diff mbox

[V2,5/8] memory: don't try to adjust endianness for zero length eventfd

Message ID 1441164325-14417-6-git-send-email-jasowang@redhat.com
State New
Headers show

Commit Message

Jason Wang Sept. 2, 2015, 3:25 a.m. UTC
There's no need to adjust endianness for zero length eventfd since the
data wrote was actually ignored by kernel. So skip the adjust in this
case to fix a possible crash when trying to use wildcard mmio eventfd
in ppc.

Cc: Greg Kurz <gkurz@linux.vnet.ibm.com>
Cc: Peter Maydell <peter.maydell@linaro.org>
Cc: Paolo Bonzini <pbonzini@redhat.com>
Signed-off-by: Jason Wang <jasowang@redhat.com>
---
 memory.c | 8 ++++++--
 1 file changed, 6 insertions(+), 2 deletions(-)

Comments

Greg Kurz Sept. 2, 2015, 3:59 p.m. UTC | #1
On Wed,  2 Sep 2015 11:25:22 +0800
Jason Wang <jasowang@redhat.com> wrote:

> There's no need to adjust endianness for zero length eventfd since the
> data wrote was actually ignored by kernel. So skip the adjust in this
> case to fix a possible crash when trying to use wildcard mmio eventfd
> in ppc.
> 
> Cc: Greg Kurz <gkurz@linux.vnet.ibm.com>
> Cc: Peter Maydell <peter.maydell@linaro.org>
> Cc: Paolo Bonzini <pbonzini@redhat.com>
> Signed-off-by: Jason Wang <jasowang@redhat.com>
> ---

Indeed, this patch prevents the crash to occur on ppc64.

Acked-by: Greg Kurz <gkurz@linux.vnet.ibm.com>

>  memory.c | 8 ++++++--
>  1 file changed, 6 insertions(+), 2 deletions(-)
> 
> diff --git a/memory.c b/memory.c
> index 0d8b2d9..de2d999 100644
> --- a/memory.c
> +++ b/memory.c
> @@ -1653,7 +1653,9 @@ void memory_region_add_eventfd(MemoryRegion *mr,
>      };
>      unsigned i;
> 
> -    adjust_endianness(mr, &mrfd.data, size);
> +    if (size) {
> +        adjust_endianness(mr, &mrfd.data, size);
> +    }
>      memory_region_transaction_begin();
>      for (i = 0; i < mr->ioeventfd_nb; ++i) {
>          if (memory_region_ioeventfd_before(mrfd, mr->ioeventfds[i])) {
> @@ -1686,7 +1688,9 @@ void memory_region_del_eventfd(MemoryRegion *mr,
>      };
>      unsigned i;
> 
> -    adjust_endianness(mr, &mrfd.data, size);
> +    if (size) {
> +        adjust_endianness(mr, &mrfd.data, size);
> +    }
>      memory_region_transaction_begin();
>      for (i = 0; i < mr->ioeventfd_nb; ++i) {
>          if (memory_region_ioeventfd_equal(mrfd, mr->ioeventfds[i])) {
diff mbox

Patch

diff --git a/memory.c b/memory.c
index 0d8b2d9..de2d999 100644
--- a/memory.c
+++ b/memory.c
@@ -1653,7 +1653,9 @@  void memory_region_add_eventfd(MemoryRegion *mr,
     };
     unsigned i;
 
-    adjust_endianness(mr, &mrfd.data, size);
+    if (size) {
+        adjust_endianness(mr, &mrfd.data, size);
+    }
     memory_region_transaction_begin();
     for (i = 0; i < mr->ioeventfd_nb; ++i) {
         if (memory_region_ioeventfd_before(mrfd, mr->ioeventfds[i])) {
@@ -1686,7 +1688,9 @@  void memory_region_del_eventfd(MemoryRegion *mr,
     };
     unsigned i;
 
-    adjust_endianness(mr, &mrfd.data, size);
+    if (size) {
+        adjust_endianness(mr, &mrfd.data, size);
+    }
     memory_region_transaction_begin();
     for (i = 0; i < mr->ioeventfd_nb; ++i) {
         if (memory_region_ioeventfd_equal(mrfd, mr->ioeventfds[i])) {