From nobody Sat Jul 25 21:20:43 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=kernel.org ARC-Seal: i=1; a=rsa-sha256; t=1783953396; cv=none; d=zohomail.com; s=zohoarc; b=ScIcPus91iFc13yjJVxTKfpWKFUfafHsZ9RdRj76CPc4QPpiU6lEYUS1rK4AnEbNoQlgP5osfGtQXNwSwxzbzv2fZagQ7FgVXjuyVNDFndBEP2/9mtkcX+B65JAkHi908cRQuF0IyVhqR3UmZZ7yJgdVO6T4NC0d1Ht7iT1WX/I= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783953396; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=YRwJLocGlcoYlaaTPE4IjhqLICavZEbrDlqYevfC/QY=; b=aobAY4Pou2URL/F7cAqNKERzWQ6poC76QQtdfpu2bis/SKObK4965F/1XRggTjbstwb+2UDWHPMTVy9JkvuNhpqdCBx7VPn3CagFCmhXSBo3VqPVrxEEuJsc4rfxzOVouj5pHP+5qwS5rRbgpI1Mk4J3HUng84n67cF0wJ3uUgc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783953396347511.6005114370598; Mon, 13 Jul 2026 07:36:36 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wjHlG-0008AG-1Z; Mon, 13 Jul 2026 10:35:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wjHl1-00088L-U7 for qemu-devel@nongnu.org; Mon, 13 Jul 2026 10:35:46 -0400 Received: from sea.source.kernel.org ([172.234.252.31]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wjHkx-0001u7-UG for qemu-devel@nongnu.org; Mon, 13 Jul 2026 10:35:43 -0400 Received: from smtp.kernel.org (quasi.space.kernel.org [100.103.45.18]) by sea.source.kernel.org (Postfix) with ESMTP id 4981F40107; Mon, 13 Jul 2026 14:35:38 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id CB7F31F000E9; Mon, 13 Jul 2026 14:35:36 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1783953338; bh=YRwJLocGlcoYlaaTPE4IjhqLICavZEbrDlqYevfC/QY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=e6NkguFZ0aktHnjn4uJOAUCErDLy+AdH0yHaaX81yZFdk1aIYq8rOHThE97TXUKfS D/9i12Itoy3BF5l3EwzAv2Hd73liTMT0rCfmM90FZWi8IfCV3laBRwVBdoiAV8GT4O JiOsLpF7Tfp+EvlYGOaAnkuBMwfqCCHKQ+AhV1KNpkJQ328bLdj2vUaJi9cXLT77RB 0mZnkbXDLzQs1i9YcSWrwVQSTDDNpQoRujiuoP0XnIr5kV9yUWkCVSLzmlgSK6cDW0 N2bNopRytKPM+aVDU6f3/9jv0X0Y9mLvF3E+LZjbQy7/T8gCaMn6Q8CaVj+PE8m3Sh 9c4YTyz74EtdA== From: Helge Deller To: Stefan Hajnoczi , qemu-devel@nongnu.org Cc: Laurent Vivier , Pierrick Bouvier , Helge Deller , Peter Maydell Subject: [PULL 1/2] linux-user: Validate guest-passed dm_ioctl data_size Date: Mon, 13 Jul 2026 16:35:30 +0200 Message-ID: <20260713143533.4641-2-deller@kernel.org> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260713143533.4641-1-deller@kernel.org> References: <20260713143533.4641-1-deller@kernel.org> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=172.234.252.31; envelope-from=deller@kernel.org; helo=sea.source.kernel.org X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @kernel.org) X-ZM-MESSAGEID: 1783953397340158500 Content-Type: text/plain; charset="utf-8" From: Peter Maydell In do_ioctl_dm() we work with a struct dm_ioctl from the guest. This has a fixed initial part, and then a variable data part; the guest tells us how long that part is by setting the data_size field. The data_size is supposed to include the length of the fixed parts of the struct dm_ioctl. Currently we don't validate anything about the guest-provided data_size, and we use it to allocate a buffer which we then copy the fixed part of the dm_ioctl struct into. This means that if the guest passes a very small data_size the copy of the fixed part will overrun the buffer. Perform the same sanitizing of the minimum and maximum limits of the data_size that the kernel does in drivers/md/dm-ioctl.c in the copy_params() function. Cc: qemu-stable@nongnu.org Fixes: 56e904ecb2018 ("linux-user: implement device mapper ioctls") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3736 Signed-off-by: Peter Maydell Reviewed-by: Helge Deller Signed-off-by: Helge Deller --- linux-user/syscall.c | 30 ++++++++++++++++++++++++++---- 1 file changed, 26 insertions(+), 4 deletions(-) diff --git a/linux-user/syscall.c b/linux-user/syscall.c index d257fb9ca9..3f060ee8b6 100644 --- a/linux-user/syscall.c +++ b/linux-user/syscall.c @@ -5088,6 +5088,9 @@ do_ioctl_usbdevfs_submiturb(const IOCTLEntry *ie, uin= t8_t *buf_temp, } #endif /* CONFIG_USBFS */ =20 +#define DM_MAX_TARGETS 1048576 +#define DM_MAX_TARGET_PARAMS 1024 + static abi_long do_ioctl_dm(const IOCTLEntry *ie, uint8_t *buf_temp, int f= d, int cmd, abi_long arg) { @@ -5100,6 +5103,7 @@ static abi_long do_ioctl_dm(const IOCTLEntry *ie, uin= t8_t *buf_temp, int fd, abi_long ret; void *big_buf =3D NULL; char *host_data; + const size_t minimum_data_size =3D offsetof(struct dm_ioctl, data); =20 arg_type++; target_size =3D thunk_type_size(arg_type, 0); @@ -5111,9 +5115,26 @@ static abi_long do_ioctl_dm(const IOCTLEntry *ie, ui= nt8_t *buf_temp, int fd, thunk_convert(buf_temp, argptr, arg_type, THUNK_HOST); unlock_user(argptr, arg, 0); =20 - /* buf_temp is too small, so fetch things into a bigger buffer */ - big_buf =3D g_malloc0(((struct dm_ioctl*)buf_temp)->data_size * 2); - memcpy(big_buf, buf_temp, target_size); + /* At this point this includes the size of the fixed dm_ioctl parts */ + guest_data_size =3D ((struct dm_ioctl *)buf_temp)->data_size; + + if (guest_data_size < minimum_data_size || + guest_data_size > DM_MAX_TARGETS * DM_MAX_TARGET_PARAMS) { + ret =3D -TARGET_EINVAL; + goto out; + } + + /* + * buf_temp is too small, so fetch things into a bigger buffer. Here + * we copy all of the fixed parts of struct dm_ioctl but not the + * data at the end (which in the struct is "char data[7]" but in + * reality is command-specific and might be nothing or might be + * much larger, as defined by data_size). We know struct dm_ioctl's + * size is not target specific so we don't need to distinguish between + * its minimum size for the host vs the target. + */ + big_buf =3D g_malloc0(guest_data_size * 2); + memcpy(big_buf, buf_temp, minimum_data_size); buf_temp =3D big_buf; host_dm =3D big_buf; =20 @@ -5122,7 +5143,8 @@ static abi_long do_ioctl_dm(const IOCTLEntry *ie, uin= t8_t *buf_temp, int fd, ret =3D -TARGET_EINVAL; goto out; } - guest_data_size =3D host_dm->data_size - host_dm->data_start; + /* Adjust down to only the size of the payload */ + guest_data_size -=3D host_dm->data_start; host_data =3D (char*)host_dm + host_dm->data_start; =20 argptr =3D lock_user(VERIFY_READ, guest_data, guest_data_size, 1); --=20 2.54.0 From nobody Sat Jul 25 21:20:43 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=kernel.org ARC-Seal: i=1; a=rsa-sha256; t=1783953415; cv=none; d=zohomail.com; s=zohoarc; b=WvfOepwpgIn1AbtHeR3IFmTSZs5YV4tV7cLEMG5fNoYaeqfvxhiTGLJSBNYb2Nk91tr0ey9pxrX19TcURkvNMdmXpTvU3nYiJ4EHxfZ5nXxbEqvUWYIEvmehwdN/3X52QX9ka67y5LwYHmMkGK9ttwrJT8HCZlZyFWjexj0xbTM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1783953415; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=T8p4n2eSgA6Zg6pqEnfewKH6Qm0lGS/uzGWFa5oza50=; b=mqj5BCBf/kwYn/NmCK3mUaHOxLQDKdZU7XcYWNGF2fCn4rjmo3dQqQshPQHbs7ooCfZ/wW0cRMTorjorWYWnlCfD/mrv5mP4kKZ0O9LrkFKbCMN4LkzKhke6xfdT1j15rpGv7v5XWIrqjyMqbcAIuZeXYI4mYtVaMNboWw8t4Fc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1783953415520562.6136403584974; Mon, 13 Jul 2026 07:36:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wjHlD-00089X-R9; Mon, 13 Jul 2026 10:35:55 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wjHl1-00088M-Uj for qemu-devel@nongnu.org; Mon, 13 Jul 2026 10:35:46 -0400 Received: from sea.source.kernel.org ([2600:3c0a:e001:78e:0:1991:8:25]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wjHkz-0001uF-QQ for qemu-devel@nongnu.org; Mon, 13 Jul 2026 10:35:43 -0400 Received: from smtp.kernel.org (quasi.space.kernel.org [100.103.45.18]) by sea.source.kernel.org (Postfix) with ESMTP id 19E3140139; Mon, 13 Jul 2026 14:35:40 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 99EA21F000E9; Mon, 13 Jul 2026 14:35:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1783953340; bh=T8p4n2eSgA6Zg6pqEnfewKH6Qm0lGS/uzGWFa5oza50=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=QVGW/YoKQfDspsaGeSUp7vOdzX6XeVf3N925i47STxxm9NL/BMSp1bxraLHaNcjAy ik1N8TsilBB9rCVBa1dnva0K+J5PwlQ+wVLCkwo0+a3i4G9v7c2MJYq1ehwxlxoBuQ nH0/APo/W4K813l2xy/pVt/0vwBZPmJLvOXAAS/kCmpg16o2a+LOj5/4W+GqhvuW/x O3eR5h9LkYzsrVIhK/GkTB96dXwGIoCsZ82Povk0+GFWY2zp+WoYx1YDHnWh53KwCM lne+HyV08sMtV29DieYz84oRJtOP4TwfvWzXuxbJ1JQgrL5VYFqWUiB+kRs4ypnH7v ZpNMbW0n2YKPg== From: Helge Deller To: Stefan Hajnoczi , qemu-devel@nongnu.org Cc: Laurent Vivier , Pierrick Bouvier , Helge Deller , Matt Turner Subject: [PULL 2/2] linux-user/alpha: populate AT_HWCAP from env->amask Date: Mon, 13 Jul 2026 16:35:31 +0200 Message-ID: <20260713143533.4641-3-deller@kernel.org> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260713143533.4641-1-deller@kernel.org> References: <20260713143533.4641-1-deller@kernel.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2600:3c0a:e001:78e:0:1991:8:25; envelope-from=deller@kernel.org; helo=sea.source.kernel.org X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @kernel.org) X-ZM-MESSAGEID: 1783953417360158500 From: Matt Turner Alpha has never set AT_HWCAP in linux-user emulation, so getauxval(AT_HWCAP) always returned 0 regardless of the emulated CPU model. The Linux kernel computes ELF_HWCAP as ~amask(-1), i.e. the set of ISA extension bits that the amask instruction reports as supported (cleared in its output). env->amask stores exactly those bits with the same layout (BWX=3D0x1, FIX=3D0x2, CIX=3D0x4, MVI=3D0x100, TRAP=3D0x200, PREFETCH=3D0x1= 000), so returning it directly from get_elf_hwcap matches the kernel convention. Add HAVE_ELF_HWCAP to target_elf.h and implement get_elf_hwcap() in elfload.c to expose the emulated CPU's capability mask to user-space programs via the auxiliary vector. Without this fix, programs using getauxval(AT_HWCAP) to detect BWX/FIX/CIX (such as glibc's memcpy or JIT compilers targeting Alpha) incorrectly concluded that no extensions were available even when emulating ev56+. Signed-off-by: Matt Turner Cc: qemu-stable@nongnu.org Reviewed-by: Helge Deller Signed-off-by: Helge Deller --- linux-user/alpha/elfload.c | 11 +++++++++++ linux-user/alpha/target_elf.h | 1 + 2 files changed, 12 insertions(+) diff --git a/linux-user/alpha/elfload.c b/linux-user/alpha/elfload.c index 1969f620a5..7be9e466b6 100644 --- a/linux-user/alpha/elfload.c +++ b/linux-user/alpha/elfload.c @@ -6,6 +6,17 @@ #include "target_elf.h" =20 =20 +abi_ulong get_elf_hwcap(CPUState *cs) +{ + /* + * The Linux kernel computes ELF_HWCAP as ~amask(-1), which clears a b= it + * for each supported ISA extension. env->amask stores exactly those = bits + * set for the extensions supported by the emulated CPU model, matching + * the kernel's convention: bit set in AT_HWCAP =E2=86=94 extension pr= esent. + */ + return cpu_env(cs)->amask; +} + void elf_core_copy_regs(target_elf_gregset_t *r, const CPUAlphaState *env) { int i; diff --git a/linux-user/alpha/target_elf.h b/linux-user/alpha/target_elf.h index 4987ae3944..dd90c6f783 100644 --- a/linux-user/alpha/target_elf.h +++ b/linux-user/alpha/target_elf.h @@ -12,6 +12,7 @@ #define ELF_MACHINE EM_ALPHA =20 #define HAVE_ELF_CORE_DUMP 1 +#define HAVE_ELF_HWCAP 1 =20 /* * Matches the kernel's elf_gregset_t (ELF_NGREG =3D 33): --=20 2.54.0