Handle GET_EVENT_STATUS_NOTIFICATION's No Event Available status in its own function.
Also ensure the buffer the driver sent us is big enough to fill in all the data we have -- else just fill in as much as the buffer can hold. Signed-off-by: Amit Shah <amit.s...@redhat.com> --- hw/ide/core.c | 42 ++++++++++++++++++++++++++++++++++++------ 1 files changed, 36 insertions(+), 6 deletions(-) diff --git a/hw/ide/core.c b/hw/ide/core.c index c4a5a13..730587e 100644 --- a/hw/ide/core.c +++ b/hw/ide/core.c @@ -1084,14 +1084,45 @@ static int ide_dvd_read_structure(IDEState *s, int format, } } +static unsigned int event_status_nea(uint8_t *buf, unsigned int max_len) +{ + unsigned int used_len; + + /* + * Ensure we don't write on memory we don't have. + * max_len of 0 should not produce an error as well. + */ + used_len = 0; + + /* No event descriptor returned */ + if (max_len > 0) { + buf[0] = 0; + used_len++; + } + if (max_len > 1) { + buf[1] = 0; + used_len++; + } + if (max_len > 2) { + buf[2] = 0x80; /* No Event Available (NEA) */ + used_len++; + } + if (max_len > 3) { + buf[3] = 0x00; /* Empty supported event classes */ + used_len++; + } + return used_len; +} + static void handle_get_event_status_notification(IDEState *s, uint8_t *buf, const uint8_t *packet) { - unsigned int max_len; + unsigned int max_len, used_len; max_len = ube16_to_cpu(packet + 7); + /* It is fine by the MMC spec to not support async mode operations */ if (!(packet[1] & 0x01)) { /* asynchronous mode */ /* Only polling is supported, asynchronous mode is not. */ ide_atapi_cmd_error(s, SENSE_ILLEGAL_REQUEST, @@ -1099,12 +1130,11 @@ static void handle_get_event_status_notification(IDEState *s, return; } - /* polling */ + /* polling mode operation */ + /* We don't support any event class (yet). */ - cpu_to_ube16(buf, 0x00); /* No event descriptor returned */ - buf[2] = 0x80; /* No Event Available (NEA) */ - buf[3] = 0x00; /* Empty supported event classes */ - ide_atapi_cmd_reply(s, 4, max_len); + used_len = event_status_nea(buf, max_len); + ide_atapi_cmd_reply(s, used_len, max_len); } static void ide_atapi_cmd(IDEState *s) -- 1.7.4.2