From: Mostafa Saleh Date: Mon, 15 Jul 2024 08:45:01 +0000 (+0000) Subject: hw/arm/smmu-common: Add missing size check for stage-1 X-Git-Tag: pull-vmclock-20250108~239^2~22 X-Git-Url: https://www.infradead.org/git/?a=commitdiff_plain;h=bde809f05f66b4be4475ffa9819d82a01686d1c7;p=users%2Fdwmw2%2Fqemu.git hw/arm/smmu-common: Add missing size check for stage-1 According to the SMMU architecture specification (ARM IHI 0070 F.b), in “3.4 Address sizes” The address output from the translation causes a stage 1 Address Size fault if it exceeds the range of the effective IPA size for the given CD. However, this check was missing. There is already a similar check for stage-2 against effective PA. Reviewed-by: Jean-Philippe Brucker Reviewed-by: Eric Auger Signed-off-by: Mostafa Saleh Message-id: 20240715084519.1189624-2-smostafa@google.com Signed-off-by: Peter Maydell --- diff --git a/hw/arm/smmu-common.c b/hw/arm/smmu-common.c index b6601cc102..e81b684d06 100644 --- a/hw/arm/smmu-common.c +++ b/hw/arm/smmu-common.c @@ -381,6 +381,16 @@ static int smmu_ptw_64_s1(SMMUTransCfg *cfg, goto error; } + /* + * The address output from the translation causes a stage 1 Address + * Size fault if it exceeds the range of the effective IPA size for + * the given CD. + */ + if (gpa >= (1ULL << cfg->oas)) { + info->type = SMMU_PTW_ERR_ADDR_SIZE; + goto error; + } + tlbe->entry.translated_addr = gpa; tlbe->entry.iova = iova & ~mask; tlbe->entry.addr_mask = mask;