@samitouri / QOSamiQemu / commits / f0a2786f7e

hw/misc/allwinner-r40-ccu.c: Correct handling of out of range accesses

In allwinner_r40_ccu_write() we handle writes to a MemoryRegion of size AW_R40_CCU_IOSIZE, and the register array is sized accordingly at (AW_R40_CCU_IOSIZE / sizeof(uint32_t)). However, one of the cases in the switch is a range up to AW_R40_CCU_IOSIZE, which makes Coverity think we might index off the end of the array. We also have a similar case in the read function, but since that returns early it doesn't have the same issue. Adjust the handling of out of range accesses: - use AW_R40_CCU_IOSIZE - 4 as the upper bound, as this is the largest value we will actually see - return early in the write case, as we do in the read case Coverity CID: 1663687 Signed-off-by: Peter Maydell <peter.maydell@linaro.org> Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com> Reviewed-by: Strahinja Jankovic <strahinja.p.jankovic@gmail.com> Message-id: 20260709104802.1989086-1-peter.maydell@linaro.org

Peter Maydell committed Jul 13, 2026 at 12:34 UTC f0a2786f7edf85e8f3a1ef7d98bff10ac1675864
1 file changed +3 -3
hw/misc/allwinner-r40-ccu.c
+3 -3
@@ -71,7 +71,7 @@ static uint64_t allwinner_r40_ccu_read(void *opaque, hwaddr offset,
71 const uint32_t idx = REG_INDEX(offset);
72
73 switch (offset) {
74 - case 0x324 ... AW_R40_CCU_IOSIZE:
74 + case 0x324 ... AW_R40_CCU_IOSIZE - 4:
75 qemu_log_mask(LOG_GUEST_ERROR, "%s: out-of-bounds offset 0x%04x\n",
76 __func__, (uint32_t)offset);
77 return 0;
@@ -113,10 +113,10 @@ static void allwinner_r40_ccu_write(void *opaque, hwaddr offset,
113 val |= REG_PLL_LOCK;
114 }
115 break;
116 - case 0x324 ... AW_R40_CCU_IOSIZE:
116 + case 0x324 ... AW_R40_CCU_IOSIZE - 4:
117 qemu_log_mask(LOG_GUEST_ERROR, "%s: out-of-bounds offset 0x%04x\n",
118 __func__, (uint32_t)offset);
119 - break;
119 + return;
120 default:
121 qemu_log_mask(LOG_UNIMP, "%s: unimplemented write offset 0x%04x\n",
122 __func__, (uint32_t)offset);