Skip to content
  • Philippe Mathieu-Daudé's avatar
    bb15013e
    hw/misc/grlib_ahb_apb_pnp: Avoid crash when writing to AHB PnP registers · bb15013e
    Philippe Mathieu-Daudé authored
    
    
    Similarly to commit 158b6594 with the APB PnP registers, guests
    can crash QEMU when writting to the AHB PnP registers:
    
      $ echo 'writeb 0xfffff042 69' | qemu-system-sparc -M leon3_generic -S -bios /etc/magic -qtest stdio
      [I 1571938309.932255] OPENED
      [R +0.063474] writeb 0xfffff042 69
      Segmentation fault (core dumped)
    
      (gdb) bt
      #0  0x0000000000000000 in  ()
      #1  0x0000562999110df4 in memory_region_write_with_attrs_accessor
          (mr=mr@entry=0x56299aa28ea0, addr=66, value=value@entry=0x7fff6abe13b8, size=size@entry=1, shift=<optimized out>, mask=mask@entry=255, attrs=...) at memory.c:503
      #2  0x000056299911095e in access_with_adjusted_size
          (addr=addr@entry=66, value=value@entry=0x7fff6abe13b8, size=size@entry=1, access_size_min=<optimized out>, access_size_max=<optimized out>, access_fn=access_fn@entry=
          0x562999110d70 <memory_region_write_with_attrs_accessor>, mr=0x56299aa28ea0, attrs=...) at memory.c:539
      #3  0x0000562999114fba in memory_region_dispatch_write (mr=mr@entry=0x56299aa28ea0, addr=66, data=<optimized out>, op=<optimized out>, attrs=attrs@entry=...) at memory.c:1482
      #4  0x00005629990c0860 in flatview_write_continue
          (fv=fv@entry=0x56299aa7d8a0, addr=addr@entry=4294963266, attrs=..., ptr=ptr@entry=0x7fff6abe1540, len=len@entry=1, addr1=<optimized out>, l=<optimized out>, mr=0x56299aa28ea0)
          at include/qemu/host-utils.h:164
      #5  0x00005629990c0a76 in flatview_write (fv=0x56299aa7d8a0, addr=4294963266, attrs=..., buf=0x7fff6abe1540, len=1) at exec.c:3165
      #6  0x00005629990c4c1b in address_space_write (as=<optimized out>, addr=<optimized out>, attrs=..., attrs@entry=..., buf=buf@entry=0x7fff6abe1540, len=len@entry=1) at exec.c:3256
      #7  0x000056299910f807 in qtest_process_command (chr=chr@entry=0x5629995ee920 <qtest_chr>, words=words@entry=0x56299acfcfa0) at qtest.c:437
    
    Instead of crashing, log the access as unimplemented.
    
    Signed-off-by: default avatarPhilippe Mathieu-Daudé <f4bug@amsat.org>
    Reviewed-by: default avatarKONRAD Frederic <frederic.konrad@adacore.com>
    Message-Id: <20200331105048.27989-3-f4bug@amsat.org>
    bb15013e
    hw/misc/grlib_ahb_apb_pnp: Avoid crash when writing to AHB PnP registers
    Philippe Mathieu-Daudé authored
    
    
    Similarly to commit 158b6594 with the APB PnP registers, guests
    can crash QEMU when writting to the AHB PnP registers:
    
      $ echo 'writeb 0xfffff042 69' | qemu-system-sparc -M leon3_generic -S -bios /etc/magic -qtest stdio
      [I 1571938309.932255] OPENED
      [R +0.063474] writeb 0xfffff042 69
      Segmentation fault (core dumped)
    
      (gdb) bt
      #0  0x0000000000000000 in  ()
      #1  0x0000562999110df4 in memory_region_write_with_attrs_accessor
          (mr=mr@entry=0x56299aa28ea0, addr=66, value=value@entry=0x7fff6abe13b8, size=size@entry=1, shift=<optimized out>, mask=mask@entry=255, attrs=...) at memory.c:503
      #2  0x000056299911095e in access_with_adjusted_size
          (addr=addr@entry=66, value=value@entry=0x7fff6abe13b8, size=size@entry=1, access_size_min=<optimized out>, access_size_max=<optimized out>, access_fn=access_fn@entry=
          0x562999110d70 <memory_region_write_with_attrs_accessor>, mr=0x56299aa28ea0, attrs=...) at memory.c:539
      #3  0x0000562999114fba in memory_region_dispatch_write (mr=mr@entry=0x56299aa28ea0, addr=66, data=<optimized out>, op=<optimized out>, attrs=attrs@entry=...) at memory.c:1482
      #4  0x00005629990c0860 in flatview_write_continue
          (fv=fv@entry=0x56299aa7d8a0, addr=addr@entry=4294963266, attrs=..., ptr=ptr@entry=0x7fff6abe1540, len=len@entry=1, addr1=<optimized out>, l=<optimized out>, mr=0x56299aa28ea0)
          at include/qemu/host-utils.h:164
      #5  0x00005629990c0a76 in flatview_write (fv=0x56299aa7d8a0, addr=4294963266, attrs=..., buf=0x7fff6abe1540, len=1) at exec.c:3165
      #6  0x00005629990c4c1b in address_space_write (as=<optimized out>, addr=<optimized out>, attrs=..., attrs@entry=..., buf=buf@entry=0x7fff6abe1540, len=len@entry=1) at exec.c:3256
      #7  0x000056299910f807 in qtest_process_command (chr=chr@entry=0x5629995ee920 <qtest_chr>, words=words@entry=0x56299acfcfa0) at qtest.c:437
    
    Instead of crashing, log the access as unimplemented.
    
    Signed-off-by: default avatarPhilippe Mathieu-Daudé <f4bug@amsat.org>
    Reviewed-by: default avatarKONRAD Frederic <frederic.konrad@adacore.com>
    Message-Id: <20200331105048.27989-3-f4bug@amsat.org>
Loading