From patchwork Fri Jan 19 19:46:48 2018 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Ard Biesheuvel X-Patchwork-Id: 125223 Delivered-To: patch@linaro.org Received: by 10.46.66.141 with SMTP id h13csp444628ljf; Fri, 19 Jan 2018 11:49:05 -0800 (PST) X-Google-Smtp-Source: ACJfBosNYW7Y0OfZlfJGuVk2PbFDXaNQL+vIsvPhs+dqBFh5WActUPrIpBbA2FZvqym+Jt7dUxye X-Received: by 10.37.214.76 with SMTP id n73mr26628730ybg.319.1516391345464; Fri, 19 Jan 2018 11:49:05 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1516391345; cv=none; d=google.com; s=arc-20160816; b=R35I1byQWF3MRzZo6YyavyHVM3SZDRgfKDm4Ucg6masKSp2u5hchQzoUS2FA2mQZGs EsrbwajvPvf3PU+3LXM46R16HrmMgDrca6W68WraWbtjbkssZrTM9c7En5b+cSfwbRsW oB5P0QV0BQBiJIUAfhNh/z67aDqQm6+ndHZU79yi0tM7h6nabBWX9eDn9h16Sw1r3t9m pF0E+u3xNj8NGYn5C6FGviofe4rz1ANwtOnldkWulqgp4bx975nKTUxU3LoGwK9NOk/1 EoH2GduVIjqey4Hks2cBI0SXWSIQdhTNo6GSohFhXjIbMRU+vzCeHqbqv0XaPhCDGP+2 nnhA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:cc:list-subscribe:list-help:list-post:list-archive :list-unsubscribe:list-id:precedence:subject:message-id:date:to:from :dkim-signature:arc-authentication-results; bh=spmiuQiVwIIVZQMmZ2yW7UqCGF/PnY1JzYNoJ3f10VM=; b=jiSmGA7jRSTQHwzFrE4v6occEvMfwXTHZtJfHvEbW9Moy8AN6/7QtTx7XkeSyR0niE m3KlyMVpRiTt+ylJV+2mbUvE3etvi6fq8P0p9INA4C3RiS1I2diDsML8C2Rwgiima75o Dy46Vr6ZDsO0T1zcUAqLBdPYBvESdMwd33H9YVBAYEA/3JAwkSDDUYRdsF+ZP4CBwnsn +M7RVqhXQhYeKYHVQcqWpUQM9M+bQY4en3rjX/fUUsFWMtpur/COG/F73G18U8Axw2zg LAkOfayX9VO+n7QnsW5P062Sl1F50juB59ofvyNUOufOuehnEhFFhG2DTRIo2v1cy1yN flKw== ARC-Authentication-Results: i=1; mx.google.com; dkim=fail header.i=@linaro.org header.s=google header.b=XIr5bTli; spf=pass (google.com: domain of qemu-devel-bounces+patch=linaro.org@nongnu.org designates 2001:4830:134:3::11 as permitted sender) smtp.mailfrom=qemu-devel-bounces+patch=linaro.org@nongnu.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=linaro.org Return-Path: Received: from lists.gnu.org (lists.gnu.org. [2001:4830:134:3::11]) by mx.google.com with ESMTPS id s84si2356715yws.800.2018.01.19.11.49.05 for (version=TLS1 cipher=AES128-SHA bits=128/128); Fri, 19 Jan 2018 11:49:05 -0800 (PST) Received-SPF: pass (google.com: domain of qemu-devel-bounces+patch=linaro.org@nongnu.org designates 2001:4830:134:3::11 as permitted sender) client-ip=2001:4830:134:3::11; Authentication-Results: mx.google.com; dkim=fail header.i=@linaro.org header.s=google header.b=XIr5bTli; spf=pass (google.com: domain of qemu-devel-bounces+patch=linaro.org@nongnu.org designates 2001:4830:134:3::11 as permitted sender) smtp.mailfrom=qemu-devel-bounces+patch=linaro.org@nongnu.org; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=linaro.org Received: from localhost ([::1]:40889 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1eccev-0002Z7-1r for patch@linaro.org; Fri, 19 Jan 2018 14:49:05 -0500 Received: from eggs.gnu.org ([2001:4830:134:3::10]:57578) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1ecccz-0001mv-Lj for qemu-devel@nongnu.org; Fri, 19 Jan 2018 14:47:06 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1ecccw-0000OT-Fa for qemu-devel@nongnu.org; Fri, 19 Jan 2018 14:47:05 -0500 Received: from mail-wm0-x243.google.com ([2a00:1450:400c:c09::243]:41072) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1ecccw-0000O4-93 for qemu-devel@nongnu.org; Fri, 19 Jan 2018 14:47:02 -0500 Received: by mail-wm0-x243.google.com with SMTP id f71so5510799wmf.0 for ; Fri, 19 Jan 2018 11:47:02 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; h=from:to:cc:subject:date:message-id; bh=spmiuQiVwIIVZQMmZ2yW7UqCGF/PnY1JzYNoJ3f10VM=; b=XIr5bTliCDC5gIJtTZ49BSaJ1uxSJyJa6W6XAlGADijdsmclMItTmy/PKp11lNS003 kfwwLtp4oDW/POpMCCqPHC1xO/VwcCB1MLN3ogav3Xg6wLdl4szSI48eYdR7NbapurUo D06B8XsMWJl3cEKYHn29tXnTfUV5hD84ycA7U= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id; bh=spmiuQiVwIIVZQMmZ2yW7UqCGF/PnY1JzYNoJ3f10VM=; b=c8vPY/uKHseoQg8Cx4NVKU4pqmDp1VlvmkkrUc2Rrm3GB7BvQBjFXexefl2tP3GcCb mFtUEqe/OmGHlF9P9bEh4rUnlj3iwhy9sqfSPgy46dag5n1jguUl/TDyfb6MAzoSDTUE RDK38Z++4y2k7+/JCcSwPbe8Fkpvu9pRUCaqcEk1Lu4h8eYMLouNBZj2bz3zqdfq7MvV lnrpWzwNcaTCfhxM6kyjdFITLGIxNaDoXdtEoMaCEdsKw3ypRqI7cZjrvaj5D8aAyAJR H0u6uztd8Ajv0ZlRHq8xJxdKYBBj8r3wupmQgdFOP9XxoLnfI/8+p1e6k9RXcbgTG+7T DM9w== X-Gm-Message-State: AKwxytdbrpj2bzBNxiW84PWPXvBNX52/Gn3sz2osTElMEiVpfq85xPBM VbHtPL6IsgdokUQBH37KmtG8B4MyefM= X-Received: by 10.28.15.131 with SMTP id 125mr33482wmp.24.1516391220800; Fri, 19 Jan 2018 11:47:00 -0800 (PST) Received: from localhost.localdomain ([160.170.62.40]) by smtp.gmail.com with ESMTPSA id 44sm4615608wrt.46.2018.01.19.11.46.58 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Fri, 19 Jan 2018 11:46:59 -0800 (PST) From: Ard Biesheuvel To: qemu-devel@nongnu.org Date: Fri, 19 Jan 2018 19:46:48 +0000 Message-Id: <20180119194648.25501-1-ard.biesheuvel@linaro.org> X-Mailer: git-send-email 2.11.0 X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 2a00:1450:400c:c09::243 Subject: [Qemu-devel] [PATCH] target/arm: Fix 32-bit address truncation X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: peter.maydell@linaro.org, Ard Biesheuvel , rth@twiddle.net Errors-To: qemu-devel-bounces+patch=linaro.org@nongnu.org Sender: "Qemu-devel" Commit ("3b39d734141a target/arm: Handle page table walk load failures correctly") modified both versions of the page table walking code (i.e., arm_ldl_ptw and arm_ldq_ptw) to record the result of the translation in a temporary 'data' variable so that it can be inspected before being returned. However, arm_ldq_ptw() returns an uint64_t, and using a temporary uint32_t variable truncates the upper bits, corrupting the result. This causes problems when using more than 4 GB of memory in a TCG guest. So use a uint64_t instead. Signed-off-by: Ard Biesheuvel --- target/arm/helper.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) -- 2.11.0 diff --git a/target/arm/helper.c b/target/arm/helper.c index 67059033019c..a41b6c3a1b82 100644 --- a/target/arm/helper.c +++ b/target/arm/helper.c @@ -8368,7 +8368,7 @@ static uint64_t arm_ldq_ptw(CPUState *cs, hwaddr addr, bool is_secure, MemTxAttrs attrs = {}; MemTxResult result = MEMTX_OK; AddressSpace *as; - uint32_t data; + uint64_t data; attrs.secure = is_secure; as = arm_addressspace(cs, attrs);