@samitouri / QOSamiQemu / commits / e9fa0330a2

ati-vga: Do not access pixel outside the screen

We check end of screen before writing the pixel but before that complement color also accesses screen pixel so we have to check before that. This fixes a segmentation fault with guest_hwcursor when pointer is partially out of screen at lower right corner. Signed-off-by: BALATON Zoltan <balaton@eik.bme.hu> Reviewed-by: Chad Jablonski <chad@jablonski.xyz> Message-ID: <26db0715a6b9f6504f394010513facc9a37882ad.1773009887.git.balaton@eik.bme.hu> Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>

BALATON Zoltan committed Mar 8, 2026 at 23:49 UTC e9fa0330a20d117d70f604cb5a1fd647f531c1b7
1 file changed +3 -3
hw/display/ati.c
+3 -3
@@ -214,6 +214,9 @@ static void ati_cursor_draw_line(VGACommonState *vga, uint8_t *d, int scr_y)
214 uint8_t abits = vga_read_byte(vga, srcoff + i);
215 uint8_t xbits = vga_read_byte(vga, srcoff + i + 8);
216 for (j = 0; j < 8; j++, abits <<= 1, xbits <<= 1, idx++) {
217 + if (vga->hw_cursor_x + idx >= h) {
218 + return; /* end of screen, don't span to next line */
219 + }
220 if (abits & BIT(7)) {
221 if (xbits & BIT(7)) {
222 color = dp[idx] ^ 0xffffffff; /* complement */
@@ -224,9 +227,6 @@ static void ati_cursor_draw_line(VGACommonState *vga, uint8_t *d, int scr_y)
227 color = (xbits & BIT(7) ? s->regs.cur_color1 :
228 s->regs.cur_color0) | 0xff000000;
229 }
227 - if (vga->hw_cursor_x + idx >= h) {
228 - return; /* end of screen, don't span to next line */
229 - }
230 dp[idx] = color;
231 }
232 }