Hi Clement, >-----Original Message----- >From: Clément MATHIEU--DRIF <[email protected]> >Subject: [PATCH] intel_iommu: Check address mask before using it in pasid-based >iotlb invalidation > >Prevent a buggy driver to execute malformed invalidation operations. > >Add the same assert as in vtd_iotlb_page_invalidate. > >Link: https://gitlab.com/qemu-project/qemu/-/work_items/3619 >Fixes: 6ebe6cf2a066 ("intel_iommu: Process PASID-based iotlb invalidation") >Signed-off-by: Clement Mathieu--Drif <[email protected]>
Reviewed-by: Zhenzhong Duan <[email protected]> Thanks Zhenzhong >--- > hw/i386/intel_iommu.c | 9 +++++++++ > 1 file changed, 9 insertions(+) > >diff --git a/hw/i386/intel_iommu.c b/hw/i386/intel_iommu.c >index bf4f0f2f6b..c591d1db3f 100644 >--- a/hw/i386/intel_iommu.c >+++ b/hw/i386/intel_iommu.c >@@ -3021,6 +3021,8 @@ static void >vtd_piotlb_page_invalidate(IntelIOMMUState *s, uint16_t domain_id, > { > VTDIOTLBPageInvInfo info; > >+ assert(am <= VTD_MAMV); >+ > info.domain_id = domain_id; > info.pasid = pasid; > info.addr = addr; >@@ -3060,6 +3062,13 @@ static bool vtd_process_piotlb_desc(IntelIOMMUState >*s, > > case VTD_INV_DESC_PIOTLB_PSI_IN_PASID: > am = VTD_INV_DESC_PIOTLB_AM(inv_desc->val[1]); >+ if (am > VTD_MAMV) { >+ error_report_once("%s: invalid piotlb inv desc: hi=0x%"PRIx64 >+ ", lo=0x%"PRIx64" (am=%u > VTD_MAMV=%u)", >+ __func__, inv_desc->val[1], inv_desc->val[0], >+ am, (unsigned)VTD_MAMV); >+ return false; >+ } > addr = (hwaddr) VTD_INV_DESC_PIOTLB_ADDR(inv_desc->val[1]); > vtd_piotlb_page_invalidate(s, domain_id, pasid, addr, am, > VTD_INV_DESC_PIOTLB_IH(inv_desc)); >-- >2.54.0
