- Introduce the SM4 cipher algorithms (OSCCA GB/T 32907-2016).
- intel_iommu: Add missed sanity check for 256-bit invalidation queue
- linux-user: use 'max' instead of 'qemu32' / 'qemu64' by default
- chardev/baum: Use definitions to avoid dynamic stack allocation
- ui/console: Get tab completion working again in the SDL monitor vc
- s390x/tcg: Fix opcode for lzrf
- virtiofsd: use g_date_time_get_microsecond to get subsecond
- ui/curses: Avoid dynamic stack allocation
- target/m68k: always call gen_exit_tb() after writes to SR
- target/m68k: Perform writback before modifying SR
- target/m68k: Fix MACSR to CCR
- target/m68k: Implement atomic test-and-set
- block/nvme: nvme_process_completion() fix bound for cid
- hw/pci-host: pnv_phb{3, 4}: Fix heap out-of-bound access failure
- target/ppc: Zero second doubleword of VSR registers for FPR insns
- target/ppc: Set OV32 when OV is set
- target/ppc: Zero second doubleword for VSX madd instructions
- target/ppc: Set result to QNaN for DENBCD when VXCVI occurs
- hw/pci: Add parenthesis to PCI_BUILD_BDF macro
- intel_iommu: Send IQE event when setting reserved bit in IQT_TAIL
- acpi: cpuhp: fix guest-visible maximum access size to the legacy reg block
- acpi: ged: Add macro for acpi sleep control register
- hw/pci-bridge: Add a Kconfig switch for the normal PCI bridge
- ui/vnc: fix handling of VNC_FEATURE_XVP
- s390/sclp: fix SCLP facility map
- docs/tools/qemu-img.rst: fix typo (sumarizes)
- chardev/char: fix qemu_chr_is_busy() check
- edu: fix DMA range upper bound check
- platform-bus: fix refcount leak
- hw/net/virtio-net: fix qemu set used ring flag even vhost started
- hw/net/can/sja1000: fix bug for single acceptance filter and standard frame
- tests/avocado: fix typo in replay_linux
- util/userfaultfd: Remove unused uffd_poll_events
- hw/core/ptimer: fix timer zero period condition for freq > 1GHz
- hcd-ohci: Drop ohci_service_iso_td() if ed->head & OHCI_DPTR_MASK is zero
- tests/unit/test-vmstate: Avoid dynamic stack allocation
- hw/usb/hcd-ohci: Use definition to avoid dynamic stack allocation
- hw/i386/multiboot: Avoid dynamic stack allocation
- hw/ppc/spapr: Fix code style problems reported by checkpatch
- chardev/baum: Replace magic values by X_MAX / Y_MAX definitions
- hw/intc/xics: Avoid dynamic stack allocation
- hw/net/e1000e_core: Use definition to avoid dynamic stack allocation
- intel_iommu: Fix invalidation descriptor type field
- configs: Fix typo in the sh4-softmmu devices config file
Signed-off-by: Jiabo Feng <fengjiabo1@huawei.com>
(cherry picked from commit 9813ed21ec2499c50cb58ac5fb114a1641708eb2)
43 lines
1.7 KiB
Diff
43 lines
1.7 KiB
Diff
From 3abff2e277d590cd59941672278bbc3c94a8b90d Mon Sep 17 00:00:00 2001
|
|
From: Zhang Jiao <zhangjiao2_yewu@cmss.chinamobile.com>
|
|
Date: Mon, 21 Oct 2024 14:48:25 +0800
|
|
Subject: [PATCH] block/nvme: nvme_process_completion() fix bound for cid
|
|
|
|
cheery-pick from cc8fb0c3ae3c950eb40e969607e17ff16a7519ac
|
|
|
|
NVMeQueuePair::reqs has length NVME_NUM_REQS, which less than
|
|
NVME_QUEUE_SIZE by 1.
|
|
|
|
Fixes: 1086e95da17050 ("block/nvme: switch to a NVMeRequest freelist")
|
|
Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>
|
|
Reviewed-by: Stefan Hajnoczi <stefanha@redhat.com>
|
|
Reviewed-by: Maksim Davydov <davydov-max@yandex-team.ru>
|
|
Message-id: 20231017125941.810461-5-vsementsov@yandex-team.ru
|
|
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
|
|
Signed-off-by: Zhang Jiao <zhangjiao2_yewu@cmss.chinamobile.com>
|
|
---
|
|
block/nvme.c | 7 ++++---
|
|
1 file changed, 4 insertions(+), 3 deletions(-)
|
|
|
|
diff --git a/block/nvme.c b/block/nvme.c
|
|
index fa360b9b3c..d8f4b04e19 100644
|
|
--- a/block/nvme.c
|
|
+++ b/block/nvme.c
|
|
@@ -410,9 +410,10 @@ static bool nvme_process_completion(NVMeQueuePair *q)
|
|
q->cq_phase = !q->cq_phase;
|
|
}
|
|
cid = le16_to_cpu(c->cid);
|
|
- if (cid == 0 || cid > NVME_QUEUE_SIZE) {
|
|
- warn_report("NVMe: Unexpected CID in completion queue: %"PRIu32", "
|
|
- "queue size: %u", cid, NVME_QUEUE_SIZE);
|
|
+ if (cid == 0 || cid > NVME_NUM_REQS) {
|
|
+ warn_report("NVMe: Unexpected CID in completion queue: %" PRIu32
|
|
+ ", should be within: 1..%u inclusively", cid,
|
|
+ NVME_NUM_REQS);
|
|
continue;
|
|
}
|
|
trace_nvme_complete_command(s, q->index, cid);
|
|
--
|
|
2.41.0.windows.1
|
|
|