Skip to content

Commit ad766d6

Browse files
committed
hw/net/lan9118: Fix overflow in MIL TX FIFO
When the MAC Interface Layer (MIL) transmit FIFO is full, truncate the packet, and raise the Transmitter Error (TXE) flag. Broken since model introduction in commit 2a42499 ("LAN9118 emulation"). When using the reproducer from https://gitlab.com/qemu-project/qemu/-/issues/2267 we get: hw/net/lan9118.c:798:17: runtime error: index 2048 out of bounds for type 'uint8_t[2048]' (aka 'unsigned char[2048]')     #0 0x563ec9a057b1 in tx_fifo_push hw/net/lan9118.c:798:43     #1 0x563ec99fbb28 in lan9118_writel hw/net/lan9118.c:1042:9     #2 0x563ec99f2de2 in lan9118_16bit_mode_write hw/net/lan9118.c:1205:9     #3 0x563ecbf78013 in memory_region_write_accessor system/memory.c:497:5     #4 0x563ecbf776f5 in access_with_adjusted_size system/memory.c:573:18     #5 0x563ecbf75643 in memory_region_dispatch_write system/memory.c:1521:16     #6 0x563ecc01bade in flatview_write_continue_step system/physmem.c:2713:18     #7 0x563ecc01b374 in flatview_write_continue system/physmem.c:2743:19     #8 0x563ecbff1c9b in flatview_write system/physmem.c:2774:12     #9 0x563ecbff1768 in address_space_write system/physmem.c:2894:18 ... [*] LAN9118 DS00002266B.pdf, Table 5.3.3 "INTERRUPT STATUS REGISTER" Cc: [email protected] Reported-by: Will Lester Reported-by: Chuhong Yuan <[email protected]> Suggested-by: Peter Maydell <[email protected]> Resolves: https://gitlab.com/qemu-project/qemu/-/issues/2267 Signed-off-by: Philippe Mathieu-Daudé <[email protected]> Reviewed-by: Peter Maydell <[email protected]> Message-Id: <[email protected]>
1 parent a452234 commit ad766d6

File tree

1 file changed

+15
-1
lines changed

1 file changed

+15
-1
lines changed

hw/net/lan9118.c

+15-1
Original file line numberDiff line numberDiff line change
@@ -799,8 +799,22 @@ static void tx_fifo_push(lan9118_state *s, uint32_t val)
799799
/* Documentation is somewhat unclear on the ordering of bytes
800800
in FIFO words. Empirical results show it to be little-endian.
801801
*/
802-
/* TODO: FIFO overflow checking. */
803802
while (n--) {
803+
if (s->txp->len == MIL_TXFIFO_SIZE) {
804+
/*
805+
* No more space in the FIFO. The datasheet is not
806+
* precise about this case. We choose what is easiest
807+
* to model: the packet is truncated, and TXE is raised.
808+
*
809+
* Note, it could be a fragmented packet, but we currently
810+
* do not handle that (see earlier TX_B case).
811+
*/
812+
qemu_log_mask(LOG_GUEST_ERROR,
813+
"MIL TX FIFO overrun, discarding %u byte%s\n",
814+
n, n > 1 ? "s" : "");
815+
s->int_sts |= TXE_INT;
816+
break;
817+
}
804818
s->txp->data[s->txp->len] = val & 0xff;
805819
s->txp->len++;
806820
val >>= 8;

0 commit comments

Comments
 (0)