- Introduce the SM4 cipher algorithms (OSCCA GB/T 32907-2016).
- intel_iommu: Add missed sanity check for 256-bit invalidation queue
- linux-user: use 'max' instead of 'qemu32' / 'qemu64' by default
- chardev/baum: Use definitions to avoid dynamic stack allocation
- ui/console: Get tab completion working again in the SDL monitor vc
- s390x/tcg: Fix opcode for lzrf
- virtiofsd: use g_date_time_get_microsecond to get subsecond
- ui/curses: Avoid dynamic stack allocation
- target/m68k: always call gen_exit_tb() after writes to SR
- target/m68k: Perform writback before modifying SR
- target/m68k: Fix MACSR to CCR
- target/m68k: Implement atomic test-and-set
- block/nvme: nvme_process_completion() fix bound for cid
- hw/pci-host: pnv_phb{3, 4}: Fix heap out-of-bound access failure
- target/ppc: Zero second doubleword of VSR registers for FPR insns
- target/ppc: Set OV32 when OV is set
- target/ppc: Zero second doubleword for VSX madd instructions
- target/ppc: Set result to QNaN for DENBCD when VXCVI occurs
- hw/pci: Add parenthesis to PCI_BUILD_BDF macro
- intel_iommu: Send IQE event when setting reserved bit in IQT_TAIL
- acpi: cpuhp: fix guest-visible maximum access size to the legacy reg block
- acpi: ged: Add macro for acpi sleep control register
- hw/pci-bridge: Add a Kconfig switch for the normal PCI bridge
- ui/vnc: fix handling of VNC_FEATURE_XVP
- s390/sclp: fix SCLP facility map
- docs/tools/qemu-img.rst: fix typo (sumarizes)
- chardev/char: fix qemu_chr_is_busy() check
- edu: fix DMA range upper bound check
- platform-bus: fix refcount leak
- hw/net/virtio-net: fix qemu set used ring flag even vhost started
- hw/net/can/sja1000: fix bug for single acceptance filter and standard frame
- tests/avocado: fix typo in replay_linux
- util/userfaultfd: Remove unused uffd_poll_events
- hw/core/ptimer: fix timer zero period condition for freq > 1GHz
- hcd-ohci: Drop ohci_service_iso_td() if ed->head & OHCI_DPTR_MASK is zero
- tests/unit/test-vmstate: Avoid dynamic stack allocation
- hw/usb/hcd-ohci: Use definition to avoid dynamic stack allocation
- hw/i386/multiboot: Avoid dynamic stack allocation
- hw/ppc/spapr: Fix code style problems reported by checkpatch
- chardev/baum: Replace magic values by X_MAX / Y_MAX definitions
- hw/intc/xics: Avoid dynamic stack allocation
- hw/net/e1000e_core: Use definition to avoid dynamic stack allocation
- intel_iommu: Fix invalidation descriptor type field
- configs: Fix typo in the sh4-softmmu devices config file
Signed-off-by: Jiabo Feng <fengjiabo1@huawei.com>
(cherry picked from commit 9813ed21ec2499c50cb58ac5fb114a1641708eb2)
50 lines
1.9 KiB
Diff
50 lines
1.9 KiB
Diff
From 364efd620bb9b6003a2b65fe7ea56b640a209be4 Mon Sep 17 00:00:00 2001
|
|
From: Liu Jing <liujing_yewu@cmss.chinamobile.com>
|
|
Date: Mon, 21 Oct 2024 19:22:03 +0800
|
|
Subject: [PATCH] target/m68k: Perform writback before modifying SR
|
|
|
|
Writes to SR may change security state, which may involve
|
|
a swap of %ssp with %usp as reflected in %a7. Finish the
|
|
writeback of %sp@+ before swapping stack pointers.
|
|
|
|
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/1206
|
|
Signed-off-by: Richard Henderson <richard.henderson@linaro.org>
|
|
Reviewed-by: Laurent Vivier <laurent@vivier.eu>
|
|
Reviewed-by: Mark Cave-Ayland <mark.cave-ayland@ilande.co.uk>
|
|
Message-Id: <20220913142818.7802-3-richard.henderson@linaro.org>
|
|
Signed-off-by: Laurent Vivier <laurent@vivier.eu>
|
|
Signed-off-by: Liu Jing <liujing_yewu@cmss.chinamobile.com>
|
|
---
|
|
target/m68k/translate.c | 8 +++++---
|
|
1 file changed, 5 insertions(+), 3 deletions(-)
|
|
|
|
diff --git a/target/m68k/translate.c b/target/m68k/translate.c
|
|
index af43c8eab8..6cc4321921 100644
|
|
--- a/target/m68k/translate.c
|
|
+++ b/target/m68k/translate.c
|
|
@@ -2269,9 +2269,9 @@ static void gen_set_sr_im(DisasContext *s, uint16_t val, int ccr_only)
|
|
tcg_gen_movi_i32(QREG_CC_N, val & CCF_N ? -1 : 0);
|
|
tcg_gen_movi_i32(QREG_CC_X, val & CCF_X ? 1 : 0);
|
|
} else {
|
|
- TCGv sr = tcg_const_i32(val);
|
|
- gen_helper_set_sr(cpu_env, sr);
|
|
- tcg_temp_free(sr);
|
|
+ /* Must writeback before changing security state. */
|
|
+ do_writebacks(s);
|
|
+ gen_helper_set_sr(cpu_env, tcg_constant_i32(val));
|
|
}
|
|
set_cc_op(s, CC_OP_FLAGS);
|
|
}
|
|
@@ -2281,6 +2281,8 @@ static void gen_set_sr(DisasContext *s, TCGv val, int ccr_only)
|
|
if (ccr_only) {
|
|
gen_helper_set_ccr(cpu_env, val);
|
|
} else {
|
|
+ /* Must writeback before changing security state. */
|
|
+ do_writebacks(s);
|
|
gen_helper_set_sr(cpu_env, val);
|
|
}
|
|
set_cc_op(s, CC_OP_FLAGS);
|
|
--
|
|
2.41.0.windows.1
|
|
|