From nobody Sun Jul 26 12:31:36 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=none dis=none) header.from=intel.com ARC-Seal: i=1; a=rsa-sha256; t=1781750570; cv=none; d=zohomail.com; s=zohoarc; b=i84rUcwQDJl4RDKMOQY0w9vo5eIo2frRlPlOatB69SD0Yebgb6VNmT9yYd+CK6vQzQ8JLjfJ06f37xo/+Yum5UpWqh79wPGz2o8w2fqqFvNaOoGRmhGGUcGDOrPXXyjH3W3oozC2yRww08Fm0aQvoqmTLPlGz+zRa+RP9+17xNk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781750570; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Haq/JFeAnLoTmdwlAFxZ+GcdlNwTrRznUJl2kqLDQdo=; b=HPry45MG4r5h6+ULDgqXRFsfdyOyTOXOrsZJHoGlFcVdwQ/IyNCs2CXcYqsng6G+xFlc1Ahvm4jiHDJG6SApqaEenUe9TN0xfkcITndVOavQPoVqz/MUk+t8CP5Y1ozjvqN4bo8GuFD4TStPW4Wa4u6sHjc4GMVqMzxiRuoJ/eU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass header.i=@intel.com; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=none dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781750570274627.5766700766483; Wed, 17 Jun 2026 19:42:50 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wa2hX-0003BP-Ue; Wed, 17 Jun 2026 22:41:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wa2hV-0003AT-8M; Wed, 17 Jun 2026 22:41:53 -0400 Received: from mgamail.intel.com ([192.198.163.9]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wa2hR-0002aC-82; Wed, 17 Jun 2026 22:41:52 -0400 Received: from fmviesa007.fm.intel.com ([10.60.135.147]) by fmvoesa103.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 17 Jun 2026 19:41:45 -0700 Received: from junjie-optiplex-micro-plus-7010.bj.intel.com ([10.238.152.98]) by fmviesa007-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 17 Jun 2026 19:41:43 -0700 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1781750509; x=1813286509; h=from:to:cc:subject:date:message-id:mime-version: content-transfer-encoding; bh=YrwcpQ0WvBz/1+z3tCzmFwH0nCWHbcXLoQuFZ9YQf+Y=; b=XpkMHSTgZ6DZHQSTVD57iarsv+9tM3IsNOBR0AOLg7aTQHjyUo9K6K7a rkY+BLwTQdJk7sun627eL1aNjHJXGSDiYvcubv5zOPRrCxBiK0RlnrC+c VXTxPtSOKDyfGuG/TNdd4l4SWYaFKsAeM7fulISOYNsIX0nGn1lUHxe4/ 796iKDwKiFm71eOZ1OVhDypKIlZwNoX3JAf3mwRQiakiLu4TNVCkHhLp5 Zbiwq15g8dZ42sr6NtkwtZHKM4X4MStSZ4U+5LUmxmbwx7wp/SZJF2gg/ 6DyfRZxvlGQqMSmOtLVJOjOn29J//1N+PnIb0Z45uMNIVkOZx9lfGUpOB Q==; X-CSE-ConnectionGUID: 9G+J9P1qQpSHJKP7xwaaUw== X-CSE-MsgGUID: vg9FeIwGRASWt8Ivceshew== X-IronPort-AV: E=McAfee;i="6800,10657,11820"; a="93229261" X-IronPort-AV: E=Sophos;i="6.24,210,1774335600"; d="scan'208";a="93229261" X-CSE-ConnectionGUID: U2DXYIQjTNO4ofBf2UTmfQ== X-CSE-MsgGUID: SF09PBIgR5OaK1yi3UvOuA== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.24,210,1774335600"; d="scan'208";a="245302087" From: Junjie Cao To: Jonathan Cameron Cc: "Michael S . Tsirkin" , qemu-devel@nongnu.org, qemu-stable@nongnu.org, linux-cxl@vger.kernel.org, Junjie Cao Subject: [PATCH] hw/cxl: Fix guest-triggerable QEMU exit on reserved interleave ways Date: Thu, 18 Jun 2026 18:43:16 +0800 Message-ID: <20260618104316.557306-1-junjie.cao@intel.com> X-Mailer: git-send-email 2.43.0 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=192.198.163.9; envelope-from=junjie.cao@intel.com; helo=mgamail.intel.com X-Spam_score_int: -28 X-Spam_score: -2.9 X-Spam_bar: -- X-Spam_report: (-2.9 / 5.0 requ) BAYES_00=-1.9, DATE_IN_FUTURE_06_12=1.947, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @intel.com) X-ZM-MESSAGEID: 1781750575392158500 Content-Type: text/plain; charset="utf-8" A buggy or malicious guest can program a committed HDM decoder with a reserved Interleave Ways encoding (e.g. 0x5-0x7, 0xb-0xf). Two call sites pass &error_fatal to cxl_interleave_ways_dec(), which calls exit(1) on the reserved encoding before the subsequent decoded_iw =3D=3D 0 guards can run: - cxl-host.c update_non_interleaved(): called at commit time from hdm_decoder_commit() via cfmws_update_non_interleaved(), so a guest writing COMMIT with a reserved IW terminates QEMU immediately. This is the primary trigger on the current tree. - cxl_type3.c cxl_type3_dpa(): called on memory access while iterating past committed decoders to accumulate dpa_base. Once the commit-time exit is removed, the decoder stays committed with the reserved encoding, so a later guest access outside that decoder's range would otherwise hit this second &error_fatal; both are fixed here. Pass NULL instead of &error_fatal at both sites so that the reserved encoding returns zero and the existing guards handle it gracefully. This can be reproduced by writing the HDM Decoder 0 Control register with a reserved IW encoding and the COMMIT bit set (e.g. IW=3D0x5, COMMIT=3D1). Cc: qemu-stable@nongnu.org Fixes: 680935c9a6ff ("hw/cxl: Add a performant (and correct) path for the n= on interleaved cases") Fixes: 48461825af1b ("hw/mem/cxl_type3: Fix potential divide by zero report= ed by coverity") Signed-off-by: Junjie Cao --- hw/cxl/cxl-host.c | 2 +- hw/mem/cxl_type3.c | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/hw/cxl/cxl-host.c b/hw/cxl/cxl-host.c index 7e744312f1..768fdadc29 100644 --- a/hw/cxl/cxl-host.c +++ b/hw/cxl/cxl-host.c @@ -442,7 +442,7 @@ static int update_non_interleaved(Object *obj, void *op= aque) } } =20 - interleave_ways_dec =3D cxl_interleave_ways_dec(iw, &error_fatal); + interleave_ways_dec =3D cxl_interleave_ways_dec(iw, NULL); if (interleave_ways_dec =3D=3D 0) { return 0; } diff --git a/hw/mem/cxl_type3.c b/hw/mem/cxl_type3.c index cba05ec57d..102afa1a19 100644 --- a/hw/mem/cxl_type3.c +++ b/hw/mem/cxl_type3.c @@ -1197,7 +1197,7 @@ static bool cxl_type3_dpa(CXLType3Dev *ct3d, hwaddr h= ost_addr, uint64_t *dpa) } if (((uint64_t)host_addr < decoder_base) || (hpa_offset >=3D decoder_size)) { - int decoded_iw =3D cxl_interleave_ways_dec(iw, &error_fatal); + int decoded_iw =3D cxl_interleave_ways_dec(iw, NULL); =20 if (decoded_iw =3D=3D 0) { return false; --=20 2.43.0