From nobody Mon Aug 24 19:00:44 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org ARC-Seal: i=1; a=rsa-sha256; t=1779487090; cv=none; d=zohomail.com; s=zohoarc; b=Tb3OLE4PzrzjvyteBWrip0JeTKUGdNaiU8hFZgdpqMlqwuiX73ynfjtupiu59L8nDpxH50gQVTme2SzjNc00qOODk0t/gG4FL+1vt9fx05a5iZ+u8plb0x989kwWJxfa6AtXg0cme6lBtH5XkUPJg6V763kHhYso0BC6TD9Ft+M= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1779487090; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=/gjeleHI2nIgUpMj4dRaF/V68uFm7zbzwwP1XXU2pcg=; b=Bk2L+SbzlKvi9YOJRSifiK18XKI/fHyxtFuRqwyI2ovmakgjOUQLc3S3ZGDc2HEvv0F4+khw9pSYojlurtT1Nc/A4a1Vou+WEjxj+Hn3uiy1aOLFtofWDbKCQy9ZTjl1wt3c9Rp92f/sOEchqKYxpguTIBdYRjRkyO4Qdnscncg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1779487090917736.6264115668624; Fri, 22 May 2026 14:58:10 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wQXmy-00045X-If; Fri, 22 May 2026 17:52:16 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wQXmi-0002rj-74; Fri, 22 May 2026 17:52:00 -0400 Received: from isrv.corpit.ru ([212.248.84.144]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wQXmf-0004FH-NL; Fri, 22 May 2026 17:51:59 -0400 Received: from tsrv.corpit.ru (tsrv.tls.msk.ru [192.168.177.2]) by isrv.corpit.ru (Postfix) with ESMTP id 180071AFB78; Sat, 23 May 2026 00:49:21 +0300 (MSK) Received: from think4mjt.tls.msk.ru (mjtthink.wg.tls.msk.ru [192.168.177.146]) by tsrv.corpit.ru (Postfix) with ESMTP id 3CF823B71C7; Sat, 23 May 2026 00:49:25 +0300 (MSK) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tls.msk.ru; s=202602; t=1779486561; bh=p6pAbECg2KacMKKyb2n/g/X3bm43YbGdZyTLDTpukU4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=uvPGKfOwKa9ssoZmJ5idOGBdx4h15Xgpa/FCnaTfAp3CooH93ug0JpCxy3u5pSUcp SULs+P8RaZi2tHbh/PxWp3TXJvgkDJ5mx/Ppz0A3Ifh60UJA8UKDP14kDP5jFep7/6 l2WNNz48sv0Jo+8m5M90UqbD+A9yYmQ3YFPQ+qEZRi9UeKF3YtX+4XobVTD3e7FtQs HvH8aopRWf/6RGC2ZxnENl///6e+1gCsiGLfsXNStPo8xoRVoWP7g7Cqk881c+u0dM bZ6vExzSH8z7CjhOksnjSar8tOL6TrCA2xmQ94W1nD3WpRxsgIbttk8RnhpQCupJFB 5UI7vK4l72Bmw== From: Michael Tokarev To: qemu-devel@nongnu.org Cc: qemu-stable@nongnu.org, Peter Maydell , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , Richard Henderson , Pierrick Bouvier , Michael Tokarev Subject: [Stable-10.2.3 130/149] meson.build: Add -fzero-init-padding-bits=all Date: Sat, 23 May 2026 00:49:02 +0300 Message-ID: <20260522214923.807017-31-mjt@tls.msk.ru> X-Mailer: git-send-email 2.47.3 In-Reply-To: References: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=212.248.84.144; envelope-from=mjt@tls.msk.ru; helo=isrv.corpit.ru X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @tls.msk.ru) X-ZM-MESSAGEID: 1779487092958154100 From: Peter Maydell The C standard doesn't always guarantee that struct and union padding bits are zero initialized, even if the code initializes a struct. For QEMU, this is potentially problematic, because we often have structs that match data structures in guest memory, where we initialize them and then bulk copy them into the guest. If the compiler didn't zero init the whole of the memory containing the struct, we could potentially leak random data from the host into the guest via the padding bytes. We already use -ftrivial-auto-var-init=3Dzero, which will zero out padding in many of these cases, but -fzero-init-padding-bits=3Dall closes some gaps, for example cases where we initialize a variable with a struct initializer, and cases involving unions. Follow the Linux kernel in using both options. Compare kernel commit dce4aab8441 ("kbuild: Use -fzero-init-padding-bits=3Dall"). This option exists in gcc-15 and above; it's not supported by clang, but clang documents that it guarantees zero init of these cases always: https://clang.llvm.org/docs/LanguageExtensions.html#union-and-aggregate-ini= tialization-in-c Older gcc which don't have the option behave as if it were set. (These options are passed through the cc.get_supported_arguments() filter, so we don't need to do anything extra to avoid passing it to a compiler that doesn't recognize it.) Cc: qemu-stable@nongnu.org Signed-off-by: Peter Maydell Reviewed-by: Daniel P. Berrang=C3=A9 Reviewed-by: Richard Henderson Reviewed-by: Pierrick Bouvier Message-id: 20260508104723.2144051-1-peter.maydell@linaro.org (cherry picked from commit a163fc1f864bef27f6e527cbad9defba7af9e60a) Signed-off-by: Michael Tokarev diff --git a/meson.build b/meson.build index 5ba29bc07d..7ae0d109ab 100644 --- a/meson.build +++ b/meson.build @@ -703,6 +703,12 @@ hardening_flags =3D [ # it harder to take advantage of uninitialized stack # data to drive exploits '-ftrivial-auto-var-init=3Dzero', + # Ensure GCC zero-initializes padding bits and trailing fields in + # unions. This avoids potentially leaking host data into the guest + # when we init a struct and copy it into guest memory. GCC prior + # to GCC 15 and clang don't have this, but they zero the padding + # and trailing portions of a union by default. + '-fzero-init-padding-bits=3Dall', ] =20 # Zero out registers used during a function call --=20 2.47.3