From nobody Sun Jul 26 13:27:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1781690996; cv=none; d=zohomail.com; s=zohoarc; b=gxA0/8/ZqkPEHG9iEqqJhYtURKD4jEUfm6/f92HNuRvFS8BybG7JpMB1LNk8be3bFMr0uiHX3owhYqIN7TAjPT2ELT/p6EXHHV16nXcOLv3tzYc3rzaI/D4X3rBwjRUne7xb2vo/IMzCw5R4yhXW6/HH+1cl00aG3ehKcyN7Qco= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781690996; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=V/90ixfnl8wIZ3LWZu/M7JTJ4C9O2Yr0AMWhPtzx12o=; b=L9VXMqQo4ADAPmUK/3eFXSe1HYr9+KUpeEbnebGMSOST3fh0Z3bwraPyfL/fZ7biZoIP6MPuv7tkV6hoEa38/9RrXsZ0InyYRrf82drS7xQEO81Jhl8sBXo78LTmFTkxq3J9vEZyMkE6BhNwcKaEt7fmlJU+xlX9kvIKPi92rhk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781690996536838.8015871767954; Wed, 17 Jun 2026 03:09:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wZnDA-0006km-8X; Wed, 17 Jun 2026 06:09:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wZnD7-0006kG-Ps for qemu-devel@nongnu.org; Wed, 17 Jun 2026 06:09:29 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wZnD6-0000Ur-CM for qemu-devel@nongnu.org; Wed, 17 Jun 2026 06:09:29 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-59-0g0V1KYXN5KPjWxWr0y3NA-1; Wed, 17 Jun 2026 06:09:25 -0400 Received: from mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.93]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 7FAD81805A0D; Wed, 17 Jun 2026 10:09:24 +0000 (UTC) Received: from sirius.home.kraxel.org (unknown [10.44.48.13]) by mx-prod-int-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id E56641800599; Wed, 17 Jun 2026 10:09:23 +0000 (UTC) Received: by sirius.home.kraxel.org (Postfix, from userid 1000) id DB0C31801A82; Wed, 17 Jun 2026 12:09:22 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1781690966; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=V/90ixfnl8wIZ3LWZu/M7JTJ4C9O2Yr0AMWhPtzx12o=; b=HKIDTDm3qpQTx5h5o6BDfnkZZiNJLbEZFLjxNy13RZEsOY2Ft/cHIHMJBGQcTH2jQP3Duo dxExQxEM2/4nbNsaPHQyv/oOdo80n9zfaxWLoIiAHbNmfxJjU+Uwj0eQojneZOzWk/V893 VbWco0SRVbXfiYHpo4VDsRyQibw2g8k= X-MC-Unique: 0g0V1KYXN5KPjWxWr0y3NA-1 X-Mimecast-MFC-AGG-ID: 0g0V1KYXN5KPjWxWr0y3NA_1781690964 From: Gerd Hoffmann To: qemu-devel@nongnu.org Cc: Stefano Garzarella , Ani Sinha , Gerd Hoffmann , Feifan Qian , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PULL 1/3] hw/uefi: fix parse_hexstr Date: Wed, 17 Jun 2026 12:09:20 +0200 Message-ID: <20260617100922.1302000-2-kraxel@redhat.com> In-Reply-To: <20260617100922.1302000-1-kraxel@redhat.com> References: <20260617100922.1302000-1-kraxel@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.93 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=kraxel@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -24 X-Spam_score: -2.5 X-Spam_bar: -- X-Spam_report: (-2.5 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1781690996928158500 Make sure we actually have two input characters available before going to parse two hex digits. Fixes one byte buffer overflow of the output buffer in case the input string has an odd number of characters. Fixes: CVE-2026-48915 Fixes: 12058948abdf ("hw/uefi: add var-service-json.c + qapi for NV vars.") Reported-by: Feifan Qian Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: Gerd Hoffmann Message-ID: <20260526135948.599148-1-kraxel@redhat.com> --- hw/uefi/var-service-json.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hw/uefi/var-service-json.c b/hw/uefi/var-service-json.c index f5f155683334..8621b86c5c5f 100644 --- a/hw/uefi/var-service-json.c +++ b/hw/uefi/var-service-json.c @@ -98,7 +98,7 @@ static void parse_hexstr(void *dest, char *src, int len) uint8_t *data =3D dest; size_t i; =20 - for (i =3D 0; i < len; i +=3D 2) { + for (i =3D 0; i + 1 < len; i +=3D 2) { *(data++) =3D parse_hexchar(src[i]) << 4 | parse_hexchar(src[i + 1]); --=20 2.54.0 From nobody Sun Jul 26 13:27:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1781690992; cv=none; d=zohomail.com; s=zohoarc; b=AAM/vp/nX75SmNhhea7cc0F+r+XavnWOPUuuZL9t/hj2FPtzIKlU8B0UZsSRL0vMZyEyJ/J8zQfcMPZOdyQzKadeUg43twOXYF7F1oP5WOxGFOqBfv5aJEfB82S0iN5S+ribHlrF55SEZ2QjrJdMp7n5OHZNguHDWjbN7q6F1lA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781690992; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Dbx41Y72VzFLQNCt4JmQgUHw7W4y3x2CCAIVw+avYl4=; b=NbBvA+YwGF+O5EH6c3twJFVSK7VyhknLY+B0AlBAvT6hFHY0yI2r250C5Ei+GFJajqG1Oo3L6KQhH6c6/h3PEjILOipM7C5lN0yxVYQqxrSUxqfVszwYvy6gt8eXVL6SvN9qgWIuPuFA+XqHVglXhQJ79pEA3RHvY2/URziBp3Q= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781690992932694.5987125345737; Wed, 17 Jun 2026 03:09:52 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wZnDD-0006nI-DU; Wed, 17 Jun 2026 06:09:35 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wZnDB-0006lH-NR for qemu-devel@nongnu.org; Wed, 17 Jun 2026 06:09:33 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wZnDA-0000Wr-1B for qemu-devel@nongnu.org; Wed, 17 Jun 2026 06:09:33 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-533-zsvnjRSJPU2tFY1QHOnzFg-1; Wed, 17 Jun 2026 06:09:27 -0400 Received: from mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.111]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 7BF12180AB37; Wed, 17 Jun 2026 10:09:26 +0000 (UTC) Received: from sirius.home.kraxel.org (unknown [10.44.48.13]) by mx-prod-int-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 8D595180049F; Wed, 17 Jun 2026 10:09:25 +0000 (UTC) Received: by sirius.home.kraxel.org (Postfix, from userid 1000) id EA7E81801A83; Wed, 17 Jun 2026 12:09:22 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1781690971; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Dbx41Y72VzFLQNCt4JmQgUHw7W4y3x2CCAIVw+avYl4=; b=TdWJvrP9m4loMd73J38LcVT4K1JnMJqR9ceJPisQZ9yZtdxHrosfb2t6u3Py7hIfc23jQT uws/dlinH84g0lEAdOZO+YBqiJnLmiq3iy7DvQQtbgAAgRQQXP2PmJgZAcULSITZORgZY3 BTaTDSjxMqSy4E0QgQifS+c/dCgvtYY= X-MC-Unique: zsvnjRSJPU2tFY1QHOnzFg-1 X-Mimecast-MFC-AGG-ID: zsvnjRSJPU2tFY1QHOnzFg_1781690966 From: Gerd Hoffmann To: qemu-devel@nongnu.org Cc: Stefano Garzarella , Ani Sinha , Gerd Hoffmann , Luigi Leonardi , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PULL 2/3] igvm: replace raw uint32_t with igvm library types Date: Wed, 17 Jun 2026 12:09:21 +0200 Message-ID: <20260617100922.1302000-3-kraxel@redhat.com> In-Reply-To: <20260617100922.1302000-1-kraxel@redhat.com> References: <20260617100922.1302000-1-kraxel@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.111 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=kraxel@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -24 X-Spam_score: -2.5 X-Spam_bar: -- X-Spam_report: (-2.5 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1781690994961158500 From: Luigi Leonardi Use IgvmVariableHeaderType and IgvmHeaderSection in QIGVMHandler and qigvm_handler() instead of plain uint32_t, so that each field's purpose is clear from its type. Reviewed-by: Stefano Garzarella Reviewed-by: Ani Sinha Signed-off-by: Luigi Leonardi Reviewed-by: Philippe Mathieu-Daud=C3=A9 Message-ID: <20260609-igvm_optional-v2-1-b1f1f08dc40e@redhat.com> Signed-off-by: Gerd Hoffmann --- backends/igvm.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/backends/igvm.c b/backends/igvm.c index 9b889f04287e..3ccbafe9b90c 100644 --- a/backends/igvm.c +++ b/backends/igvm.c @@ -102,8 +102,8 @@ static int qigvm_initialization_guest_policy(QIgvm *ctx, Error **errp); =20 struct QIGVMHandler { - uint32_t type; - uint32_t section; + IgvmVariableHeaderType type; + IgvmHeaderSection section; int (*handler)(QIgvm *ctx, const uint8_t *header_data, Error **errp); }; =20 @@ -132,7 +132,7 @@ static struct QIGVMHandler handlers[] =3D { qigvm_directive_madt }, }; =20 -static int qigvm_handler(QIgvm *ctx, uint32_t type, Error **errp) +static int qigvm_handler(QIgvm *ctx, IgvmVariableHeaderType type, Error **= errp) { size_t handler; IgvmHandle header_handle; --=20 2.54.0 From nobody Sun Jul 26 13:27:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1781690978; cv=none; d=zohomail.com; s=zohoarc; b=O3ngbk6TNmvZNlr8CBZcKeVZskx79FsmFPPfIKZ4qGyvB88jUZjr5+W0b08u0GPUceR2fAFRzvP8MKPkO2fJSwmx9S3v+qMO+l4ThZYqjT7JUZ4JRJzT6nVXpzb7P38flQ5OZB+J0DUKOmUpMgqjmd7lV7rcPgVVNdz0YWCxoWk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781690978; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=WDHK55odBvgL5WNEiMm6wKtzzsfWxmYvXH0NGMhmUvw=; b=IqTG5BhdN81gOGRXjSnfauj/PGkUieHgrEV1NMroX/YKocnN8Ky1K6733Y/JWnHCUUscCpcVxgxChjB9HycV80t5alGmNZH5xOZvFQrjXHdUFB5+ksTwBkUTbbiFBBNC1wqNawLoty17dqRWvVIq7774gOVoVAfv12kBcr38Sc4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781690978429992.242528665993; Wed, 17 Jun 2026 03:09:38 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wZnDC-0006lg-Ri; Wed, 17 Jun 2026 06:09:34 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wZnDB-0006lF-Jf for qemu-devel@nongnu.org; Wed, 17 Jun 2026 06:09:33 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wZnD9-0000Wb-Qn for qemu-devel@nongnu.org; Wed, 17 Jun 2026 06:09:33 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-316-PhPWYVRcMsWCYkIiSS-TFA-1; Wed, 17 Jun 2026 06:09:28 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 52910195E90A for ; Wed, 17 Jun 2026 10:09:26 +0000 (UTC) Received: from sirius.home.kraxel.org (unknown [10.44.48.13]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id B45283189; Wed, 17 Jun 2026 10:09:25 +0000 (UTC) Received: by sirius.home.kraxel.org (Postfix, from userid 1000) id 0DDB21801A85; Wed, 17 Jun 2026 12:09:23 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1781690970; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=WDHK55odBvgL5WNEiMm6wKtzzsfWxmYvXH0NGMhmUvw=; b=PAhmdzjxJNIEYB4OXUI63VfnPMa3Civbs+gTWa9AYBRTFlh8prQHRj9V7DpLlqE5UaKfRR M3LOMr2sw939YN8GxXf/YICAQ2pegKiXdP9nTO6C/ukvH7kIgIx9OQeskUT5HILpgq4Q5U wtFHTVJAtWLGRBVDwSpqEQUyMGqbD0A= X-MC-Unique: PhPWYVRcMsWCYkIiSS-TFA-1 X-Mimecast-MFC-AGG-ID: PhPWYVRcMsWCYkIiSS-TFA_1781690966 From: Gerd Hoffmann To: qemu-devel@nongnu.org Cc: Stefano Garzarella , Ani Sinha , Gerd Hoffmann , Luigi Leonardi Subject: [PULL 3/3] igvm: fix handling of optional variable header types Date: Wed, 17 Jun 2026 12:09:22 +0200 Message-ID: <20260617100922.1302000-4-kraxel@redhat.com> In-Reply-To: <20260617100922.1302000-1-kraxel@redhat.com> References: <20260617100922.1302000-1-kraxel@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=kraxel@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 8 X-Spam_score: 0.8 X-Spam_bar: / X-Spam_report: (0.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1781690978857158500 Content-Type: text/plain; charset="utf-8" From: Luigi Leonardi The IGVM spec defines bit 31 of the variable header type as an optional flag: if set, a loader that does not recognize the header type may safely skip it. If clear, the loader must reject the file. Currently, the optional bit is not stripped before comparing header types, so headers with the bit set fail to match any known type and are rejected. Mask bit 31 before comparing header types throughout the IGVM loader, and skip with a warning any unrecognized header that has the optional bit set. Fixes: c1d466d267cf ("backends/igvm: Add IGVM loader and configuration") Signed-off-by: Luigi Leonardi Message-ID: <20260609-igvm_optional-v2-2-b1f1f08dc40e@redhat.com> Signed-off-by: Gerd Hoffmann --- backends/igvm.c | 37 +++++++++++++++++++++++++++++++++---- 1 file changed, 33 insertions(+), 4 deletions(-) diff --git a/backends/igvm.c b/backends/igvm.c index 3ccbafe9b90c..3f4b97a5d417 100644 --- a/backends/igvm.c +++ b/backends/igvm.c @@ -26,6 +26,25 @@ #include #include =20 +#ifndef IGVM_VHT_OPTIONAL_BIT +#define IGVM_VHT_OPTIONAL_BIT (1U << 31) +#endif + +/* + * Bit 31 of the variable header type indicates that the header is + * optional and can be safely ignored by a loader that does not + * support it. If the bit is clear, the file cannot be loaded. + * https://docs.rs/igvm_defs/0.4.0/igvm_defs/struct.IgvmVariableHeaderType= .html + */ +static IgvmVariableHeaderType igvm_vht_type(IgvmVariableHeaderType type) +{ + return type & ~IGVM_VHT_OPTIONAL_BIT; +} + +static bool igvm_vht_optional(IgvmVariableHeaderType type) +{ + return !!(type & IGVM_VHT_OPTIONAL_BIT); +} =20 /* * Some directives are specific to particular confidential computing platf= orms. @@ -132,12 +151,14 @@ static struct QIGVMHandler handlers[] =3D { qigvm_directive_madt }, }; =20 -static int qigvm_handler(QIgvm *ctx, IgvmVariableHeaderType type, Error **= errp) +static int qigvm_handler(QIgvm *ctx, IgvmVariableHeaderType raw_type, + Error **errp) { size_t handler; IgvmHandle header_handle; const uint8_t *header_data; int result; + IgvmVariableHeaderType type =3D igvm_vht_type(raw_type); =20 for (handler =3D 0; handler < G_N_ELEMENTS(handlers); handler++) { if (handlers[handler].type !=3D type) { @@ -166,6 +187,13 @@ static int qigvm_handler(QIgvm *ctx, IgvmVariableHeade= rType type, Error **errp) igvm_free_buffer(ctx->file, header_handle); return result; } + + if (igvm_vht_optional(raw_type)) { + warn_report("IGVM: Skipping unsupported optional header type 0x%" + PRIX32, type); + return 0; + } + error_setg(errp, "IGVM: Unknown header type encountered when processing file= : " "(type 0x%X)", @@ -787,6 +815,7 @@ static int qigvm_supported_platform_compat_mask(QIgvm *= ctx, Error **errp) header_index++) { IgvmVariableHeaderType typ =3D igvm_get_header_type( ctx->file, IGVM_HEADER_SECTION_PLATFORM, header_index); + typ =3D igvm_vht_type(typ); if (typ =3D=3D IGVM_VHT_SUPPORTED_PLATFORM) { header_handle =3D igvm_get_header( ctx->file, IGVM_HEADER_SECTION_PLATFORM, header_index); @@ -945,10 +974,10 @@ int qigvm_process_file(IgvmCfg *cfg, MachineState *ma= chine_state, for (ctx.current_header_index =3D 0; ctx.current_header_index < (unsigned)header_count; ctx.current_header_index++) { - IgvmVariableHeaderType type =3D igvm_get_header_type( + IgvmVariableHeaderType raw_type =3D igvm_get_header_type( ctx.file, IGVM_HEADER_SECTION_DIRECTIVE, ctx.current_header_in= dex); - if (!onlyVpContext || (type =3D=3D IGVM_VHT_VP_CONTEXT)) { - if (qigvm_handler(&ctx, type, errp) < 0) { + if (!onlyVpContext || igvm_vht_type(raw_type) =3D=3D IGVM_VHT_VP_C= ONTEXT) { + if (qigvm_handler(&ctx, raw_type, errp) < 0) { goto cleanup_parameters; } } --=20 2.54.0