From nobody Sun Jul 26 10:07:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1783446845; cv=none; d=zohomail.com; s=zohoarc; b=CICskHbtvACSUzxT8ZMke+EdpMvo+jQy2TA4L2AsI9G8ZZhIlYTN8bs/3zN39JHHdK3zFt7WQbWr3Byn7EidpSQdW6kO5A6yi/7zZz841nBilJTua5/wjvu/z1dNWbdjeJBPeHSHdCF3FXkflS/pAzyTN+WkLC4rhJfQ5Vn+CMg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783446845; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=9bInZlgd1XssUUbcYAeUaJBWtvw/+u7OAaptk4l1twQ=; b=epxh7E5H2Xf2TGwBcVZ1TchXphiSOD3vw4ttHREkVOcukG5Yl/wTbsSY4otWeZVArs0zfa5A0oT0GInMCC/19xaVt8W2i6J7d7ijqLJZ/e55SrlSwh5F0vCa6gbePZzTvyk/EedL30ukeSk62iUihkwppzngGPRh/Vcfu18hZxg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783446845915936.6200097611099; Tue, 7 Jul 2026 10:54:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wh9x7-0006bh-7U; Tue, 07 Jul 2026 13:51:25 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wh9wP-0005qP-1d for qemu-devel@nongnu.org; Tue, 07 Jul 2026 13:50:41 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wh9wM-0001JK-58 for qemu-devel@nongnu.org; Tue, 07 Jul 2026 13:50:40 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-647-j-vdmoGYN-WIBjoM27JT7w-1; Tue, 07 Jul 2026 13:50:34 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 048AB195411F; Tue, 7 Jul 2026 17:50:33 +0000 (UTC) Received: from berrange.com (unknown [10.44.33.142]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 19F3236933; Tue, 7 Jul 2026 17:50:30 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1783446636; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=9bInZlgd1XssUUbcYAeUaJBWtvw/+u7OAaptk4l1twQ=; b=CR03bGQZpt9tiliTypH+FlwSyrxf2Fmvuq0W1Hd15bUnV6oR8TyfAlbA4EAYp1UvoJxG7U 8l9TMjJecBKDwb227U/tJvx92EOfT+lYg+zKLVmVie7DcJOEhpZnctn7zxFtqTYzTpvD44 EKz8DhmVs09BySkjd0U7nINIlphZPTY= X-MC-Unique: j-vdmoGYN-WIBjoM27JT7w-1 X-Mimecast-MFC-AGG-ID: j-vdmoGYN-WIBjoM27JT7w_1783446633 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , Pierrick Bouvier , yujun Subject: [PULL 1/4] crypto/x509-utils: fix gnutls error code in crt_init failure path Date: Tue, 7 Jul 2026 18:50:24 +0100 Message-ID: <20260707175027.3029620-2-berrange@redhat.com> In-Reply-To: <20260707175027.3029620-1-berrange@redhat.com> References: <20260707175027.3029620-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 8 X-Spam_score: 0.8 X-Spam_bar: / X-Spam_report: (0.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1783446847769158500 From: yujun qcrypto_get_x509_cert_fingerprint() reports gnutls_strerror(ret) when gnutls_x509_crt_init() fails, but ret is still the initial value -1. Store the gnutls return code before formatting the error, matching other gnutls call sites in the tree. Fixes: 2183ab6251 ("crypto/x509-utils: Check for error from gnutls_x509_crt= _init()") Signed-off-by: yujun Reviewed-by: Daniel P. Berrang=C3=A9 Signed-off-by: Daniel P. Berrang=C3=A9 --- crypto/x509-utils.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/crypto/x509-utils.c b/crypto/x509-utils.c index 39bb6d4d8c..1843488bca 100644 --- a/crypto/x509-utils.c +++ b/crypto/x509-utils.c @@ -46,7 +46,8 @@ int qcrypto_get_x509_cert_fingerprint(uint8_t *cert, size= _t size, return -1; } =20 - if (gnutls_x509_crt_init(&crt) < 0) { + ret =3D gnutls_x509_crt_init(&crt); + if (ret < 0) { error_setg(errp, "Unable to initialize certificate: %s", gnutls_strerror(ret)); return -1; --=20 2.55.0 From nobody Sun Jul 26 10:07:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1783446759; cv=none; d=zohomail.com; s=zohoarc; b=OSQ9sycf2l0xBdscEo1zmn7fwBYK+ZTkvRKXA2sWGf9VPF86DJqj+11BY2Y4G2al122PIGA9GvDMXJZqSyQQRYKmTdmYTG3yHgTTOPRl63KKbbdz2Vl2ke4nlMEwoQ+6SuddDQnXGttuYURfEbzfHDefRrbPqqnB/oDdj5UlyHs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783446759; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=23n61GrAfEGCfYIkBBlHO/krCWMAXXK+Kqwhuwne/cA=; b=CqCFDicHjSSuoaC/qZ95FAxM+XPdQBjkOf6P90OUNf6xi2338GxbV/pi3WGTcXWbGr8x/GQpyPR/0L9ig3regrlJeSMjXXuEyzBSDR9e1PhJcLa8nguGmtzMTB8SdDBkw4oQKJwNyrOIdkll7zSblrgXR102qgYDlpDlU8F0NXI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783446759594424.2975257394543; Tue, 7 Jul 2026 10:52:39 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wh9xG-0006ys-As; Tue, 07 Jul 2026 13:51:34 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wh9wX-00066D-3f for qemu-devel@nongnu.org; Tue, 07 Jul 2026 13:50:49 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wh9wV-0001Px-8u for qemu-devel@nongnu.org; Tue, 07 Jul 2026 13:50:48 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-619-EV69eHGQMWGi34BRhqaLUw-1; Tue, 07 Jul 2026 13:50:36 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 1C8011806CBE; Tue, 7 Jul 2026 17:50:35 +0000 (UTC) Received: from berrange.com (unknown [10.44.33.142]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 73A363692B; Tue, 7 Jul 2026 17:50:33 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1783446646; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=23n61GrAfEGCfYIkBBlHO/krCWMAXXK+Kqwhuwne/cA=; b=eIVv+cID0tCLF7rtx1dVl3Rcbx8di1XBTlWmwcpToITCVSpLT7xcvQacc/HbdVA7O5bgZ/ NC/LtdVwuzo+moj6UfOpNzP/oXZB4SBELlRIDTZRhVxytNd0Wc409X/C/gsB6wIlfNKLEA 9zfXoozBwJB27oZH69RTfCFgIDrx86o= X-MC-Unique: EV69eHGQMWGi34BRhqaLUw-1 X-Mimecast-MFC-AGG-ID: EV69eHGQMWGi34BRhqaLUw_1783446635 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , Pierrick Bouvier , Evgeny Kolmakov Subject: [PULL 2/4] util/filemonitor-inotify: Use QEMU_LOCK_GUARD() Date: Tue, 7 Jul 2026 18:50:25 +0100 Message-ID: <20260707175027.3029620-3-berrange@redhat.com> In-Reply-To: <20260707175027.3029620-1-berrange@redhat.com> References: <20260707175027.3029620-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -24 X-Spam_score: -2.5 X-Spam_bar: -- X-Spam_report: (-2.5 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1783446761336158500 From: Evgeny Kolmakov Replace manual qemu_mutex_(un)lock() calls with QEMU_LOCK_GUARD() to remove 'goto cleanup' code Signed-off-by: Evgeny Kolmakov Reviewed-by: Daniel P. Berrang=C3=A9 Signed-off-by: Daniel P. Berrang=C3=A9 --- util/filemonitor-inotify.c | 28 ++++++++-------------------- 1 file changed, 8 insertions(+), 20 deletions(-) diff --git a/util/filemonitor-inotify.c b/util/filemonitor-inotify.c index 7352b9fe53..fe2057f820 100644 --- a/util/filemonitor-inotify.c +++ b/util/filemonitor-inotify.c @@ -21,6 +21,7 @@ #include "qemu/osdep.h" #include "qemu/filemonitor.h" #include "qemu/main-loop.h" +#include "qemu/lockable.h" #include "qemu/error-report.h" #include "qapi/error.h" #include "trace.h" @@ -59,10 +60,9 @@ static void qemu_file_monitor_watch(void *arg) int used =3D 0; int len; =20 - qemu_mutex_lock(&mon->lock); + QEMU_LOCK_GUARD(&mon->lock); =20 if (mon->fd =3D=3D -1) { - qemu_mutex_unlock(&mon->lock); return; } =20 @@ -72,11 +72,10 @@ static void qemu_file_monitor_watch(void *arg) if (errno !=3D EAGAIN) { error_report("Failure monitoring inotify FD '%s'," "disabling events", strerror(errno)); - goto cleanup; } =20 /* no more events right now */ - goto cleanup; + return; } =20 /* Loop over all events in the buffer */ @@ -151,9 +150,6 @@ static void qemu_file_monitor_watch(void *arg) } } } - - cleanup: - qemu_mutex_unlock(&mon->lock); } =20 =20 @@ -257,9 +253,8 @@ qemu_file_monitor_add_watch(QFileMonitor *mon, { QFileMonitorDir *dir; QFileMonitorWatch watch; - int64_t ret =3D -1; =20 - qemu_mutex_lock(&mon->lock); + QEMU_LOCK_GUARD(&mon->lock); dir =3D g_hash_table_lookup(mon->dirs, dirpath); if (!dir) { int rv =3D inotify_add_watch(mon->fd, dirpath, @@ -268,7 +263,7 @@ qemu_file_monitor_add_watch(QFileMonitor *mon, =20 if (rv < 0) { error_setg_errno(errp, errno, "Unable to watch '%s'", dirpath); - goto cleanup; + return -1; } =20 trace_qemu_file_monitor_enable_watch(mon, dirpath, rv); @@ -297,11 +292,7 @@ qemu_file_monitor_add_watch(QFileMonitor *mon, filename ? filename : "", cb, opaque, watch.id); =20 - ret =3D watch.id; - - cleanup: - qemu_mutex_unlock(&mon->lock); - return ret; + return watch.id; } =20 =20 @@ -312,13 +303,13 @@ void qemu_file_monitor_remove_watch(QFileMonitor *mon, QFileMonitorDir *dir; gsize i; =20 - qemu_mutex_lock(&mon->lock); + QEMU_LOCK_GUARD(&mon->lock); =20 trace_qemu_file_monitor_remove_watch(mon, dirpath, id); =20 dir =3D g_hash_table_lookup(mon->dirs, dirpath); if (!dir) { - goto cleanup; + return; } =20 for (i =3D 0; i < dir->watches->len; i++) { @@ -342,7 +333,4 @@ void qemu_file_monitor_remove_watch(QFileMonitor *mon, qemu_set_fd_handler(mon->fd, NULL, NULL, NULL); } } - - cleanup: - qemu_mutex_unlock(&mon->lock); } --=20 2.55.0 From nobody Sun Jul 26 10:07:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1783446845; cv=none; d=zohomail.com; s=zohoarc; b=mJYR+6t8ijkkkcDUzHsdJKW1eF5okBprsTX+RYimr84RAYIrt/QcDR6a7ec7+qeU/1mR6AKkZmDgt1DAYW8mdNnr+wtlGEjf7zEHRtUI/0bK/WZgfwgNKPtkc0MF3LYdAp1shAZeSXqSJjSHuWecRAOEonGOv2ij53rob7QwJr0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783446845; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=rU5d0VbqexpaPUUC+IxxQyJPHnqRNZBfwNRtAC9/36U=; b=Wp5P4L59sWVqlw4L7SvZjArQSQS6CxYpEMM18l9NW7NLQ8iGOicq6XueYEeogR3HITI6gciy5zw1mJGYBFYnTCVB/SJ5RQeuSY3tcT+UCAgqmFqJjtKyLKwfsqQcfsB27WRqn2nqGThZ0bK12foq5oLc71RJvNEjq/47Pbpvm3I= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783446845915606.7949363729433; Tue, 7 Jul 2026 10:54:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wh9xP-00079O-Ro; Tue, 07 Jul 2026 13:51:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wh9wR-0005xx-Oe for qemu-devel@nongnu.org; Tue, 07 Jul 2026 13:50:43 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wh9wO-0001MM-QX for qemu-devel@nongnu.org; Tue, 07 Jul 2026 13:50:43 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-602-3gIdN707PP2KpjhsgkbXOw-1; Tue, 07 Jul 2026 13:50:38 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 108DE180895C; Tue, 7 Jul 2026 17:50:37 +0000 (UTC) Received: from berrange.com (unknown [10.44.33.142]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 819563692B; Tue, 7 Jul 2026 17:50:35 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1783446639; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=rU5d0VbqexpaPUUC+IxxQyJPHnqRNZBfwNRtAC9/36U=; b=TBnlKJljUJLk2SpJdfHv58Kb4bNLgy6OZGGq+uToYZHvJ0oSRg/LsBQjeNAxbOQfh7hrGO N/hIw45++HXsJL0GGcnctPRD1WJmQQiHJk+HCXLLIs7+Z1tosdY9qam4bU4pjeigGvc4tY Q8hTBvOcu9tJEiVry9b9Qv2P8Sug/4U= X-MC-Unique: 3gIdN707PP2KpjhsgkbXOw-1 X-Mimecast-MFC-AGG-ID: 3gIdN707PP2KpjhsgkbXOw_1783446637 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , Pierrick Bouvier , Peter Maydell Subject: [PULL 3/4] io/channel-socket: Document why we can ignore socket_set_cork() errors Date: Tue, 7 Jul 2026 18:50:26 +0100 Message-ID: <20260707175027.3029620-4-berrange@redhat.com> In-Reply-To: <20260707175027.3029620-1-berrange@redhat.com> References: <20260707175027.3029620-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -24 X-Spam_score: -2.5 X-Spam_bar: -- X-Spam_report: (-2.5 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1783446847522158500 From: Peter Maydell In qio_channel_socket_set_cork(), we call socket_set_cork() but ignore its success/failure return value. This is OK because we are implementing qio_channel_set_cork() here, and that function's API documentation states that the setting is merely a hint. So even if setting TCP_CORK on the underlying socket fails for some reason, this isn't going to be a problem for the caller; correspondingly the qio_channel_set_cork() function has no error return. Add a comment in qio_channel_socket_set_cork() explaining why we don't check for errors. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/2254 Signed-off-by: Peter Maydell Reviewed-by: Daniel P. Berrang=C3=A9 Signed-off-by: Daniel P. Berrang=C3=A9 --- io/channel-socket.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/io/channel-socket.c b/io/channel-socket.c index ea2ec84108..12773b832c 100644 --- a/io/channel-socket.c +++ b/io/channel-socket.c @@ -946,6 +946,12 @@ qio_channel_socket_set_cork(QIOChannel *ioc, QIOChannelSocket *sioc =3D QIO_CHANNEL_SOCKET(ioc); int v =3D enabled ? 1 : 0; =20 + /* + * We can ignore the error return from socket_set_cork() because + * at the QIO API level set_cork is only a hint, and so + * qio_channel_set_cork() can never fail even if it didn't + * actually do anything. + */ socket_set_cork(sioc->fd, v); } =20 --=20 2.55.0 From nobody Sun Jul 26 10:07:34 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1783446759; cv=none; d=zohomail.com; s=zohoarc; b=j9oY0R1lCV84UL8jryFHi8kI8pGhX/ZYAYc28T1DnRpWF+cb/NQr1bCm9Y6LRDKCcNnswE+hFbRZJJVjS+LN9OwzvuasDIkw2/hTwiB1xW+G+PYH/L7V6UE6PgBZP62tBQX81Xi7xxw3z5jtBuk6z+TaEEx2JVUa781wFlPPLK8= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783446759; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=XdVTva91bwLGqqzohpnP/TPz/kRPi9v0JlFPYmELZg0=; b=A0Bl6ZHvLGFJ6A4AgidbPypMZEMKym/owYnabP3Uj2Wvbocx9ad0QKJFWh6jwIBOSiuxhpRc3cuLBnICb6tHl/Q9ySPip3pbtK8qdKFD0RLHZuvE085djQzljRtXLovSY7v1S+ibQ1lDlD/mLHsogBZ+LK8hFbmS4YS6ytQnkgU= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783446759702520.425952185786; Tue, 7 Jul 2026 10:52:39 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wh9xF-0006xD-60; Tue, 07 Jul 2026 13:51:33 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wh9wV-000636-9H for qemu-devel@nongnu.org; Tue, 07 Jul 2026 13:50:47 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wh9wT-0001OV-Ij for qemu-devel@nongnu.org; Tue, 07 Jul 2026 13:50:47 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-135-ua2GnAByNE6leebZzbEniw-1; Tue, 07 Jul 2026 13:50:41 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 88EE419540E5; Tue, 7 Jul 2026 17:50:40 +0000 (UTC) Received: from berrange.com (unknown [10.44.33.142]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id D61E33692F; Tue, 7 Jul 2026 17:50:37 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1783446644; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=XdVTva91bwLGqqzohpnP/TPz/kRPi9v0JlFPYmELZg0=; b=Hn4VpIJ5fJEgIlpr3iVzVmfRjYrwGsqU6VeZdCFPaXbthoxBJaNu8u/wzSwDfisaOAM0fg phApTHbVqVhDoZzr06sx7eSOtoyccTTn2w2LDPOjRiW8xWjgmcnPWCrXWw4W5RhbpUnqw4 nnJ+fTT59EhzZNBCPWaIyGRJHsm2jJg= X-MC-Unique: ua2GnAByNE6leebZzbEniw-1 X-Mimecast-MFC-AGG-ID: ua2GnAByNE6leebZzbEniw_1783446640 From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , Pierrick Bouvier , Thomas Huth , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , "Michael S. Tsirkin" , Mauro Matteo Cascella Subject: [PULL 4/4] docs: outline some guidelines for security classification Date: Tue, 7 Jul 2026 18:50:27 +0100 Message-ID: <20260707175027.3029620-5-berrange@redhat.com> In-Reply-To: <20260707175027.3029620-1-berrange@redhat.com> References: <20260707175027.3029620-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 8 X-Spam_score: 0.8 X-Spam_bar: / X-Spam_report: (0.8 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.445, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1783446761703158500 Beyond the overall virt/non-virt use case classification, there are a number of scenarios which we have decided will not be treated as security issues. Start to document some of these to give consistency in our treatment of incoming disclosures. Reviewed-by: Thomas Huth Reviewed-by: C=C3=A9dric Le Goater Acked-by: Michael S. Tsirkin Reviewed-by: Mauro Matteo Cascella Signed-off-by: Daniel P. Berrang=C3=A9 --- docs/system/security.rst | 63 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 63 insertions(+) diff --git a/docs/system/security.rst b/docs/system/security.rst index 53992048e6..52bbf0cc7a 100644 --- a/docs/system/security.rst +++ b/docs/system/security.rst @@ -75,6 +75,69 @@ Bugs affecting the non-virtualization use case are not c= onsidered security bugs at this time. Users with non-virtualization use cases must not rely = on QEMU to provide guest isolation or any security guarantees. =20 +Security boundary scope +''''''''''''''''''''''' + +Even where a flaw affects the virtualization use case described above, +not all scenarios will be considered in scope. The following guidelines +are used to evaluate whether to apply the full security process, or treat +an issue as a normal bug. + +* **assert** / **abort**. If triggering the code path requires kernel + privileges (or root account access) in the guest, asserts/aborts in + QEMU are a self inflicted denial of service. These will **not** be + treated as security flaws, at most hardening bugs. If triggering the + code path can be done by an unprivileged guest OS account, this + **may** justify handling as a security bug. + +* **vhost-user/vfio-user backends**. The backend processes have + shared memory regions co-mapped with the QEMU process. The intent + of the process separation is operational resilience & flexibility + and allowing for independent software suppliers. There is not + considered to be security boundary between QEMU and the vhost-user + & vfio-user backends. Thus flaws in the backends which can cause + crashes / undesirable behaviour in QEMU will **not** be treated as + security flaws, but should be fixed as hardening bugs. + +* **memory allocation bounds**. There are many ways in which a QEMU + process can legitimately consume an amount of memory that is + significantly larger than the assigned guest RAM. QEMU's worst + case memory usage should be considered effectively unbounded. As + such the QEMU deployment on the host should account for the + possibility of large memory peaks and apply countermeasures to + provide continuity of host operations. It is typical for the Linux + OOM killer to reap the process triggering host memory overcommit + in the case of exccessive usage, offering a degree of protection. + As such, bugs which can lead to excessive/unbounded memory allocations + will usually not be classified as security flaws, but should be + fixed as hardening bugs. + +* **degraded guest behaviour**. There are a set of bugs which can + lead guest hardware devices to misbehave. For example, a flawed + virtual IOMMU operation may not offer the guest device isolation + that would otherwise be expected. If a guest triggered exploit + requires kernel privileges (or root account access), and leads + to sub-optimal behaviour of the virtual device this is considered + a self inflicted service degradation. These will **not** be + treated as security flaws, at most hardening bugs. If triggering + the code path can be done by an unprivileged guest OS account, + this may justify handling as a security bug. + +* **nested virtualization**. The scope for nested virtualization + is to prevent a level 2 guest from breaking out into a level + 1 guest. As noted above, a number of scenarios exclude security + handling for flaws only exploitable by the guest kernel / root + account with affect the guest's own service/availability. In the + context of nested virtualization with PCI device assignment, it + may may be possible for a level 2 guest kernel to trigger flaws + that affect the level 0 QEMU process. While these bugs should be + fixed, they will not be triaged as security flaws at this time. + +* **low severity impact**. As a catch all rule, issues which + are judged to have a "low" severity impact on the system will + usually not justify handling as security bugs, nor assignment + of CVEs. They will be fixed as routine bugs when time allows. + Architecture ------------ =20 --=20 2.55.0