[PATCH] tests/tcg: fix buffer overflow in multiarch/linux/linux-sigrtminmax

Max Filippov posted 1 patch 2 weeks, 3 days ago
Patches applied successfully (tree, apply log)
git fetch https://github.com/patchew-project/qemu tags/patchew/20260708150541.2137546-1-jcmvbkbc@gmail.com
Maintainers: "Alex Bennée" <alex.bennee@linaro.org>
tests/tcg/multiarch/linux/linux-sigrtminmax.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
[PATCH] tests/tcg: fix buffer overflow in multiarch/linux/linux-sigrtminmax
Posted by Max Filippov 2 weeks, 3 days ago
Fix new_argv allocation size to be `(argc + 2) * sizeof(char *)` bytes,
which matches the way it's used to store `argc + 2` pointers.

This fixes the test for me, which otherwise fails on xtensa with the
following message

  linux-sigrtminmax.c: 59: main: Assertion `execve(new_argv[0], new_argv, environ) == 0' failed.'.

Signed-off-by: Max Filippov <jcmvbkbc@gmail.com>
---
 tests/tcg/multiarch/linux/linux-sigrtminmax.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/tests/tcg/multiarch/linux/linux-sigrtminmax.c b/tests/tcg/multiarch/linux/linux-sigrtminmax.c
index a7059aacd9cb..b5ea65f3d393 100644
--- a/tests/tcg/multiarch/linux/linux-sigrtminmax.c
+++ b/tests/tcg/multiarch/linux/linux-sigrtminmax.c
@@ -39,7 +39,7 @@ int main(int argc, char **argv)
     assert(qemu);
 
     if (!getenv("QEMU_RTSIG_MAP")) {
-        char **new_argv = malloc((argc + 2) + sizeof(char *));
+        char **new_argv = malloc((argc + 2) * sizeof(char *));
         int tsig1, hsig1, count1, tsig2, hsig2, count2;
         char rt_sigmap[64];
 
-- 
2.47.3
Re: [PATCH] tests/tcg: fix buffer overflow in multiarch/linux/linux-sigrtminmax
Posted by Markus Armbruster 2 weeks, 3 days ago
Max Filippov <jcmvbkbc@gmail.com> writes:

> Fix new_argv allocation size to be `(argc + 2) * sizeof(char *)` bytes,
> which matches the way it's used to store `argc + 2` pointers.
>
> This fixes the test for me, which otherwise fails on xtensa with the
> following message
>
>   linux-sigrtminmax.c: 59: main: Assertion `execve(new_argv[0], new_argv, environ) == 0' failed.'.
>
> Signed-off-by: Max Filippov <jcmvbkbc@gmail.com>
> ---
>  tests/tcg/multiarch/linux/linux-sigrtminmax.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/tests/tcg/multiarch/linux/linux-sigrtminmax.c b/tests/tcg/multiarch/linux/linux-sigrtminmax.c
> index a7059aacd9cb..b5ea65f3d393 100644
> --- a/tests/tcg/multiarch/linux/linux-sigrtminmax.c
> +++ b/tests/tcg/multiarch/linux/linux-sigrtminmax.c
> @@ -39,7 +39,7 @@ int main(int argc, char **argv)
>      assert(qemu);
>  
>      if (!getenv("QEMU_RTSIG_MAP")) {
> -        char **new_argv = malloc((argc + 2) + sizeof(char *));
> +        char **new_argv = malloc((argc + 2) * sizeof(char *));

If you can switch to glib's malloc, then g_new(argc + 2, sizeof(char *))
is better.  Yes, @argc can't become big enough for the multiplication to
overflow, but g_new() removes the need for reasoning.

>          int tsig1, hsig1, count1, tsig2, hsig2, count2;
>          char rt_sigmap[64];
Re: [PATCH] tests/tcg: fix buffer overflow in multiarch/linux/linux-sigrtminmax
Posted by Alex Bennée 2 weeks, 3 days ago
Markus Armbruster <armbru@redhat.com> writes:

> Max Filippov <jcmvbkbc@gmail.com> writes:
>
>> Fix new_argv allocation size to be `(argc + 2) * sizeof(char *)` bytes,
>> which matches the way it's used to store `argc + 2` pointers.
>>
>> This fixes the test for me, which otherwise fails on xtensa with the
>> following message
>>
>>   linux-sigrtminmax.c: 59: main: Assertion `execve(new_argv[0], new_argv, environ) == 0' failed.'.
>>
>> Signed-off-by: Max Filippov <jcmvbkbc@gmail.com>
>> ---
>>  tests/tcg/multiarch/linux/linux-sigrtminmax.c | 2 +-
>>  1 file changed, 1 insertion(+), 1 deletion(-)
>>
>> diff --git a/tests/tcg/multiarch/linux/linux-sigrtminmax.c b/tests/tcg/multiarch/linux/linux-sigrtminmax.c
>> index a7059aacd9cb..b5ea65f3d393 100644
>> --- a/tests/tcg/multiarch/linux/linux-sigrtminmax.c
>> +++ b/tests/tcg/multiarch/linux/linux-sigrtminmax.c
>> @@ -39,7 +39,7 @@ int main(int argc, char **argv)
>>      assert(qemu);
>>  
>>      if (!getenv("QEMU_RTSIG_MAP")) {
>> -        char **new_argv = malloc((argc + 2) + sizeof(char *));
>> +        char **new_argv = malloc((argc + 2) * sizeof(char *));
>
> If you can switch to glib's malloc, then g_new(argc + 2, sizeof(char *))
> is better.  Yes, @argc can't become big enough for the multiplication to
> overflow, but g_new() removes the need for reasoning.

Not for TCG test cases - we are limited to plain old glibc.

>
>>          int tsig1, hsig1, count1, tsig2, hsig2, count2;
>>          char rt_sigmap[64];

-- 
Alex Bennée
Virtualisation Tech Lead @ Linaro
Re: [PATCH] tests/tcg: fix buffer overflow in multiarch/linux/linux-sigrtminmax
Posted by Daniel P. Berrangé 2 weeks, 3 days ago
On Thu, Jul 09, 2026 at 10:56:09AM +0200, Markus Armbruster wrote:
> Max Filippov <jcmvbkbc@gmail.com> writes:
> 
> > Fix new_argv allocation size to be `(argc + 2) * sizeof(char *)` bytes,
> > which matches the way it's used to store `argc + 2` pointers.
> >
> > This fixes the test for me, which otherwise fails on xtensa with the
> > following message
> >
> >   linux-sigrtminmax.c: 59: main: Assertion `execve(new_argv[0], new_argv, environ) == 0' failed.'.
> >
> > Signed-off-by: Max Filippov <jcmvbkbc@gmail.com>
> > ---
> >  tests/tcg/multiarch/linux/linux-sigrtminmax.c | 2 +-
> >  1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/tests/tcg/multiarch/linux/linux-sigrtminmax.c b/tests/tcg/multiarch/linux/linux-sigrtminmax.c
> > index a7059aacd9cb..b5ea65f3d393 100644
> > --- a/tests/tcg/multiarch/linux/linux-sigrtminmax.c
> > +++ b/tests/tcg/multiarch/linux/linux-sigrtminmax.c
> > @@ -39,7 +39,7 @@ int main(int argc, char **argv)
> >      assert(qemu);
> >  
> >      if (!getenv("QEMU_RTSIG_MAP")) {
> > -        char **new_argv = malloc((argc + 2) + sizeof(char *));
> > +        char **new_argv = malloc((argc + 2) * sizeof(char *));
> 
> If you can switch to glib's malloc, then g_new(argc + 2, sizeof(char *))
> is better.  Yes, @argc can't become big enough for the multiplication to
> overflow, but g_new() removes the need for reasoning.

The TCG unit tests don't link to GLib, only basic libc.

Fortunately unit tests have a trusted caller (the QEMU
meson build system), so we don't have to worry about
malicious usage with overflow in this context.

> 
> >          int tsig1, hsig1, count1, tsig2, hsig2, count2;
> >          char rt_sigmap[64];
> 
> 

With regards,
Daniel
-- 
|: https://berrange.com       ~~        https://hachyderm.io/@berrange :|
|: https://libvirt.org          ~~          https://entangle-photo.org :|
|: https://pixelfed.art/berrange   ~~    https://fstop138.berrange.com :|
Re: [PATCH] tests/tcg: fix buffer overflow in multiarch/linux/linux-sigrtminmax
Posted by Ilya Leoshkevich 2 weeks, 3 days ago

On 7/8/26 17:05, Max Filippov wrote:
> Fix new_argv allocation size to be `(argc + 2) * sizeof(char *)` bytes,
> which matches the way it's used to store `argc + 2` pointers.
> 
> This fixes the test for me, which otherwise fails on xtensa with the
> following message
> 
>    linux-sigrtminmax.c: 59: main: Assertion `execve(new_argv[0], new_argv, environ) == 0' failed.'.
> 
> Signed-off-by: Max Filippov <jcmvbkbc@gmail.com>
> ---
>   tests/tcg/multiarch/linux/linux-sigrtminmax.c | 2 +-
>   1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/tests/tcg/multiarch/linux/linux-sigrtminmax.c b/tests/tcg/multiarch/linux/linux-sigrtminmax.c
> index a7059aacd9cb..b5ea65f3d393 100644
> --- a/tests/tcg/multiarch/linux/linux-sigrtminmax.c
> +++ b/tests/tcg/multiarch/linux/linux-sigrtminmax.c
> @@ -39,7 +39,7 @@ int main(int argc, char **argv)
>       assert(qemu);
>   
>       if (!getenv("QEMU_RTSIG_MAP")) {
> -        char **new_argv = malloc((argc + 2) + sizeof(char *));
> +        char **new_argv = malloc((argc + 2) * sizeof(char *));
>           int tsig1, hsig1, count1, tsig2, hsig2, count2;
>           char rt_sigmap[64];
>   

Whoops, a silly typo on my part.
Thanks for taking the time to fix it!

Reviewed-by: Ilya Leoshkevich <iii@linux.ibm.com>
Re: [PATCH] tests/tcg: fix buffer overflow in multiarch/linux/linux-sigrtminmax
Posted by Philippe Mathieu-Daudé 2 weeks, 3 days ago
On 8/7/26 17:05, Max Filippov wrote:
> Fix new_argv allocation size to be `(argc + 2) * sizeof(char *)` bytes,
> which matches the way it's used to store `argc + 2` pointers.
> 
> This fixes the test for me, which otherwise fails on xtensa with the
> following message
> 
>    linux-sigrtminmax.c: 59: main: Assertion `execve(new_argv[0], new_argv, environ) == 0' failed.'.
> 
> Signed-off-by: Max Filippov <jcmvbkbc@gmail.com>
> ---
>   tests/tcg/multiarch/linux/linux-sigrtminmax.c | 2 +-
>   1 file changed, 1 insertion(+), 1 deletion(-)

Fixes: 6f58b090328 ("tests/tcg: Add SIGRTMIN/SIGRTMAX test")
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>

Re: [PATCH] tests/tcg: fix buffer overflow in multiarch/linux/linux-sigrtminmax
Posted by Richard Henderson 2 weeks, 3 days ago
On 7/8/26 08:05, Max Filippov wrote:
> Fix new_argv allocation size to be `(argc + 2) * sizeof(char *)` bytes,
> which matches the way it's used to store `argc + 2` pointers.
> 
> This fixes the test for me, which otherwise fails on xtensa with the
> following message
> 
>    linux-sigrtminmax.c: 59: main: Assertion `execve(new_argv[0], new_argv, environ) == 0' failed.'.
> 
> Signed-off-by: Max Filippov <jcmvbkbc@gmail.com>
> ---
>   tests/tcg/multiarch/linux/linux-sigrtminmax.c | 2 +-
>   1 file changed, 1 insertion(+), 1 deletion(-)

Reviewed-by: Richard Henderson <richard.henderson@linaro.org>


r~

> 
> diff --git a/tests/tcg/multiarch/linux/linux-sigrtminmax.c b/tests/tcg/multiarch/linux/linux-sigrtminmax.c
> index a7059aacd9cb..b5ea65f3d393 100644
> --- a/tests/tcg/multiarch/linux/linux-sigrtminmax.c
> +++ b/tests/tcg/multiarch/linux/linux-sigrtminmax.c
> @@ -39,7 +39,7 @@ int main(int argc, char **argv)
>       assert(qemu);
>   
>       if (!getenv("QEMU_RTSIG_MAP")) {
> -        char **new_argv = malloc((argc + 2) + sizeof(char *));
> +        char **new_argv = malloc((argc + 2) * sizeof(char *));
>           int tsig1, hsig1, count1, tsig2, hsig2, count2;
>           char rt_sigmap[64];
>
Re: [PATCH] tests/tcg: fix buffer overflow in multiarch/linux/linux-sigrtminmax
Posted by Alex Bennée 2 weeks, 3 days ago
Max Filippov <jcmvbkbc@gmail.com> writes:

> Fix new_argv allocation size to be `(argc + 2) * sizeof(char *)` bytes,
> which matches the way it's used to store `argc + 2` pointers.
>
> This fixes the test for me, which otherwise fails on xtensa with the
> following message
>
>   linux-sigrtminmax.c: 59: main: Assertion `execve(new_argv[0], new_argv, environ) == 0' failed.'.
>
> Signed-off-by: Max Filippov <jcmvbkbc@gmail.com>

Reviewed-by: Alex Bennée <alex.bennee@linaro.org>

> ---
>  tests/tcg/multiarch/linux/linux-sigrtminmax.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/tests/tcg/multiarch/linux/linux-sigrtminmax.c b/tests/tcg/multiarch/linux/linux-sigrtminmax.c
> index a7059aacd9cb..b5ea65f3d393 100644
> --- a/tests/tcg/multiarch/linux/linux-sigrtminmax.c
> +++ b/tests/tcg/multiarch/linux/linux-sigrtminmax.c
> @@ -39,7 +39,7 @@ int main(int argc, char **argv)
>      assert(qemu);
>  
>      if (!getenv("QEMU_RTSIG_MAP")) {
> -        char **new_argv = malloc((argc + 2) + sizeof(char *));
> +        char **new_argv = malloc((argc + 2) * sizeof(char *));
>          int tsig1, hsig1, count1, tsig2, hsig2, count2;
>          char rt_sigmap[64];

-- 
Alex Bennée
Virtualisation Tech Lead @ Linaro