]> git.ipfire.org Git - thirdparty/qemu.git/commitdiff
hw/sd/sdcard: Fix error case for CMD18
authorBernhard Beschow <shentey@gmail.com>
Mon, 20 Jul 2026 20:11:32 +0000 (22:11 +0200)
committerPhilippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Tue, 21 Jul 2026 10:38:44 +0000 (12:38 +0200)
In commit 468fa450a7e0 ("hw/sd: Switch read/write primitive to
buf+len"), `sd_read_byte()` changed its contract to return the read size
rather than the read value (and was renamed to `sd_read_data()`
accordingly). In an error case, however, `sd_read_data()` returns 0 by
means of `dummy_byte` which is the code for the old contract. Moreover,
`sdbus_read_data()` asserts the virtual method `read_data()` (and thus
`sd_read_data()`) to return a non-zero size, i.e. to make progress and
not loop forever. Fix the code to behave like the "DAT read illegal for
command" case.

Fixes: 468fa450a7e0 ("hw/sd: Switch read/write primitive to buf+len")
Reviewed-by: Bin Meng <bin.meng@processmission.com>
Signed-off-by: Bernhard Beschow <shentey@gmail.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Message-ID: <20260720201133.24796-2-shentey@gmail.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
hw/sd/sd.c

index 336075700431f8fe0e224768358ffe8961859615..a30c541df07280423853236dd1145d2b179be00f 100644 (file)
@@ -2860,7 +2860,8 @@ static size_t sd_read_data(SDState *sd, void *buf, size_t length)
         if (sd->data_offset == 0) {
             if (!address_in_range(sd, "READ_MULTIPLE_BLOCK",
                                   sd->data_start, io_len)) {
-                return dummy_byte;
+                *value = dummy_byte;
+                return length;
             }
             partition_access = sd->ext_csd[EXT_CSD_PART_CONFIG]
                     & EXT_CSD_PART_CONFIG_ACC_MASK;