Re: [PATCH-for-11.1 v3 48/51] target/arm: Be more defensive for invalid tlbi_aa64_get_range

Philippe Mathieu-Daudé <[email protected]>
Newsgroups org.nongnu.qemu-riscv,org.nongnu.qemu-arm,org.nongnu.qemu-devel
Message-ID <[email protected]>
On 10/7/26 22:53, Richard Henderson wrote:
> It's possible to program TCR_ELx with an invalid granule size,
> which could match passing an invalid granule size to TLBI RVA,
> which would then fall through to assert in arm_granule_bits.
> 
> Cc: [email protected]
> Fixes: 3c003f7029e ("target/arm: Use ARMGranuleSize in ARMVAParameters")
> Signed-off-by: Richard Henderson <[email protected]>
> ---
>   target/arm/tcg/tlb-insns.c | 2 +-
>   1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/target/arm/tcg/tlb-insns.c b/target/arm/tcg/tlb-insns.c
> index 1a0a332583..b24eb57788 100644
> --- a/target/arm/tcg/tlb-insns.c
> +++ b/target/arm/tcg/tlb-insns.c
> @@ -854,7 +854,7 @@ static TLBIRange tlbi_aa64_get_range(CPUARMState *env, ARMMMUIdx mmuidx,
>       gran = tlbi_range_tg_to_gran_size(page_size_granule);
>   
>       /* The granule encoded in value must match the granule in use. */
> -    if (gran != param.gran) {
> +    if (gran != param.gran || gran == GranInvalid) {
>           qemu_log_mask(LOG_GUEST_ERROR, "Invalid tlbi page size granule %d\n",
>                         page_size_granule);
>           return ret;

Reviewed-by: Philippe Mathieu-Daudé <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.