From nobody Sun Feb 8 12:51:46 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=google.com ARC-Seal: i=1; a=rsa-sha256; t=1625177654; cv=none; d=zohomail.com; s=zohoarc; b=Q4yDrB2X+kANf46Pi38rNMTJwyZ5PxQpHBqZWj8Qs+PIL6rO8ijVfzb6Hgq6WOekjB9UO0o9gVYZ5gByx291SU2Iw/NHcJgcjcJGkouL5dtY0VYbGhsaeWbmx9yLpUgC6ehpro7hX/XF0n8Ajm8wswPbNBkLGPdrB9rAtXUJNBw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1625177654; h=Content-Type:Cc:Date:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:To; bh=m71lZzRC7hVmf2lDz/jDXE9saDRisXowlTsGw5b6gZk=; b=NTYZWaxaCnCCODC/8gXeVL7gb0M4zKTxIVh71adkYaUSBt9QY69M4tylbbVIa6lk8imff2OzCrKxS98AaOVdgGGEHG3eLLkh5Ls9JDRfwWlNKE1E3ixCLqbKGlxWyjVpZEbthO9qCIYtpFS6rIkFZZtCNJbbMjF8IeVElhae4iA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1625177654869956.621686955744; Thu, 1 Jul 2021 15:14:14 -0700 (PDT) Received: from localhost ([::1]:38670 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1lz4wn-0006rL-Nc for importer@patchew.org; Thu, 01 Jul 2021 18:14:13 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:57848) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <36z3eYAgKCuwcObRSfgcUccUZS.QcaeSai-RSjSZbcbUbi.cfU@flex--oanderso.bounces.google.com>) id 1lz4vf-0005n3-Qr for qemu-devel@nongnu.org; Thu, 01 Jul 2021 18:13:03 -0400 Received: from mail-pg1-x54a.google.com ([2607:f8b0:4864:20::54a]:41617) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from <36z3eYAgKCuwcObRSfgcUccUZS.QcaeSai-RSjSZbcbUbi.cfU@flex--oanderso.bounces.google.com>) id 1lz4vd-00006m-Ug for qemu-devel@nongnu.org; Thu, 01 Jul 2021 18:13:03 -0400 Received: by mail-pg1-x54a.google.com with SMTP id o9-20020a6561490000b0290226fc371410so5044777pgv.8 for ; Thu, 01 Jul 2021 15:13:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=date:message-id:mime-version:subject:from:to:cc; bh=m71lZzRC7hVmf2lDz/jDXE9saDRisXowlTsGw5b6gZk=; b=dgbffJon6jEyH4mES8JcLY/8Zhg5jHFL+PZAknZZiM+lKLKet0lzRBoCziDYgzYlDY IVBl/cok0qY986c9MsZDMSLnBCDwr4sOhEsXkyHxYF7xm80vP1HrN0xAwFLXjqk7KWz+ 0+uQfBwKXrmjiV4H1wqAhIneva0bjCBJAkcoDcnF+rYX1jYbblHTXBFT0XiojLjvDCWx oE3Q7+i8XAN38bMbg7FN0Bw0B2fD6b+6UdvF934nOdFaSALWZqcU0uNb8cqhbh1Q8k1W OMPlklMZwwYdY+X8j+7Pu7LAndnn4s+EG3zjezdJKogVckxdkVh6ymd1V2LATCBcx9Up WEEg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:date:message-id:mime-version:subject:from:to:cc; bh=m71lZzRC7hVmf2lDz/jDXE9saDRisXowlTsGw5b6gZk=; b=k4w5/eFBWbNmf6R8KylkI6oRkSx+gk5lGAr7liwFipH95MpZbdjtZrBF5JJgwW+UVR tIy+Eh38c8IDT4g9RHKKFecXEZD5JdOfjF98B5KYc5M+MMkZcXmL6x4GPopaFXUiA5SI FQclenhFzCTTo2ctOA/uZXA7UgtYrT9+RnzsdZe512pxP4nuFkk2IlEef6YDttYTJtXm Od3MEBLiVry9F56M/H8sENGKHW7zknzpbKk1CCS9+0ZoM5hdimGbmOhtoNr3KDiQS3O5 DksNBeU7RigRJDVL/n4xg/yfxzd5DzssAzHtH86IUHwoD1gjGV1ebBffi52uYQMsifPA YStQ== X-Gm-Message-State: AOAM530WuK4TG/Ppge9Ci/nctNjBnNK9cCdbi+ZZaiQ1ZmQbJIyD1hTs DyxLRMyVQ1fCJZ+/KVKJ0un5oc6+SBFjhg== X-Google-Smtp-Source: ABdhPJxMwk00SEswXc5O1LReMv+Dk0dRmQuG0tZ83XEqUvecu1blkU8is0YHRri68JUJucMKPkVpqJV2tZT0Ow== X-Received: from oanderso-specialist.c.googlers.com ([fda3:e722:ac3:cc00:7f:e700:c0a8:7ff5]) (user=oanderso job=sendgmr) by 2002:a17:90a:a393:: with SMTP id x19mr158217pjp.1.1625177579207; Thu, 01 Jul 2021 15:12:59 -0700 (PDT) Date: Thu, 1 Jul 2021 22:12:55 +0000 Message-Id: <20210701221255.107976-1-oanderso@google.com> Mime-Version: 1.0 X-Mailer: git-send-email 2.32.0.93.g670b81a890-goog Subject: [PATCH] fd-trans: Fix race condition on reallocation of the translation table. From: Owen Anderson To: Laurent Vivier Cc: qemu-devel@nongnu.org, Owen Anderson Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=2607:f8b0:4864:20::54a; envelope-from=36z3eYAgKCuwcObRSfgcUccUZS.QcaeSai-RSjSZbcbUbi.cfU@flex--oanderso.bounces.google.com; helo=mail-pg1-x54a.google.com X-Spam_score_int: -96 X-Spam_score: -9.7 X-Spam_bar: --------- X-Spam_report: (-9.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_MED=-0.056, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, USER_IN_DEF_DKIM_WL=-7.5 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail-DKIM: pass (identity @google.com) Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The mapping from file-descriptors to translator functions is not guarded on realloc which may cause invalid function pointers to be read from a previously deallocated mapping. Signed-off-by: Owen Anderson Reviewed-by: Laurent Vivier --- linux-user/fd-trans.c | 1 + linux-user/fd-trans.h | 55 +++++++++++++++++++++++++++++++++++++------ linux-user/main.c | 3 +++ 3 files changed, 52 insertions(+), 7 deletions(-) diff --git a/linux-user/fd-trans.c b/linux-user/fd-trans.c index 23adaca836..86b6f484d3 100644 --- a/linux-user/fd-trans.c +++ b/linux-user/fd-trans.c @@ -267,6 +267,7 @@ enum { }; =20 TargetFdTrans **target_fd_trans; +QemuMutex target_fd_trans_lock; unsigned int target_fd_max; =20 static void tswap_nlmsghdr(struct nlmsghdr *nlh) diff --git a/linux-user/fd-trans.h b/linux-user/fd-trans.h index a3fcdaabc7..1b9fa2041c 100644 --- a/linux-user/fd-trans.h +++ b/linux-user/fd-trans.h @@ -16,6 +16,8 @@ #ifndef FD_TRANS_H #define FD_TRANS_H =20 +#include "qemu/lockable.h" + typedef abi_long (*TargetFdDataFunc)(void *, size_t); typedef abi_long (*TargetFdAddrFunc)(void *, abi_ulong, socklen_t); typedef struct TargetFdTrans { @@ -25,12 +27,23 @@ typedef struct TargetFdTrans { } TargetFdTrans; =20 extern TargetFdTrans **target_fd_trans; +extern QemuMutex target_fd_trans_lock; =20 extern unsigned int target_fd_max; =20 +static inline void fd_trans_init(void) +{ + qemu_mutex_init(&target_fd_trans_lock); +} + static inline TargetFdDataFunc fd_trans_target_to_host_data(int fd) { - if (fd >=3D 0 && fd < target_fd_max && target_fd_trans[fd]) { + if (fd < 0) { + return NULL; + } + + QEMU_LOCK_GUARD(&target_fd_trans_lock); + if (fd < target_fd_max && target_fd_trans[fd]) { return target_fd_trans[fd]->target_to_host_data; } return NULL; @@ -38,7 +51,12 @@ static inline TargetFdDataFunc fd_trans_target_to_host_d= ata(int fd) =20 static inline TargetFdDataFunc fd_trans_host_to_target_data(int fd) { - if (fd >=3D 0 && fd < target_fd_max && target_fd_trans[fd]) { + if (fd < 0) { + return NULL; + } + + QEMU_LOCK_GUARD(&target_fd_trans_lock); + if (fd < target_fd_max && target_fd_trans[fd]) { return target_fd_trans[fd]->host_to_target_data; } return NULL; @@ -46,13 +64,19 @@ static inline TargetFdDataFunc fd_trans_host_to_target_= data(int fd) =20 static inline TargetFdAddrFunc fd_trans_target_to_host_addr(int fd) { - if (fd >=3D 0 && fd < target_fd_max && target_fd_trans[fd]) { + if (fd < 0) { + return NULL; + } + + QEMU_LOCK_GUARD(&target_fd_trans_lock); + if (fd < target_fd_max && target_fd_trans[fd]) { return target_fd_trans[fd]->target_to_host_addr; } return NULL; } =20 -static inline void fd_trans_register(int fd, TargetFdTrans *trans) +static inline void internal_fd_trans_register_unsafe(int fd, + TargetFdTrans *trans) { unsigned int oldmax; =20 @@ -67,18 +91,35 @@ static inline void fd_trans_register(int fd, TargetFdTr= ans *trans) target_fd_trans[fd] =3D trans; } =20 -static inline void fd_trans_unregister(int fd) +static inline void fd_trans_register(int fd, TargetFdTrans *trans) +{ + QEMU_LOCK_GUARD(&target_fd_trans_lock); + internal_fd_trans_register_unsafe(fd, trans); +} + +static inline void internal_fd_trans_unregister_unsafe(int fd) { if (fd >=3D 0 && fd < target_fd_max) { target_fd_trans[fd] =3D NULL; } } =20 +static inline void fd_trans_unregister(int fd) +{ + if (fd < 0) { + return; + } + + QEMU_LOCK_GUARD(&target_fd_trans_lock); + internal_fd_trans_unregister_unsafe(fd); +} + static inline void fd_trans_dup(int oldfd, int newfd) { - fd_trans_unregister(newfd); + QEMU_LOCK_GUARD(&target_fd_trans_lock); + internal_fd_trans_unregister_unsafe(newfd); if (oldfd < target_fd_max && target_fd_trans[oldfd]) { - fd_trans_register(newfd, target_fd_trans[oldfd]); + internal_fd_trans_register_unsafe(newfd, target_fd_trans[oldfd]); } } =20 diff --git a/linux-user/main.c b/linux-user/main.c index 2fb3a366a6..37ed50d98e 100644 --- a/linux-user/main.c +++ b/linux-user/main.c @@ -48,6 +48,7 @@ #include "target_elf.h" #include "cpu_loop-common.h" #include "crypto/init.h" +#include "fd-trans.h" =20 #ifndef AT_FLAGS_PRESERVE_ARGV0 #define AT_FLAGS_PRESERVE_ARGV0_BIT 0 @@ -829,6 +830,8 @@ int main(int argc, char **argv, char **envp) cpu->opaque =3D ts; task_settid(ts); =20 + fd_trans_init(); + ret =3D loader_exec(execfd, exec_path, target_argv, target_environ, re= gs, info, &bprm); if (ret !=3D 0) { --=20 2.32.0.93.g670b81a890-goog