On Wed, 1 Jul 2026 at 10:12, Eric Auger <[email protected]> wrote:
>
> STRTAB_BASE_CFG.LOG2SIZE is programmed by the guest through the
> emulated SMMUv3 MMIO register interface. Currently the value is
> not checked and used directly in smmu_find_ste() for strtab_base
> alignment computation with risk that MAKE_64BIT_MASK() runs out
> of bounds. On FMT==1 the strtab_size cannot be greater than 64 after
> the SPLIT being at minimum 6 (log2size is max 64).
>
> However on FMT=0 path, strtab_size= log2size + 6 can potentially
> exceed 64. Let's abort in that case.
>
> Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3632
> Signed-off-by: Eric Auger <[email protected]>
> ---
>  hw/arm/smmuv3.c | 8 ++++++++
>  1 file changed, 8 insertions(+)
>
> diff --git a/hw/arm/smmuv3.c b/hw/arm/smmuv3.c
> index 285e6164a07..5ec3700d0d5 100644
> --- a/hw/arm/smmuv3.c
> +++ b/hw/arm/smmuv3.c
> @@ -1696,6 +1696,14 @@ static MemTxResult smmu_writel(SMMUv3State *s, hwaddr 
> offset,
>                  s->sid_split = 6;
>              }
>              s->features |= SMMU_FEATURE_2LVL_STE;
> +        } else {
> +            uint32_t log2size = FIELD_EX32(data, STRTAB_BASE_CFG, LOG2SIZE);
> +
> +            if (log2size + 6 > 64) {
> +                qemu_log_mask(LOG_GUEST_ERROR,
> +                              "Invalid STRTAB_BASE_CFG.LOG2SIZE: %d", 
> log2size);
> +                g_assert_not_reached();

This doesn't look right. Either:
 (a) the guest can do something silly that gets us to this code path:
     in that case we mustn't assert, but must continue (doing whatever
     the spec permits and that is reasonably straightforward to implement)
 (b) we can't actually get here in practice: in that case the logging
     isn't needed and we could just assert(log2size + 6 <= 64);

It sounds like we're in case (a) here.

thanks
-- PMM

Reply via email to