On 6/30/26 11:18 AM, Daniel P. Berrangé wrote:
> On Tue, Jun 30, 2026 at 10:30:20AM +0200, Eric Auger wrote:
>> STRTAB_BASE_CFG.LOG2SIZE is programmed by the guest through the
>> emulated SMMUv3 MMIO register interface. Currently the value is
>> not checked.
>>
>> The SMMU spec says: "Except for readback of a written value, the
>> effective LOG2SIZE is <= SMMU_IDR1.SIDSIZE for the purposes of
>> input StreamID range checking and upper/lower/linear Stream table
>> index address calculation."
>>
>> So for STE lookup make sure log2size is capped at SMMU_IDR1.SIDSIZE.
>>
>> Signed-off-by: Eric Auger <[email protected]>
>> ---
>> hw/arm/smmuv3.c | 9 +++++++++
>> 1 file changed, 9 insertions(+)
> Can you add the "Resolves: bug URL" to the commit message so it
> gets auto-closed on merge.
sure. Thanks for the hint
Eric
>
>> diff --git a/hw/arm/smmuv3.c b/hw/arm/smmuv3.c
>> index 0a8d2fbb6a7..db5aca26ec0 100644
>> --- a/hw/arm/smmuv3.c
>> +++ b/hw/arm/smmuv3.c
>> @@ -672,6 +672,15 @@ int smmu_find_ste(SMMUv3State *s, uint32_t sid, STE
>> *ste, SMMUEventInfo *event)
>> /*
>> * Check SID range against both guest-configured and implementation
>> limits
>> */
>> + if (log2size > SMMU_IDR1_SIDSIZE) {
>> + /*
>> + * spec says: Except for readback of a written value, the effective
>> + * LOG2SIZE is <= SMMU_IDR1.SIDSIZE for the purposes of input
>> StreamID
>> + * range checking and upper/lower/linear Stream table index address
>> + * calculation.
>> + */
>> + log2size = SMMU_IDR1_SIDSIZE;
>> + }
>> if (sid >= (1 << MIN(log2size, SMMU_IDR1_SIDSIZE))) {
>> event->type = SMMU_EVT_C_BAD_STREAMID;
>> return -EINVAL;
>> --
>> 2.53.0
>>
> With regards,
> Daniel