aboutsummaryrefslogtreecommitdiff
path: root/io
diff options
context:
space:
mode:
authorPeter Maydell <peter.maydell@linaro.org>2023-09-12 15:04:23 +0100
committerPeter Maydell <peter.maydell@linaro.org>2023-09-21 16:07:13 +0100
commit903dbefc2b6918c10d12d9aafa0168cee8d287c7 (patch)
tree618a00b8c77ce2f3a0eed4833081f3dbf2d27dc4 /io
parent0b5ad31d2a997c9b80e7e24aafce7f079fc67bbd (diff)
downloadqemu-903dbefc2b6918c10d12d9aafa0168cee8d287c7.zip
qemu-903dbefc2b6918c10d12d9aafa0168cee8d287c7.tar.gz
qemu-903dbefc2b6918c10d12d9aafa0168cee8d287c7.tar.bz2
target/arm: Don't skip MTE checks for LDRT/STRT at EL0
The LDRT/STRT "unprivileged load/store" instructions behave like normal ones if executed at EL0. We handle this correctly for the load/store semantics, but get the MTE checking wrong. We always look at s->mte_active[is_unpriv] to see whether we should be doing MTE checks, but in hflags.c when we set the TB flags that will be used to fill the mte_active[] array we only set the MTE0_ACTIVE bit if UNPRIV is true (i.e. we are not at EL0). This means that a LDRT at EL0 will see s->mte_active[1] as 0, and will not do MTE checks even when MTE is enabled. To avoid the translate-time code having to do an explicit check on s->unpriv to see if it is OK to index into the mte_active[] array, duplicate MTE_ACTIVE into MTE0_ACTIVE when UNPRIV is false. (This isn't a very serious bug because generally nobody executes LDRT/STRT at EL0, because they have no use there.) Cc: qemu-stable@nongnu.org Signed-off-by: Peter Maydell <peter.maydell@linaro.org> Reviewed-by: Richard Henderson <richard.henderson@linaro.org> Message-id: 20230912140434.1333369-2-peter.maydell@linaro.org
Diffstat (limited to 'io')
0 files changed, 0 insertions, 0 deletions