hw/dma/pl080: Ignore bottom 2 bits of LLI register
The PL080 channel LLI (linked list item) register has bits [31:2] of the address of the next LLI in bits [31:2], with bit [1] reserved and bits [0] the AHB master select. We were incorrectly using the whole register value as the address, which meant that if the guest programmed something into the AHB master select bit we would use an incorrect address, and read incorrect data from memory. The following reproducer creates a setup which has bit 0 set in an LLI value: Configuration ../configure --target-list=arm-softmmu --enable-debug Reproducer ./qemu-system-arm -M versatilepb -m 128M -nographic -S \ -device loader,addr=0x00002000,data=0x00000004,data-len=4 \ -device loader,addr=0x00002004,data=0x00001004,data-len=4 \ -device loader,addr=0x00002008,data=0x00000000,data-len=4 \ -device loader,addr=0x0000200c,data=0x9e4bf001,data-len=4 \ -device loader,addr=0x00000000,data=0x44332211,data-len=4 \ -device loader,addr=0x00000004,data=0x88776655,data-len=4 \ -device loader,addr=0x00001000,data=0x00000000,data-len=4 \ -device loader,addr=0x00001004,data=0x00000000,data-len=4 \ -device loader,addr=0x10130030,data=0x00000001,data-len=4 \ -device loader,addr=0x10130100,data=0x00000000,data-len=4 \ -device loader,addr=0x10130104,data=0x00001000,data-len=4 \ -device loader,addr=0x10130108,data=0x00002001,data-len=4 \ -device loader,addr=0x1013010C,data=0x1e4bf001,data-len=4 \ -device loader,addr=0x10130110,data=0x0000c001,data-len=4 The correct result with this bug fix: (qemu) xp /1wx 0x00001000 00001000: 0x44332211 (qemu) xp /1wx 0x00001004 00001004: 0x88776655 Cc: qemu-stable@nongnu.org Signed-off-by: Tao Ding <dingtao0430@163.com> [PMM: Adjusted commit message] Reviewed-by: Peter Maydell <peter.maydell@linaro.org> Message-id: cb35c1b622674da7a2b70691402132f691933f2c.1773301927.git.dingtao0430@163.com Signed-off-by: Peter Maydell <peter.maydell@linaro.org>