In allwinner_r40_ccu_write() we handle writes to a MemoryRegion of size AW_R40_CCU_IOSIZE, and the register array is sized accordingly at (AW_R40_CCU_IOSIZE / sizeof(uint32_t)). However, one of the cases in the switch is a range up to AW_R40_CCU_IOSIZE, which makes Coverity think we might index off the end of the array. We also have a similar case in the read function, but since that returns early it doesn't have the same issue.
Adjust the handling of out of range accesses: - use AW_R40_CCU_IOSIZE - 4 as the upper bound, as this is the largest value we will actually see - return early in the write case, as we do in the read case Coverity CID: 1663687 Signed-off-by: Peter Maydell <[email protected]> Reviewed-by: Philippe Mathieu-Daudé <[email protected]> Reviewed-by: Strahinja Jankovic <[email protected]> Message-id: [email protected] --- hw/misc/allwinner-r40-ccu.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/hw/misc/allwinner-r40-ccu.c b/hw/misc/allwinner-r40-ccu.c index 8ba4e7aa429..00840e98507 100644 --- a/hw/misc/allwinner-r40-ccu.c +++ b/hw/misc/allwinner-r40-ccu.c @@ -71,7 +71,7 @@ static uint64_t allwinner_r40_ccu_read(void *opaque, hwaddr offset, const uint32_t idx = REG_INDEX(offset); switch (offset) { - case 0x324 ... AW_R40_CCU_IOSIZE: + case 0x324 ... AW_R40_CCU_IOSIZE - 4: qemu_log_mask(LOG_GUEST_ERROR, "%s: out-of-bounds offset 0x%04x\n", __func__, (uint32_t)offset); return 0; @@ -113,10 +113,10 @@ static void allwinner_r40_ccu_write(void *opaque, hwaddr offset, val |= REG_PLL_LOCK; } break; - case 0x324 ... AW_R40_CCU_IOSIZE: + case 0x324 ... AW_R40_CCU_IOSIZE - 4: qemu_log_mask(LOG_GUEST_ERROR, "%s: out-of-bounds offset 0x%04x\n", __func__, (uint32_t)offset); - break; + return; default: qemu_log_mask(LOG_UNIMP, "%s: unimplemented write offset 0x%04x\n", __func__, (uint32_t)offset); -- 2.43.0
