[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [PATCH v2 13/13] hw/intc/arm_gicv3_its: Range-check ICID before inde
From: |
Alex Bennée |
Subject: |
Re: [PATCH v2 13/13] hw/intc/arm_gicv3_its: Range-check ICID before indexing into collection table |
Date: |
Tue, 18 Jan 2022 17:37:13 +0000 |
User-agent: |
mu4e 1.7.5; emacs 28.0.91 |
Peter Maydell <peter.maydell@linaro.org> writes:
> In process_its_cmd(), we read an ICID out of the interrupt table
> entry, and then use it as an index into the collection table. Add a
> check that it is within range for the collection table first.
>
> This check is not strictly necessary, because:
> * we range check the ICID from the guest before writing it into
> the interrupt table entry, so the the only way to get an
> out of range ICID in process_its_cmd() is if a badly-behaved
> guest is writing directly to the interrupt table memory
> * the collection table is in guest memory, so QEMU won't fall
> over if we read off the end of it
>
> However, it seems clearer to include the check.
>
> Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Alex Bennée <alex.bennee@linaro.org>
--
Alex Bennée
- Re: [PATCH v2 01/13] hw/intc/arm_gicv3_its: Fix event ID bounds checks, (continued)
- [PATCH v2 03/13] hw/intc/arm_gicv3_its: Fix handling of process_its_cmd() return value, Peter Maydell, 2022/01/11
- [PATCH v2 05/13] hw/intc/arm_gicv3_its: Use enum for return value of process_* functions, Peter Maydell, 2022/01/11
- [PATCH v2 07/13] hw/intc/arm_gicv3_its: Refactor process_its_cmd() to reduce nesting, Peter Maydell, 2022/01/11
- [PATCH v2 10/13] hw/intc/arm_gicv3_its: Fix return codes in process_mapd(), Peter Maydell, 2022/01/11
- [PATCH v2 09/13] hw/intc/arm_gicv3_its: Fix return codes in process_mapc(), Peter Maydell, 2022/01/11
- [PATCH v2 11/13] hw/intc/arm_gicv3_its: Factor out "find address of table entry" code, Peter Maydell, 2022/01/11
- [PATCH v2 13/13] hw/intc/arm_gicv3_its: Range-check ICID before indexing into collection table, Peter Maydell, 2022/01/11
- [PATCH v2 12/13] hw/intc/arm_gicv3_its: Check indexes before use, not after, Peter Maydell, 2022/01/11
- Re: [PATCH v2 00/13] arm gicv3 ITS: Various bug fixes and refactorings, Alex Bennée, 2022/01/18