On Sun, 6 Sept 2026 at 23:25, Brian Cain <[email protected]> wrote:
>
> HEX_SYS_OPEN copied guest bytes into a fixed-size buffer until it found a NUL.
> A missing terminator could overrun that buffer, so use lock_user_string()
> instead.
Do you have a link to the specification for these hexagon semihosting
calls? Looking at this patch I'm wondering if maybe I steered you
a bit wrong with suggesting lock_user_string():
> @@ -461,31 +462,14 @@ static void sim_handle_trap0(CPUHexagonState *env)
>
> case HEX_SYS_OPEN:
> {
> - char filename[BUFSIZ];
> + char *filename;
> target_ulong physical_filename_addr;
> unsigned int filemode;
> - int length;
> int real_openmode;
> int ret, err = 0;
> - int i = 0;
>
> hexagon_read_memory(env, swi_info, 4, &physical_filename_addr,
> retaddr);
> hexagon_read_memory(env, swi_info + 4, 4, &filemode, retaddr);
> - hexagon_read_memory(env, swi_info + 8, 4, &length, retaddr);
We no longer do anything with the length argument, which seems
like it might not be right.
If we know the (max) length of the string, then perhaps
lock_user() (which takes a length argument) would fit better.
thanks
-- PMM