Hi Clement,

>-----Original Message-----
>From: Clément MATHIEU--DRIF <[email protected]>
>Subject: [PATCH] intel_iommu: Check address mask before using it in pasid-based
>iotlb invalidation
>
>Prevent a buggy driver to execute malformed invalidation operations.
>
>Add the same assert as in vtd_iotlb_page_invalidate.
>
>Link: https://gitlab.com/qemu-project/qemu/-/work_items/3619
>Fixes: 6ebe6cf2a066 ("intel_iommu: Process PASID-based iotlb invalidation")
>Signed-off-by: Clement Mathieu--Drif <[email protected]>

Reviewed-by: Zhenzhong Duan <[email protected]>

Thanks
Zhenzhong

>---
> hw/i386/intel_iommu.c | 9 +++++++++
> 1 file changed, 9 insertions(+)
>
>diff --git a/hw/i386/intel_iommu.c b/hw/i386/intel_iommu.c
>index bf4f0f2f6b..c591d1db3f 100644
>--- a/hw/i386/intel_iommu.c
>+++ b/hw/i386/intel_iommu.c
>@@ -3021,6 +3021,8 @@ static void
>vtd_piotlb_page_invalidate(IntelIOMMUState *s, uint16_t domain_id,
> {
>     VTDIOTLBPageInvInfo info;
>
>+    assert(am <= VTD_MAMV);
>+
>     info.domain_id = domain_id;
>     info.pasid = pasid;
>     info.addr = addr;
>@@ -3060,6 +3062,13 @@ static bool vtd_process_piotlb_desc(IntelIOMMUState
>*s,
>
>     case VTD_INV_DESC_PIOTLB_PSI_IN_PASID:
>         am = VTD_INV_DESC_PIOTLB_AM(inv_desc->val[1]);
>+        if (am > VTD_MAMV) {
>+            error_report_once("%s: invalid piotlb inv desc: hi=0x%"PRIx64
>+                              ", lo=0x%"PRIx64" (am=%u > VTD_MAMV=%u)",
>+                              __func__, inv_desc->val[1], inv_desc->val[0],
>+                              am, (unsigned)VTD_MAMV);
>+            return false;
>+        }
>         addr = (hwaddr) VTD_INV_DESC_PIOTLB_ADDR(inv_desc->val[1]);
>         vtd_piotlb_page_invalidate(s, domain_id, pasid, addr, am,
>                                    VTD_INV_DESC_PIOTLB_IH(inv_desc));
>--
>2.54.0

Reply via email to