[PATCH] accel/mshv: Fix pointer to proc feature bitfield

Magnus Kulke posted 1 patch 3 weeks, 3 days ago
Patches applied successfully (tree, apply log)
git fetch https://github.com/patchew-project/qemu tags/patchew/20260701130335.418156-1-magnuskulke@linux.microsoft.com
Maintainers: Magnus Kulke <magnuskulke@linux.microsoft.com>, Wei Liu <wei.liu@kernel.org>, "Doru Blânzeanu" <dblanzeanu@linux.microsoft.com>
accel/mshv/mshv-all.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
[PATCH] accel/mshv: Fix pointer to proc feature bitfield
Posted by Magnus Kulke 3 weeks, 3 days ago
Processor features are stored in a union containing two "banks":

union hv_partition_processor_features {
    uint64_t as_uint[2];
    struct {
        uint64_t sse3_support:1;
        ...
    }
}

get_proc_features() to retrieve the 2nd bank was passing a pointer that
steps over the whole union (+16B) instead of picking the 2nd bank _in_
the union. This manifests in mismatching feature bits for the 2nd bank
and possibly other side-effects caused by writing beyond the union.

We need to step over the first bank (+8B) by using as_uint64[0/1] to
correct this behaviour.

Fixes: 2f6da91e8a ("accel/mshv: store partition proc features")
Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
---
 accel/mshv/mshv-all.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/accel/mshv/mshv-all.c b/accel/mshv/mshv-all.c
index 9452504ac2..c8b7f10294 100644
--- a/accel/mshv/mshv-all.c
+++ b/accel/mshv/mshv-all.c
@@ -167,7 +167,7 @@ static int get_proc_features(int vm_fd,
 
     ret = get_partition_property(vm_fd,
                                  HV_PARTITION_PROPERTY_PROCESSOR_FEATURES0,
-                                 features[0].as_uint64);
+                                 &features->as_uint64[0]);
     if (ret < 0) {
         error_report("Failed to get processor features bank 0");
         return -1;
@@ -175,7 +175,7 @@ static int get_proc_features(int vm_fd,
 
     ret = get_partition_property(vm_fd,
                                  HV_PARTITION_PROPERTY_PROCESSOR_FEATURES1,
-                                 features[1].as_uint64);
+                                 &features->as_uint64[1]);
     if (ret < 0) {
         error_report("Failed to get processor features bank 1");
         return -1;
-- 
2.34.1
Re: [PATCH] accel/mshv: Fix pointer to proc feature bitfield
Posted by Philippe Mathieu-Daudé 2 weeks, 6 days ago
On 1/7/26 15:03, Magnus Kulke wrote:
> Processor features are stored in a union containing two "banks":
> 
> union hv_partition_processor_features {
>      uint64_t as_uint[2];
>      struct {
>          uint64_t sse3_support:1;
>          ...
>      }
> }
> 
> get_proc_features() to retrieve the 2nd bank was passing a pointer that
> steps over the whole union (+16B) instead of picking the 2nd bank _in_
> the union. This manifests in mismatching feature bits for the 2nd bank
> and possibly other side-effects caused by writing beyond the union.
> 
> We need to step over the first bank (+8B) by using as_uint64[0/1] to
> correct this behaviour.
> 
> Fixes: 2f6da91e8a ("accel/mshv: store partition proc features")
> Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
> ---
>   accel/mshv/mshv-all.c | 4 ++--
>   1 file changed, 2 insertions(+), 2 deletions(-)

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>

Re: [PATCH] accel/mshv: Fix pointer to proc feature bitfield
Posted by Doru Blânzeanu 3 weeks, 2 days ago
On Wed, Jul 01, 2026 at 03:03:35PM +0200, Magnus Kulke wrote:
> Processor features are stored in a union containing two "banks":
> 
> union hv_partition_processor_features {
>     uint64_t as_uint[2];
>     struct {
>         uint64_t sse3_support:1;
>         ...
>     }
> }
> 
> get_proc_features() to retrieve the 2nd bank was passing a pointer that
> steps over the whole union (+16B) instead of picking the 2nd bank _in_
> the union. This manifests in mismatching feature bits for the 2nd bank
> and possibly other side-effects caused by writing beyond the union.
> 
> We need to step over the first bank (+8B) by using as_uint64[0/1] to
> correct this behaviour.
> 
> Fixes: 2f6da91e8a ("accel/mshv: store partition proc features")
> Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>
> ---
>  accel/mshv/mshv-all.c | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)
> 
> diff --git a/accel/mshv/mshv-all.c b/accel/mshv/mshv-all.c
> index 9452504ac2..c8b7f10294 100644
> --- a/accel/mshv/mshv-all.c
> +++ b/accel/mshv/mshv-all.c
> @@ -167,7 +167,7 @@ static int get_proc_features(int vm_fd,
>  
>      ret = get_partition_property(vm_fd,
>                                   HV_PARTITION_PROPERTY_PROCESSOR_FEATURES0,
> -                                 features[0].as_uint64);
> +                                 &features->as_uint64[0]);
>      if (ret < 0) {
>          error_report("Failed to get processor features bank 0");
>          return -1;
> @@ -175,7 +175,7 @@ static int get_proc_features(int vm_fd,
>  
>      ret = get_partition_property(vm_fd,
>                                   HV_PARTITION_PROPERTY_PROCESSOR_FEATURES1,
> -                                 features[1].as_uint64);
> +                                 &features->as_uint64[1]);
>      if (ret < 0) {
>          error_report("Failed to get processor features bank 1");
>          return -1;
> -- 
> 2.34.1

Reviewed-by: Doru Blânzeanu <dblanzeanu@linux.microsoft.com>
Re: [PATCH] accel/mshv: Fix pointer to proc feature bitfield
Posted by Peter Maydell 3 weeks, 3 days ago
On Wed, 1 Jul 2026 at 14:03, Magnus Kulke
<magnuskulke@linux.microsoft.com> wrote:
>
> Processor features are stored in a union containing two "banks":
>
> union hv_partition_processor_features {
>     uint64_t as_uint[2];
>     struct {
>         uint64_t sse3_support:1;
>         ...
>     }
> }
>
> get_proc_features() to retrieve the 2nd bank was passing a pointer that
> steps over the whole union (+16B) instead of picking the 2nd bank _in_
> the union. This manifests in mismatching feature bits for the 2nd bank
> and possibly other side-effects caused by writing beyond the union.
>
> We need to step over the first bank (+8B) by using as_uint64[0/1] to
> correct this behaviour.
>
> Fixes: 2f6da91e8a ("accel/mshv: store partition proc features")
> Signed-off-by: Magnus Kulke <magnuskulke@linux.microsoft.com>

Reviewed-by: Peter Maydell <peter.maydell@linaro.org>

thanks
-- PMM