diff options
author | Nicholas Piggin <npiggin@gmail.com> | 2024-11-04 02:09:12 +1000 |
---|---|---|
committer | Nicholas Piggin <npiggin@gmail.com> | 2024-11-04 09:14:10 +1000 |
commit | 07f2770503e24889720028ddf9ef54788ddf3b6d (patch) | |
tree | ae7f3ff1eb2f5f9900a2f16adca3a62bd8237094 /hw/intc | |
parent | 889c5c4c7a32be298aa499a246dbfd0c5fea8a74 (diff) | |
download | qemu-07f2770503e24889720028ddf9ef54788ddf3b6d.zip qemu-07f2770503e24889720028ddf9ef54788ddf3b6d.tar.gz qemu-07f2770503e24889720028ddf9ef54788ddf3b6d.tar.bz2 |
ppc/xive: Fix ESB length overflow on 32-bit hosts
The length of this region can be > 32-bits, which overflows size_t on
32-bit hosts. Change to uint64_t.
Signed-off-by: Nicholas Piggin <npiggin@gmail.com>
Diffstat (limited to 'hw/intc')
-rw-r--r-- | hw/intc/spapr_xive_kvm.c | 4 | ||||
-rw-r--r-- | hw/intc/xive.c | 2 |
2 files changed, 3 insertions, 3 deletions
diff --git a/hw/intc/spapr_xive_kvm.c b/hw/intc/spapr_xive_kvm.c index 5789062..7a86197 100644 --- a/hw/intc/spapr_xive_kvm.c +++ b/hw/intc/spapr_xive_kvm.c @@ -720,7 +720,7 @@ int kvmppc_xive_connect(SpaprInterruptController *intc, uint32_t nr_servers, { SpaprXive *xive = SPAPR_XIVE(intc); XiveSource *xsrc = &xive->source; - size_t esb_len = xive_source_esb_len(xsrc); + uint64_t esb_len = xive_source_esb_len(xsrc); size_t tima_len = 4ull << TM_SHIFT; CPUState *cs; int fd; @@ -824,7 +824,7 @@ void kvmppc_xive_disconnect(SpaprInterruptController *intc) { SpaprXive *xive = SPAPR_XIVE(intc); XiveSource *xsrc; - size_t esb_len; + uint64_t esb_len; assert(xive->fd != -1); diff --git a/hw/intc/xive.c b/hw/intc/xive.c index 5a02dd8..b600546 100644 --- a/hw/intc/xive.c +++ b/hw/intc/xive.c @@ -1242,7 +1242,7 @@ static void xive_source_reset(void *dev) static void xive_source_realize(DeviceState *dev, Error **errp) { XiveSource *xsrc = XIVE_SOURCE(dev); - size_t esb_len = xive_source_esb_len(xsrc); + uint64_t esb_len = xive_source_esb_len(xsrc); assert(xsrc->xive); |