Skip to content

Commit 5dbb1f0

Browse files
committed
Merge tag 'pull-ufs-20240630' of https://gitlab.com/jeuk20.kim/qemu into staging
hw/ufs: fix coverity issue # -----BEGIN PGP SIGNATURE----- # # iQIzBAABCgAdFiEEUBfYMVl8eKPZB+73EuIgTA5dtgIFAmaA1MQACgkQEuIgTA5d # tgIYSBAAul4qW0P6q0h3Dj/MLcGMPo4Y4kcWKe2AAkE/mBRvKbE7bLsA0y47WU5S # MJJApw4lwCsM12ZcD0W3YNbNwGUclQAVhLU5TOMowwaEWjNwmcsBR+AVwya4M2jQ # zSw6udIo5dfdy6KSe2EbRAuoDqBFJrcIH6EbXn/pBIhotlFzyUYYcpPBAq3rwh+V # haEtt3DapAektx+QkswBNEWu002OHyNDQXqfHnFvNMAYN9T25Nr+REai3VhZj379 # F/p5bFxou9FnwuGXRrpS1Em1jT+gRJnYoxp6iML8Zb4eZLhFs7T3WWkXHhbq7Nbt # oeg1CFdQeIt1iowk/dhtnSEQqnLe9dfPHj7pxU98dkYXHcN52Q5CRb+c0JnEyBLc # lGIjLVWvqYitOwGmvIdSmStd5TCLtuYmQGaI3slZCvsJTSo4Tkx3eI504NTVQ4K2 # lNY0jb+0PIsEUlyssimlsDA0SCkbpe5yE1G2NDCP74MjG0mlUm/h/OU0etk7uhwv # DNr1Lljr04FhcgVbMGX5sbMeK2QiCDuOlCF1T4zkzDFdWKIl414vH1wvjv1cBKlj # RdAfAi8zIV5lOeSqX13E9B0tjwUALlWFApW8J7pefijSBOGxEfFQJ39Gd4eIEFgD # Bj9Nc1ddDs30YaCZSMYsqcHU09srlobWmPqadba6hyJW4L1B9bU= # =d0WA # -----END PGP SIGNATURE----- # gpg: Signature made Sat 29 Jun 2024 08:45:08 PM PDT # gpg: using RSA key 5017D831597C78A3D907EEF712E2204C0E5DB602 # gpg: Good signature from "Jeuk Kim <jeuk20.kim@samsung.com>" [unknown] # gpg: aka "Jeuk Kim <jeuk20.kim@gmail.com>" [unknown] # gpg: WARNING: This key is not certified with a trusted signature! # gpg: There is no indication that the signature belongs to the owner. # Primary key fingerprint: 5017 D831 597C 78A3 D907 EEF7 12E2 204C 0E5D B602 * tag 'pull-ufs-20240630' of https://gitlab.com/jeuk20.kim/qemu: hw/ufs: Fix potential bugs in MMIO read|write Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
2 parents 3665dd6 + e12b11f commit 5dbb1f0

File tree

1 file changed

+16
-15
lines changed

1 file changed

+16
-15
lines changed

hw/ufs/ufs.c

+16-15
Original file line numberDiff line numberDiff line change
@@ -55,17 +55,18 @@ static inline uint64_t ufs_reg_size(UfsHc *u)
5555
return ufs_mcq_op_reg_addr(u, 0) + sizeof(u->mcq_op_reg);
5656
}
5757

58-
static inline bool ufs_is_mcq_reg(UfsHc *u, uint64_t addr)
58+
static inline bool ufs_is_mcq_reg(UfsHc *u, uint64_t addr, unsigned size)
5959
{
6060
uint64_t mcq_reg_addr = ufs_mcq_reg_addr(u, 0);
61-
return addr >= mcq_reg_addr && addr < mcq_reg_addr + sizeof(u->mcq_reg);
61+
return (addr >= mcq_reg_addr &&
62+
addr + size <= mcq_reg_addr + sizeof(u->mcq_reg));
6263
}
6364

64-
static inline bool ufs_is_mcq_op_reg(UfsHc *u, uint64_t addr)
65+
static inline bool ufs_is_mcq_op_reg(UfsHc *u, uint64_t addr, unsigned size)
6566
{
6667
uint64_t mcq_op_reg_addr = ufs_mcq_op_reg_addr(u, 0);
6768
return (addr >= mcq_op_reg_addr &&
68-
addr < mcq_op_reg_addr + sizeof(u->mcq_op_reg));
69+
addr + size <= mcq_op_reg_addr + sizeof(u->mcq_op_reg));
6970
}
7071

7172
static MemTxResult ufs_addr_read(UfsHc *u, hwaddr addr, void *buf, int size)
@@ -774,25 +775,25 @@ static void ufs_write_mcq_op_reg(UfsHc *u, hwaddr offset, uint32_t data,
774775
static uint64_t ufs_mmio_read(void *opaque, hwaddr addr, unsigned size)
775776
{
776777
UfsHc *u = (UfsHc *)opaque;
777-
uint8_t *ptr;
778+
uint32_t *ptr;
778779
uint64_t value;
779780
uint64_t offset;
780781

781-
if (addr < sizeof(u->reg)) {
782+
if (addr + size <= sizeof(u->reg)) {
782783
offset = addr;
783-
ptr = (uint8_t *)&u->reg;
784-
} else if (ufs_is_mcq_reg(u, addr)) {
784+
ptr = (uint32_t *)&u->reg;
785+
} else if (ufs_is_mcq_reg(u, addr, size)) {
785786
offset = addr - ufs_mcq_reg_addr(u, 0);
786-
ptr = (uint8_t *)&u->mcq_reg;
787-
} else if (ufs_is_mcq_op_reg(u, addr)) {
787+
ptr = (uint32_t *)&u->mcq_reg;
788+
} else if (ufs_is_mcq_op_reg(u, addr, size)) {
788789
offset = addr - ufs_mcq_op_reg_addr(u, 0);
789-
ptr = (uint8_t *)&u->mcq_op_reg;
790+
ptr = (uint32_t *)&u->mcq_op_reg;
790791
} else {
791792
trace_ufs_err_invalid_register_offset(addr);
792793
return 0;
793794
}
794795

795-
value = *(uint32_t *)(ptr + offset);
796+
value = ptr[offset >> 2];
796797
trace_ufs_mmio_read(addr, value, size);
797798
return value;
798799
}
@@ -804,11 +805,11 @@ static void ufs_mmio_write(void *opaque, hwaddr addr, uint64_t data,
804805

805806
trace_ufs_mmio_write(addr, data, size);
806807

807-
if (addr < sizeof(u->reg)) {
808+
if (addr + size <= sizeof(u->reg)) {
808809
ufs_write_reg(u, addr, data, size);
809-
} else if (ufs_is_mcq_reg(u, addr)) {
810+
} else if (ufs_is_mcq_reg(u, addr, size)) {
810811
ufs_write_mcq_reg(u, addr - ufs_mcq_reg_addr(u, 0), data, size);
811-
} else if (ufs_is_mcq_op_reg(u, addr)) {
812+
} else if (ufs_is_mcq_op_reg(u, addr, size)) {
812813
ufs_write_mcq_op_reg(u, addr - ufs_mcq_op_reg_addr(u, 0), data, size);
813814
} else {
814815
trace_ufs_err_invalid_register_offset(addr);

0 commit comments

Comments
 (0)