From: Wei Yongjun <[email protected]>

If bit offset operands is a negative number, BitOp instruction
will return wrong value. This patch fix it.

Signed-off-by: Wei Yongjun <[email protected]>
Reviewed-by: Paolo Bonzini <[email protected]>
Signed-off-by: Avi Kivity <[email protected]>

diff --git a/arch/x86/kvm/emulate.c b/arch/x86/kvm/emulate.c
index a2a079f..5a5d527 100644
--- a/arch/x86/kvm/emulate.c
+++ b/arch/x86/kvm/emulate.c
@@ -723,6 +723,22 @@ done:
        return rc;
 }
 
+static void fetch_bit_operand(struct decode_cache *c)
+{
+       long sv, mask;
+
+       if (c->dst.type == OP_MEM) {
+               mask = ~(c->dst.bytes * 8 - 1);
+
+               if (c->src.bytes == 2)
+                       sv = (s16)c->src.val & (s16)mask;
+               else if (c->src.bytes == 4)
+                       sv = (s32)c->src.val & (s32)mask;
+
+               c->dst.addr.mem += (sv >> 3);
+       }
+}
+
 static int read_emulated(struct x86_emulate_ctxt *ctxt,
                         struct x86_emulate_ops *ops,
                         unsigned long addr, void *dest, unsigned size)
@@ -2639,12 +2655,8 @@ done_prefixes:
                        c->dst.bytes = 8;
                else
                        c->dst.bytes = (c->d & ByteOp) ? 1 : c->op_bytes;
-               if (c->dst.type == OP_MEM && (c->d & BitOp)) {
-                       unsigned long mask = ~(c->dst.bytes * 8 - 1);
-
-                       c->dst.addr.mem = c->dst.addr.mem +
-                                                  (c->src.val & mask) / 8;
-               }
+               if (c->d & BitOp)
+                       fetch_bit_operand(c);
                c->dst.orig_val = c->dst.val;
                break;
        case DstAcc:
--
To unsubscribe from this list: send the line "unsubscribe kvm-commits" in
the body of a message to [email protected]
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Reply via email to