qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [Bug 1909823] [NEW] RDPMC check on PCE is backwards
@ 2021-01-01 17:50 Bruce Merry
  2021-05-12 11:27 ` [Bug 1909823] " Thomas Huth
  2021-05-15  8:32 ` Bruce Merry
  0 siblings, 2 replies; 3+ messages in thread
From: Bruce Merry @ 2021-01-01 17:50 UTC (permalink / raw)
  To: qemu-devel

Public bug reported:

At [this
line](https://github.com/qemu/qemu/blob/75ee62ac606bfc9eb59310b9446df3434bf6e8c2/target/i386/tcg/misc_helper.c#L225)
the check on CR4_PCE_MASK is backwards: it's raising an exception if the
flag is set (and CPL != 0) rather than if the flag is clear.

It's low priority at the moment because the instruction isn't
implemented, so you get an illegal opcode exception when expecting a
GPF, or vice versa, but it's a time bomb for if it is ever implemented.

The Intel docs also indicate that CR0.PE influences the protection; I
don't know if that's already reflected in env->hflags & HF_CPL_MASK.

** Affects: qemu
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of qemu-
devel-ml, which is subscribed to QEMU.
https://bugs.launchpad.net/bugs/1909823

Title:
  RDPMC check on PCE is backwards

Status in QEMU:
  New

Bug description:
  At [this
  line](https://github.com/qemu/qemu/blob/75ee62ac606bfc9eb59310b9446df3434bf6e8c2/target/i386/tcg/misc_helper.c#L225)
  the check on CR4_PCE_MASK is backwards: it's raising an exception if
  the flag is set (and CPL != 0) rather than if the flag is clear.

  It's low priority at the moment because the instruction isn't
  implemented, so you get an illegal opcode exception when expecting a
  GPF, or vice versa, but it's a time bomb for if it is ever
  implemented.

  The Intel docs also indicate that CR0.PE influences the protection; I
  don't know if that's already reflected in env->hflags & HF_CPL_MASK.

To manage notifications about this bug go to:
https://bugs.launchpad.net/qemu/+bug/1909823/+subscriptions


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2021-05-15  8:43 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2021-01-01 17:50 [Bug 1909823] [NEW] RDPMC check on PCE is backwards Bruce Merry
2021-05-12 11:27 ` [Bug 1909823] " Thomas Huth
2021-05-15  8:32 ` Bruce Merry

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).