Skip to content
  • Zheyu Ma's avatar
    net: tulip: Restrict DMA engine to memories · 36a894ae
    Zheyu Ma authored and Jason Wang's avatar Jason Wang committed
    
    
    The DMA engine is started by I/O access and then itself accesses the
    I/O registers, triggering a reentrancy bug.
    
    The following log can reveal it:
    ==5637==ERROR: AddressSanitizer: stack-overflow
        #0 0x5595435f6078 in tulip_xmit_list_update qemu/hw/net/tulip.c:673
        #1 0x5595435f204a in tulip_write qemu/hw/net/tulip.c:805:13
        #2 0x559544637f86 in memory_region_write_accessor qemu/softmmu/memory.c:492:5
        #3 0x5595446379fa in access_with_adjusted_size qemu/softmmu/memory.c:554:18
        #4 0x5595446372fa in memory_region_dispatch_write qemu/softmmu/memory.c
        #5 0x55954468b74c in flatview_write_continue qemu/softmmu/physmem.c:2825:23
        #6 0x559544683662 in flatview_write qemu/softmmu/physmem.c:2867:12
        #7 0x5595446833f3 in address_space_write qemu/softmmu/physmem.c:2963:18
        #8 0x5595435fb082 in dma_memory_rw_relaxed qemu/include/sysemu/dma.h:87:12
        #9 0x5595435fb082 in dma_memory_rw qemu/include/sysemu/dma.h:130:12
        #10 0x5595435fb082 in dma_memory_write qemu/include/sysemu/dma.h:171:12
        #11 0x5595435fb082 in stl_le_dma qemu/include/sysemu/dma.h:272:1
        #12 0x5595435fb082 in stl_le_pci_dma qemu/include/hw/pci/pci.h:910:1
        #13 0x5595435fb082 in tulip_desc_write qemu/hw/net/tulip.c:101:9
        #14 0x5595435f7e3d in tulip_xmit_list_update qemu/hw/net/tulip.c:706:9
        #15 0x5595435f204a in tulip_write qemu/hw/net/tulip.c:805:13
    
    Fix this bug by restricting the DMA engine to memories regions.
    
    Signed-off-by: default avatarZheyu Ma <zheyuma97@gmail.com>
    Signed-off-by: Jason Wang's avatarJason Wang <jasowang@redhat.com>
    36a894ae