[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[PULL 1/6] target/i386: fix direction of "32-bit MMU" test
From: |
Paolo Bonzini |
Subject: |
[PULL 1/6] target/i386: fix direction of "32-bit MMU" test |
Date: |
Wed, 20 Mar 2024 11:32:08 +0100 |
The low bit of MMU indices for x86 TCG indicates whether the processor is
in 32-bit mode and therefore linear addresses have to be masked to 32 bits.
However, the index was computed incorrectly, leading to possible conflicts
in the TLB for any address above 4G.
Analyzed-by: Mark Cave-Ayland <mark.cave-ayland@ilande.co.uk>
Fixes: b1661801c18 ("target/i386: Fix physical address truncation", 2024-02-28)
Cc: qemu-stable@nongnu.org
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/2206
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
---
target/i386/cpu.h | 2 +-
target/i386/cpu.c | 2 +-
2 files changed, 2 insertions(+), 2 deletions(-)
diff --git a/target/i386/cpu.h b/target/i386/cpu.h
index 952174bb6f5..6b057380791 100644
--- a/target/i386/cpu.h
+++ b/target/i386/cpu.h
@@ -2334,7 +2334,7 @@ static inline bool is_mmu_index_32(int mmu_index)
static inline int cpu_mmu_index_kernel(CPUX86State *env)
{
- int mmu_index_32 = (env->hflags & HF_LMA_MASK) ? 1 : 0;
+ int mmu_index_32 = (env->hflags & HF_LMA_MASK) ? 0 : 1;
int mmu_index_base =
!(env->hflags & HF_SMAP_MASK) ? MMU_KNOSMAP64_IDX :
((env->hflags & HF_CPL_MASK) < 3 && (env->eflags & AC_MASK)) ?
MMU_KNOSMAP64_IDX : MMU_KSMAP64_IDX;
diff --git a/target/i386/cpu.c b/target/i386/cpu.c
index 9a210d8d929..33760a2ee16 100644
--- a/target/i386/cpu.c
+++ b/target/i386/cpu.c
@@ -7735,7 +7735,7 @@ static bool x86_cpu_has_work(CPUState *cs)
static int x86_cpu_mmu_index(CPUState *cs, bool ifetch)
{
CPUX86State *env = cpu_env(cs);
- int mmu_index_32 = (env->hflags & HF_CS64_MASK) ? 1 : 0;
+ int mmu_index_32 = (env->hflags & HF_CS64_MASK) ? 0 : 1;
int mmu_index_base =
(env->hflags & HF_CPL_MASK) == 3 ? MMU_USER64_IDX :
!(env->hflags & HF_SMAP_MASK) ? MMU_KNOSMAP64_IDX :
--
2.44.0
- [PULL 0/6] QEMU bug fixes for 20240320, Paolo Bonzini, 2024/03/20
- [PULL 1/6] target/i386: fix direction of "32-bit MMU" test,
Paolo Bonzini <=
- [PULL 4/6] target/i386: Revert monitor_puts() in do_inject_x86_mce(), Paolo Bonzini, 2024/03/20
- [PULL 5/6] tests/plugins: fix use-after-free bug, Paolo Bonzini, 2024/03/20
- [PULL 3/6] vl: do not assert if sev-guest is used together with TCG, Paolo Bonzini, 2024/03/20
- [PULL 6/6] meson: remove dead dictionary access, Paolo Bonzini, 2024/03/20
- [PULL 2/6] vl: convert qemu_machine_creation_done() to Error **, Paolo Bonzini, 2024/03/20
- Re: [PULL 0/6] QEMU bug fixes for 20240320, Peter Maydell, 2024/03/20