The current code fails to sanitize SMMU_S_STRTAB_BASE_CFG LOG2SIZE and SPLIT which are used in the STE lookup. This could potentially lead to wrong shifts/masks in smmu_find_ste() and does not fully comply with the spec.
Also the series fixes different issues related to strtab base address alignment computations: off-by-one mask, unchecked span, missing L2ptr base address alignment. Those issues were not visible because the guest kernel does what it should but better comply with the spec. Best Regards Eric Eric Auger (5): hw/arm/smmuv3: Fix off-by-one bug in alignment strtab mask hw/arm/smmuv3: Sanitize SMMU_S_STRTAB_BASE_CFG.SPLIT hw/arm/smmuv3: Sanitize SMMU_S_STRTAB_BASE_CFG.LOG2SIZE hw/arm/smmuv3: Check L1STD.SPAN hw/arm/smmuv3: Enforce alignment of L2Ptr according to the span hw/arm/smmuv3.c | 39 +++++++++++++++++++++++++++++++++------ 1 file changed, 33 insertions(+), 6 deletions(-) -- 2.53.0
