphmhaIdRqWIt/ysSZEwiemdpwpObYdcb/nTmA=; b=gvWJXykvjOpfhSoSlmfapZ/4iNpql5qrDE8JUPYOyb+0wqXwq343J7zf40DSpzfkKp 5Wwo/c05l6QvZMR+Xvot/UeuPFW2o/o4g2DXekdSjvXNw2MsclPNUOFD251xHVoh8y0J EFlpC68ijmDtxKl1Ct4GDAygfBMuNew4mYXTURBLdZArgyWtAYdAcyGS47dPy8OblM/4 SAk/GC4VT5pMXrnibhjyn9LVA2501fKnqj42djc+lRGkM6T+VJ0YBHp2aBNPKjJuQ+x/ k9tgAN5NIAGha0GFtLpmloGtldXz1KDgXPpn4GXUA3GjQJNhfgBU5VOvYxni3mYzNySs 2jxg== ARC-Authentication-Results: i=1; mx.google.com; dkim=fail header.i=@gmail.com header.s=20161025 header.b=stoZDnAF; spf=pass (google.com: domain of qemu-devel-bounces+patch=linaro.org@nongnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom="qemu-devel-bounces+patch=linaro.org@nongnu.org"; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=ibm.com Return-Path: Received: from lists.gnu.org (lists.gnu.org. [209.51.188.17]) by mx.google.com with ESMTPS id w1si23938544ybt.389.2020.06.16.07.51.20 for (version=TLS1_2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305 bits=256/256); Tue, 16 Jun 2020 07:51:20 -0700 (PDT) Received-SPF: pass (google.com: domain of qemu-devel-bounces+patch=linaro.org@nongnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; Authentication-Results: mx.google.com; dkim=fail header.i=@gmail.com header.s=20161025 header.b=stoZDnAF; spf=pass (google.com: domain of qemu-devel-bounces+patch=linaro.org@nongnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom="qemu-devel-bounces+patch=linaro.org@nongnu.org"; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=ibm.com Received: from localhost ([::1]:44300 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1jlCvo-0003WB-6W for patch@linaro.org; Tue, 16 Jun 2020 10:51:20 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:58222) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1jlCQr-0003vG-Va; Tue, 16 Jun 2020 10:19:22 -0400 Received: from mail-ot1-x343.google.com ([2607:f8b0:4864:20::343]:42866) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1jlCQq-00070V-Da; Tue, 16 Jun 2020 10:19:21 -0400 Received: by mail-ot1-x343.google.com with SMTP id t6so16023672otk.9; Tue, 16 Jun 2020 07:19:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id:in-reply-to:references; bh=rOQwJDphmhaIdRqWIt/ysSZEwiemdpwpObYdcb/nTmA=; b=stoZDnAFLyaVidRBFf2vh7DppTmcd++JgdNyKYUO4mPu1j4IF8owJSWXYIEHQHvvdb lo2jFmPP9F9VLVt+lO0+5W8zdRWFB74hiFXbzgQHPmJYG02BCzxxYjBD3B9nFL6rrrHk gNXNhW10ZRSGPzm0QFxFRzLIlQXqR73xqZhsP8lApUuGwFD9MjDeid5uzoseO8UztJe4 1C93sDQG5QMPB+Ve+jj2W8ny0/gyHz1mreBJ5Z/ZF7WuA+/lebHxi7vTqLhV/jNKNmq8 /zR6oVPewxB0V6+Dm5klaoY2RZwk2DHdCPsMyYPvRpNhA/aS+mbeUluIWDMAWkfOqA9F JLpQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :in-reply-to:references; bh=rOQwJDphmhaIdRqWIt/ysSZEwiemdpwpObYdcb/nTmA=; b=gVCnh06poEHutEU8H/1ytJeQ32300LsJtKwaSltNiEFeM7kyBdnOAfflWefALnWfsK RmJQim+8vJvAyx3J/+Eofi2cfWkgEBgymnj32X2ctaozD2USKJgOtJ6EC2t8UdbFYu9M 2po6fngdsPVW08c8pFRoYpLX/gNC062Ox7nRmVLR8yrYTKff6gxEeYBKe5A8y2dkYvjJ YH2zrR1Yffu8o3cQv/KOdXZqHmKbG8nZegFTyNxhPAdyYNf6jkSnGJLYs3pjjCpha55p NnAZ3IUc6y0L+uNi/bBq4R0wiZTXW3kiXf9q/qumMYPFW+6XD7enf8SlkOiPBOkBfspr e0Iw== X-Gm-Message-State: AOAM53047jDZPneaTxoLScTI2XQOm0tTWQAmiXAEOMYw10PWivQNDhzi vCctm1IbAJFafPwfDULWcYpmEdTj X-Received: by 2002:a9d:554d:: with SMTP id h13mr2342117oti.201.1592317157109; Tue, 16 Jun 2020 07:19:17 -0700 (PDT) Received: from localhost (76-251-165-188.lightspeed.austtx.sbcglobal.net. [76.251.165.188]) by smtp.gmail.com with ESMTPSA id c10sm4120781ooq.30.2020.06.16.07.19.15 (version=TLS1_2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305 bits=256/256); Tue, 16 Jun 2020 07:19:15 -0700 (PDT) From: Michael Roth To: qemu-devel@nongnu.org Subject: [PATCH 63/78] hw/i386/amd_iommu.c: Fix corruption of log events passed to guest Date: Tue, 16 Jun 2020 09:15:32 -0500 Message-Id: <20200616141547.24664-64-mdroth@linux.vnet.ibm.com> X-Mailer: git-send-email 2.17.1 In-Reply-To: <20200616141547.24664-1-mdroth@linux.vnet.ibm.com> References: <20200616141547.24664-1-mdroth@linux.vnet.ibm.com> Received-SPF: pass client-ip=2607:f8b0:4864:20::343; envelope-from=flukshun@gmail.com; helo=mail-ot1-x343.google.com X-detected-operating-system: by eggs.gnu.org: No matching host in p0f cache. That's all we know. X-Spam_score_int: 0 X-Spam_score: 0.0 X-Spam_bar: / X-Spam_report: (0.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FORGED_FROMDOMAIN=1, FREEMAIL_FROM=0.001, HEADER_FROM_DIFFERENT_DOMAINS=1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=_AUTOLEARN X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Peter Maydell , qemu-stable@nongnu.org, "Michael S . Tsirkin" Errors-To: qemu-devel-bounces+patch=linaro.org@nongnu.org Sender: "Qemu-devel" From: Peter Maydell In the function amdvi_log_event(), we write an event log buffer entry into guest ram, whose contents are passed to the function via the "uint64_t *evt" argument. Unfortunately, a spurious '&' in the call to dma_memory_write() meant that instead of writing the event to the guest we would write the literal value of the pointer, plus whatever was in the following 8 bytes on the stack. This error was spotted by Coverity. Fix the bug by removing the '&'. Fixes: CID 1421945 Cc: qemu-stable@nongnu.org Signed-off-by: Peter Maydell Message-Id: <20200326105349.24588-1-peter.maydell@linaro.org> Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin (cherry picked from commit 32a2d6b1f6b4405f0fc20c031e61d5d48e3d9cd1) Signed-off-by: Michael Roth --- hw/i386/amd_iommu.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) -- 2.17.1 diff --git a/hw/i386/amd_iommu.c b/hw/i386/amd_iommu.c index d55dbf07fc..ac5f2fddc5 100644 --- a/hw/i386/amd_iommu.c +++ b/hw/i386/amd_iommu.c @@ -181,7 +181,7 @@ static void amdvi_log_event(AMDVIState *s, uint64_t *evt) } if (dma_memory_write(&address_space_memory, s->evtlog + s->evtlog_tail, - &evt, AMDVI_EVENT_LEN)) { + evt, AMDVI_EVENT_LEN)) { trace_amdvi_evntlog_fail(s->evtlog, s->evtlog_tail); }