mirror of
https://github.com/mii443/qemu.git
synced 2025-08-23 07:35:47 +00:00
virtio: use virtio accessor to access packed descriptor flags
We used to access packed descriptor flags via address_space_{write|read}_cached(). When we hit the cache, memcpy() is used which is not an atomic operation which may lead a wrong value is read or wrote. So this patch switches to use virito_{stw|lduw}_phys_cached() to make sure the aceess is atomic. Fixes:86044b24e8
("virtio: basic packed virtqueue support") Cc: qemu-stable@nongnu.org Signed-off-by: Jason Wang <jasowang@redhat.com> Message-Id: <20211111063854.29060-1-jasowang@redhat.com> Reviewed-by: Philippe Mathieu-Daudé <philmd@redhat.com> Reviewed-by: Michael S. Tsirkin <mst@redhat.com> Signed-off-by: Michael S. Tsirkin <mst@redhat.com> (cherry picked from commitf463e761a4
) Signed-off-by: Michael Roth <michael.roth@amd.com>
This commit is contained in:
@ -509,11 +509,9 @@ static void vring_packed_desc_read_flags(VirtIODevice *vdev,
|
|||||||
MemoryRegionCache *cache,
|
MemoryRegionCache *cache,
|
||||||
int i)
|
int i)
|
||||||
{
|
{
|
||||||
address_space_read_cached(cache,
|
hwaddr off = i * sizeof(VRingPackedDesc) + offsetof(VRingPackedDesc, flags);
|
||||||
i * sizeof(VRingPackedDesc) +
|
|
||||||
offsetof(VRingPackedDesc, flags),
|
*flags = virtio_lduw_phys_cached(vdev, cache, off);
|
||||||
flags, sizeof(*flags));
|
|
||||||
virtio_tswap16s(vdev, flags);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
static void vring_packed_desc_read(VirtIODevice *vdev,
|
static void vring_packed_desc_read(VirtIODevice *vdev,
|
||||||
@ -566,8 +564,7 @@ static void vring_packed_desc_write_flags(VirtIODevice *vdev,
|
|||||||
{
|
{
|
||||||
hwaddr off = i * sizeof(VRingPackedDesc) + offsetof(VRingPackedDesc, flags);
|
hwaddr off = i * sizeof(VRingPackedDesc) + offsetof(VRingPackedDesc, flags);
|
||||||
|
|
||||||
virtio_tswap16s(vdev, &desc->flags);
|
virtio_stw_phys_cached(vdev, cache, off, desc->flags);
|
||||||
address_space_write_cached(cache, off, &desc->flags, sizeof(desc->flags));
|
|
||||||
address_space_cache_invalidate(cache, off, sizeof(desc->flags));
|
address_space_cache_invalidate(cache, off, sizeof(desc->flags));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
Reference in New Issue
Block a user