On Tue, Jun 30, 2026 at 10:30:20AM +0200, Eric Auger wrote:
> STRTAB_BASE_CFG.LOG2SIZE is programmed by the guest through the
> emulated SMMUv3 MMIO register interface. Currently the value is
> not checked.
> 
> The SMMU spec says: "Except for readback of a written value, the
> effective LOG2SIZE is <= SMMU_IDR1.SIDSIZE for the purposes of
> input StreamID range checking and upper/lower/linear Stream table
> index address calculation."
> 
> So for STE lookup make sure log2size is capped at SMMU_IDR1.SIDSIZE.
> 
> Signed-off-by: Eric Auger <[email protected]>
> ---
>  hw/arm/smmuv3.c | 9 +++++++++
>  1 file changed, 9 insertions(+)

Can you add the "Resolves: bug URL" to the commit message so it
gets auto-closed on merge.

> 
> diff --git a/hw/arm/smmuv3.c b/hw/arm/smmuv3.c
> index 0a8d2fbb6a7..db5aca26ec0 100644
> --- a/hw/arm/smmuv3.c
> +++ b/hw/arm/smmuv3.c
> @@ -672,6 +672,15 @@ int smmu_find_ste(SMMUv3State *s, uint32_t sid, STE 
> *ste, SMMUEventInfo *event)
>      /*
>       * Check SID range against both guest-configured and implementation 
> limits
>       */
> +    if (log2size > SMMU_IDR1_SIDSIZE) {
> +        /*
> +         * spec says: Except for readback of a written value, the effective
> +         * LOG2SIZE is <= SMMU_IDR1.SIDSIZE for the purposes of input 
> StreamID
> +         * range checking and upper/lower/linear Stream table index address
> +         * calculation.
> +         */
> +        log2size = SMMU_IDR1_SIDSIZE;
> +    }
>      if (sid >= (1 << MIN(log2size, SMMU_IDR1_SIDSIZE))) {
>          event->type = SMMU_EVT_C_BAD_STREAMID;
>          return -EINVAL;
> -- 
> 2.53.0
> 

With regards,
Daniel
-- 
|: https://berrange.com       ~~        https://hachyderm.io/@berrange :|
|: https://libvirt.org          ~~          https://entangle-photo.org :|
|: https://pixelfed.art/berrange   ~~    https://fstop138.berrange.com :|


Reply via email to