From nobody Sat Jul 25 09:29:13 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784653679; cv=none; d=zohomail.com; s=zohoarc; b=Ak5DoHTXRH48fSSI0iZYH4Pa9ZOXzZuhLJhXOFJ6guRJxt5BE5MWtqBxl+YetEZth73vLefv50OXW33AeOOl3AkPvtIeYI6MJZuepH0tjhkaxSrMDJUU3JtDxLC+z4oKd5lNUJaInq2OP51V/eSm8581jwLKNKahJZPNMmGe8LI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784653679; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Ls3p/bTX4nCuNnshAFjSlUyfFX7ZZPLPVZ6OwzJD8zM=; b=B6P/69Qr96eUAzy1CkZwBYnqZY2T0m2PUwD6XBRbHFvHobCe1CmnLxO2EJWgcrYqhzKhUzhMdqwTVdgNsfhDuinxn0oSWEEMS+SA18MQnkEF9tI96d0LYsWe7RT5mzZNljT9ke/0uwuler48O8D7HTt9tOgA01UKBaY2UaknJaQ= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784653679377313.4336963837276; Tue, 21 Jul 2026 10:07:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmDuO-0004lb-Iz; Tue, 21 Jul 2026 13:05:32 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuM-0004kr-C3 for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:30 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuK-00072O-3l for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:30 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-644-yOEL44fAOQWHfbn0CFVr1A-1; Tue, 21 Jul 2026 13:05:25 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 9078D19774FC; Tue, 21 Jul 2026 17:05:24 +0000 (UTC) Received: from corto.redhat.com (unknown [10.44.48.82]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 454F61598; Tue, 21 Jul 2026 17:05:22 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784653527; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Ls3p/bTX4nCuNnshAFjSlUyfFX7ZZPLPVZ6OwzJD8zM=; b=LTGp+mRormv9UHOH+2wlANxbMAhyvxTF3W4xg6T2Aag6rm/cEGRdUKuvN6YGFgNebY53jM JXa/4JWs6AY0O4iYW+JlGdcW/XfpSnpTk5RSwk9CcCoYPBqVKANXDyklorlou6hyeywmT6 gHS4QFcOUK4ie+AVRAy/HLt993sPKHY= X-MC-Unique: yOEL44fAOQWHfbn0CFVr1A-1 X-Mimecast-MFC-AGG-ID: yOEL44fAOQWHfbn0CFVr1A_1784653524 From: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= To: qemu-devel@nongnu.org Cc: Tomita Moeko , K S Maan , qemu-stable@nongnu.org, Alex Williamson , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= Subject: [PULL 01/13] vfio/igd: Clear saved BDSM in legacy VBIOS ROM at load time Date: Tue, 21 Jul 2026 19:05:06 +0200 Message-ID: <20260721170518.4160785-2-clg@redhat.com> In-Reply-To: <20260721170518.4160785-1-clg@redhat.com> References: <20260721170518.4160785-1-clg@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=clg@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784653680112158500 From: Tomita Moeko IGD does not come with a ROM BAR [1], the ROM BAR read by default from kernel is actually the host VBIOS shadow RAM region that contains host modifications on boot. With AI-assisted reverse engineering on VBIOS binaries, it is observed that VBIOS saves BDSM register value on first access and uses saved value if present. When the image is executed in guest, since there is already a saved HPA in VBIOS, it keeps using that value instead of the GPA programmed by SeaBIOS in BDSM register in PCI config space, causing VBIOS to program GTT entries with wrong address, resulting in garbled output in BIOS POST and the error below detected by i915 driver. i915 0000:00:02.0: [drm] *ERROR* Initial plane programming using invalid ra= nge, dma_addr=3D0x00000000db200000 ((null) [0x00000000baf00000-0x00000000be= efffff]) The previous solution, c4c45e943e51 ("vfio/pci: Intel graphics legacy mode assignment"), adjusts GTT entry addresses to (addr - host BDSM + guest BDSM) to workaround that. But it is removed in 5aed8b0f0be2 ("vfio/igd: Remove GTT write quirk in IO BAR 4") due to inconsistent values in MMIO BAR0 and IO BAR4. Since it was a value latched into the VBIOS that breaks virtualization (QEMU does not map the GTT at the same address in the VM), a ROM quirk clearing the saved value in VBIOS image is introduced. It searches the BDSM accessor routine by matching a 19-byte signature anchored on the unique `mov $0x105e,%ax` instruction, then locates the offset of saved BDSM and clears it. This makes the routine fall through to the PCI config read on the first call inside the guest. [1] 3.5.15, 4th Generation Intel Core Processor Family Datasheet Vol. 2 https://www.intel.com/content/dam/www/public/us/en/documents/datasheets= /4th-gen-core-family-desktop-vol-2-datasheet.pdf Fixes: 5aed8b0f0be2 ("vfio/igd: Remove GTT write quirk in IO BAR 4") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3093 Reported-by: K S Maan Cc: qemu-stable@nongnu.org Signed-off-by: Tomita Moeko Reviewed-by: Alex Williamson Link: https://lore.kernel.org/qemu-devel/20260708103100.23127-1-tomitamoeko= @gmail.com Signed-off-by: C=C3=A9dric Le Goater --- hw/vfio/pci.h | 3 ++ hw/vfio/igd-stubs.c | 5 ++ hw/vfio/igd.c | 115 +++++++++++++++++++++++++++++++++++++++++++ hw/vfio/pci-quirks.c | 5 ++ hw/vfio/pci.c | 2 + hw/vfio/trace-events | 1 + 6 files changed, 131 insertions(+) diff --git a/hw/vfio/pci.h b/hw/vfio/pci.h index fe52e9df6e67707c9899d418b0261afeedf4aab2..c9ab9498708ec0343e206c7f343= 085b0be8a7a1e 100644 --- a/hw/vfio/pci.h +++ b/hw/vfio/pci.h @@ -252,10 +252,13 @@ void vfio_bar_quirk_exit(VFIOPCIDevice *vdev, int nr); void vfio_bar_quirk_finalize(VFIOPCIDevice *vdev, int nr); void vfio_setup_resetfn_quirk(VFIOPCIDevice *vdev); bool vfio_add_virt_caps(VFIOPCIDevice *vdev, Error **errp); +void vfio_rom_quirk_setup(VFIOPCIDevice *vdev); void vfio_quirk_reset(VFIOPCIDevice *vdev); VFIOQuirk *vfio_quirk_alloc(int nr_mem); + void vfio_probe_igd_bar0_quirk(VFIOPCIDevice *vdev, int nr); bool vfio_probe_igd_config_quirk(VFIOPCIDevice *vdev, Error **errp); +void vfio_igd_legacy_rom_quirk(VFIOPCIDevice *vdev); =20 extern const PropertyInfo qdev_prop_nv_gpudirect_clique; =20 diff --git a/hw/vfio/igd-stubs.c b/hw/vfio/igd-stubs.c index f7687d909125c2233e76f7e6d03aa90f38c3b89f..5f60b24c8b46d94f0de2573aeb6= b6c80690476cb 100644 --- a/hw/vfio/igd-stubs.c +++ b/hw/vfio/igd-stubs.c @@ -18,3 +18,8 @@ bool vfio_probe_igd_config_quirk(VFIOPCIDevice *vdev, Err= or **errp) { return true; } + +void vfio_igd_legacy_rom_quirk(VFIOPCIDevice *vdev) +{ + return; +} diff --git a/hw/vfio/igd.c b/hw/vfio/igd.c index e091f21b6a3aea0013e0b3094d2ca13588200c98..413a49aae9163c6500bc50f29e5= 454f698addaa4 100644 --- a/hw/vfio/igd.c +++ b/hw/vfio/igd.c @@ -724,3 +724,118 @@ bool vfio_probe_igd_config_quirk(VFIOPCIDevice *vdev,= Error **errp) =20 return vfio_pci_igd_config_quirk(vdev, errp); } + +/* + * IGD ROM BAR read from kernel is actually the host VBIOS shadow RAM regi= on, + * which contains host modifications. In Gen 6-9 VBIOS, the routine below = is + * used to get BDSM value when programming the initial GTT. + * xx xx xx xx v: .long ? # saved value + * 66 53 push %ebx + * 66 2e 83 3e xx xx 00 cmpl $0x0,%cs:v # is saved value em= pty? + * 74 07 je 1f # if zero, go compu= te + * 66 2e a1 xx xx mov %cs:v,%eax # else return saved= value + * eb 0f jmp 2f + * b8 5e 10 1: mov $0x105e,%ax # dev 00:02.0, offs= et 5E + * e8 xx xx call pci_read_cfg_word + * 66 c1 e0 10 shl $0x10,%eax # left shift 16 bits + * 66 2e a3 xx xx mov %eax,%cs:v # save the result + * 66 5b 2: pop %ebx + * c3 ret + * When running the VBIOS in guest, saved value still reflects the host st= olen + * memory base address, which is not correct in guest. So we need to patch= the + * VBIOS to clear the saved value. + * + * The unique 19-byte starts at `cmpl $0,%cs:v` and ends at `mov $0x105e,%= ax` + * anchors the match to the routine. Both `cs:` displacements must referen= ce + * the same offset. + */ +static int igd_vbios_find_saved_bdsm(const uint8_t *rom, size_t rom_size, + uint16_t *bdsm_offset) +{ + static const uint8_t start[] =3D { 0x66, 0x2e, 0x83, 0x3e }; + static const uint8_t middle[] =3D { 0x00, 0x74, 0x07, 0x66, 0x2e, 0xa1= }; + static const uint8_t end[] =3D { 0xeb, 0x0f, 0xb8, 0x5e, 0x10 }; + uint16_t val; + size_t i; + bool found =3D false; + + if (rom_size < 19) { + return -ENOENT; + } + + for (i =3D 0; i + 19 <=3D rom_size; i++) { + if (memcmp(rom + i, start, sizeof(start)) !=3D 0 || + memcmp(rom + i + 6, middle, sizeof(middle)) !=3D 0 || + memcmp(rom + i + 14, end, sizeof(end)) !=3D 0) { + continue; + } + + /* same saved value address? */ + if (rom[i + 4] !=3D rom[i + 12] || rom[i + 5] !=3D rom[i + 13]) { + continue; + } + + if (found) { + return -EEXIST; + } + + val =3D rom[i + 4] | ((uint16_t)rom[i + 5] << 8); + if (val + sizeof(uint32_t) <=3D rom_size) { + *bdsm_offset =3D val; + found =3D true; + } + } + + if (!found) { + return -ENOENT; + } + + return 0; +} + +void vfio_igd_legacy_rom_quirk(VFIOPCIDevice *vdev) +{ + uint8_t *rom =3D vdev->rom; + int gen; + uint16_t pcir_offset; + uint16_t bdsm_offset =3D 0; + uint8_t checksum =3D 0; + uint32_t i; + + if (!vfio_pci_is(vdev, PCI_VENDOR_ID_INTEL, PCI_ANY_ID) || + !vfio_is_vga(vdev) || !vdev->vga) { + return; + } + + /* Only Gen 6~9 devices have legacy VBIOS as Option ROM */ + gen =3D igd_gen(vdev); + if (gen < 6 || gen > 9) { + return; + } + + if (pci_get_word(rom) !=3D 0xaa55) { + return; + } + + /* Must be a legacy ROM */ + pcir_offset =3D pci_get_word(rom + 0x18); + if (pcir_offset + 0x14 >=3D vdev->rom_size || + memcmp(rom + pcir_offset, "PCIR", 4) || + pci_get_byte(rom + pcir_offset + 0x14) !=3D 0x00) { + return; + } + + /* Search and clear the saved BDSM value */ + if (igd_vbios_find_saved_bdsm(rom, vdev->rom_size, &bdsm_offset)) { + return; + } + memset(rom + bdsm_offset, 0, sizeof(uint32_t)); + + /* Recalculate checksum and patch it. */ + for (i =3D 0; i < vdev->rom_size; i++) { + checksum +=3D rom[i]; + } + rom[6] -=3D checksum; + + trace_vfio_pci_igd_vbios_patched(vdev->vbasedev.name); +} diff --git a/hw/vfio/pci-quirks.c b/hw/vfio/pci-quirks.c index bccf31751fd47387fd89110e27b695e5c822d5c4..c5b4f9091d498d49eb3371c0502= e7ab6b7b76b30 100644 --- a/hw/vfio/pci-quirks.c +++ b/hw/vfio/pci-quirks.c @@ -1592,3 +1592,8 @@ bool vfio_add_virt_caps(VFIOPCIDevice *vdev, Error **= errp) =20 return true; } + +void vfio_rom_quirk_setup(VFIOPCIDevice *vdev) +{ + vfio_igd_legacy_rom_quirk(vdev); +} diff --git a/hw/vfio/pci.c b/hw/vfio/pci.c index c204706e63045c930bda7977adc8034f907b6890..dcfc92aae1c78d3a803665bcaea= 1e83f66a6d030 100644 --- a/hw/vfio/pci.c +++ b/hw/vfio/pci.c @@ -1119,6 +1119,8 @@ static bool vfio_pci_load_rom(VFIOPCIDevice *vdev, Er= ror **errp) } } =20 + vfio_rom_quirk_setup(vdev); + return true; } =20 diff --git a/hw/vfio/trace-events b/hw/vfio/trace-events index f71d0bbc0a5440e4ccd374fac4733af08438e7be..bfdaf229e42b0d9d40e38c828c9= 7cf47eb831a87 100644 --- a/hw/vfio/trace-events +++ b/hw/vfio/trace-events @@ -90,6 +90,7 @@ vfio_pci_igd_bar4_write(const char *name, uint32_t index,= uint32_t data, uint32_ vfio_pci_igd_bdsm_enabled(const char *name, int size) "%s %dMB" vfio_pci_igd_host_bridge_enabled(const char *name) "%s" vfio_pci_igd_lpc_bridge_enabled(const char *name) "%s" +vfio_pci_igd_vbios_patched(const char *name) "%s" =20 # listener.c vfio_iommu_map_notify(const char *op, uint64_t iova_start, uint64_t iova_e= nd) "iommu %s @ 0x%"PRIx64" - 0x%"PRIx64 --=20 2.55.0 From nobody Sat Jul 25 09:29:13 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784653606; cv=none; d=zohomail.com; s=zohoarc; b=eZpYxsWDY/CqXBxgQJCy8B4b7bz63W75hUp2FbTfcbHy4ubJy/OqEzXFMGnFsPjCtARy2gHcZ90ZPbIZfc0Pg/y6fhKqMTQf2S7AThZzggOOdNvrm+M9sb9nowgS71pMD6qeEEe18wEZBm2TqVXmUjR+nZamg+L+BKQhkV46DKg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784653606; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=FvrvTez3Tth/d3RQhRxQnACm/KeEgvWlI9eFWupyO3M=; b=U9r2o2l5ylSX1qZmB2mMbdgm23zO859gIF7RCzrKhBXkDdo6DuS9c+qBuDjApPUfh6dOlFX9OWwnfQwjGdBW1p01r8ivFhKLNAKT5BrRbQPBn+NIpxrY+GSvQ2g6SxGgN7D69n4GKrvUm/sVPf6Yi5cJKCvGRm2Vlv0AgI7igFk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784653606825838.269223860634; Tue, 21 Jul 2026 10:06:46 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmDuR-0004mK-D7; Tue, 21 Jul 2026 13:05:35 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuP-0004m9-Pe for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:33 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuO-000735-Aj for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:33 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-20-C1UmKPlsOzenJmloDoUHLQ-1; Tue, 21 Jul 2026 13:05:27 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id AD983195FCD6; Tue, 21 Jul 2026 17:05:26 +0000 (UTC) Received: from corto.redhat.com (unknown [10.44.48.82]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 3D0821599; Tue, 21 Jul 2026 17:05:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784653531; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=FvrvTez3Tth/d3RQhRxQnACm/KeEgvWlI9eFWupyO3M=; b=YTfalTuRVrjtl/YGbXNk5DxE+WMkrEh20lHhTRq6p5qe59+tUsJ4ZB+PuLoNhkCp7V4xSQ rYheP/oskO8tGmeunPoevBPN4tHpJgKyn5Ciiu8Wk4R6u55cApkTdZyYpgkE4DVw1tnVE/ dN/Dz9yeFvQve2gex/9jsSlc1u3yZAw= X-MC-Unique: C1UmKPlsOzenJmloDoUHLQ-1 X-Mimecast-MFC-AGG-ID: C1UmKPlsOzenJmloDoUHLQ_1784653526 From: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , Nicolin Chen , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PULL 02/13] vfio/region: Clarify dma-buf failure messages Date: Tue, 21 Jul 2026 19:05:07 +0200 Message-ID: <20260721170518.4160785-3-clg@redhat.com> In-Reply-To: <20260721170518.4160785-1-clg@redhat.com> References: <20260721170518.4160785-1-clg@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=clg@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784653607587158500 The dma-buf failure messages in vfio_region_create_dma_buf() say "PCI BAR IOMMU mappings may fail", which suggests the BAR is broken. In practice, only P2P DMA is affected -- normal passthrough uses the mmap fallback. Reword both messages to mention P2P DMA explicitly and clarify that the mmap fallback is in use. Use warn_report_err_once() at the call site so per-BAR repetition on mdev devices is suppressed. Fixes: dcf1b77e834d ("hw/vfio/region: Create dmabuf for PCI BAR per region") Cc: Nicolin Chen Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: C=C3=A9dric Le Goater --- hw/vfio/region.c | 11 +++++------ 1 file changed, 5 insertions(+), 6 deletions(-) diff --git a/hw/vfio/region.c b/hw/vfio/region.c index dbde3391802691888ca31d5e329aba5ba680feb4..54ad11a6c8ed8e04fa365262ccb= 8bd694bdb45f7 100644 --- a/hw/vfio/region.c +++ b/hw/vfio/region.c @@ -321,13 +321,12 @@ static bool vfio_region_create_dma_buf(VFIORegion *re= gion, Error **errp) ret =3D vfio_device_get_feature(vbasedev, feature); if (ret < 0) { if (ret =3D=3D -ENOTTY) { - warn_report_once("VFIO dma-buf not supported in kernel: " - "PCI BAR IOMMU mappings may fail"); + warn_report_once("VFIO dma-buf not supported in kernel, " + "using mmap fallback, P2P DMA will not work"); return true; } - /* P2P DMA or exposing device memory use cases are not supported. = */ - error_setg_errno(errp, -ret, "%s: failed to create dma-buf: " - "PCI BAR IOMMU mappings may fail", + error_setg_errno(errp, -ret, "%s: dma-buf unavailable, " + "using mmap fallback, P2P DMA will not work", memory_region_name(region->mem)); return false; } @@ -448,7 +447,7 @@ int vfio_region_mmap(VFIORegion *region) } =20 if (!vfio_region_create_dma_buf(region, &local_err)) { - error_report_err(local_err); + warn_report_err_once(local_err); } =20 return 0; --=20 2.55.0 From nobody Sat Jul 25 09:29:13 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784653591; cv=none; d=zohomail.com; s=zohoarc; b=W9H/F64F5KbOLVHyye0QdG62WfqKZ0lZcsr4+YpaLIVWIdKO/bEwtdwJzid0xMwGiwuODMVQxpoQ71eV8x5eF5YUXQbB+GGqsiCrHz9kK1mlteRQWmzPgNGRtb6NXic3KU/1EX1DlGcfZfGiZa1g5jqTf7kxOji8y5o4juY9caA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784653591; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=4AlBhhCQddSb59LxPp1ggPvA1JZHINheOT6h06v9+KI=; b=PlpUKNLSgRa6y8zNuo9sdlXSAspBIpUTYLEWQOXffaV+UzPKoZVCWgaAgs9mjTk/PKJbXl3UlKohZHj8CHhHh5wPNOUW7kn7IDK2qXJVtKUDK9EN81WK0tqRqleb9F9QmXJfOpWdRF78amB8G4pTQRbr4ln0fEov8C4t6vxCk9o= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178465359199199.88105005839043; Tue, 21 Jul 2026 10:06:31 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmDuU-0004nF-BX; Tue, 21 Jul 2026 13:05:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuS-0004mg-Lh for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:37 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuQ-00073T-St for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:36 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-686-d30PyiLhMPySIuWqsQKwJA-1; Tue, 21 Jul 2026 13:05:30 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id C5F42180AA93; Tue, 21 Jul 2026 17:05:28 +0000 (UTC) Received: from corto.redhat.com (unknown [10.44.48.82]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 2998E1598; Tue, 21 Jul 2026 17:05:26 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784653534; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=4AlBhhCQddSb59LxPp1ggPvA1JZHINheOT6h06v9+KI=; b=bAtVHNgHPGM3ACEq6Fx5q/EWHe2dmlzPs64UB0Pkc/p7Xoevki2Avz2PrNL3hXEihimZZH +1UVUvJxCRCWG8xGDME2S17cEB6GFpibvtlGPYDHfEZ+RU6FEWjn+tju7tUgBTRTQ41nkw OOiIh7/bf34IYOtOVxr5Qj22jriZxZk= X-MC-Unique: d30PyiLhMPySIuWqsQKwJA-1 X-Mimecast-MFC-AGG-ID: d30PyiLhMPySIuWqsQKwJA_1784653529 From: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= To: qemu-devel@nongnu.org Cc: "Denis V. Lunev" , Alex Williamson , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= Subject: [PULL 03/13] vfio/pci: don't narrow a failed config read to a plausible value Date: Tue, 21 Jul 2026 19:05:08 +0200 Message-ID: <20260721170518.4160785-4-clg@redhat.com> In-Reply-To: <20260721170518.4160785-1-clg@redhat.com> References: <20260721170518.4160785-1-clg@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=clg@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784653593826158500 From: "Denis V. Lunev" vfio_pci_read_config() signals a failed host-side read by returning (uint32_t)-1, regardless of the requested length. vfio_intx_enable() and vfio_pci_pre_reset() both narrowed that return value straight into a uint8_t/uint16_t local before checking anything, which truncates -1 into 0xff or 0xffff - values a real 1- or 2-byte register read can legitimately produce. From that point on, a failed read and real all-ones content are indistinguishable. Keep the full uint32_t result and check it against (uint32_t)-1 before narrowing. In vfio_pci_pre_reset(), skip the corresponding write-back on a failed read instead of writing back constructed garbage to the device. Resolves: Coverity CID 1663684 Resolves: Coverity CID 1663688 Signed-off-by: Denis V. Lunev CC: Alex Williamson CC: C=C3=A9dric Le Goater Link: https://lore.kernel.org/qemu-devel/20260717122232.468955-2-den@openvz= .org [ clg: Added Coverity IDs ] Reviewed-by: C=C3=A9dric Le Goater Signed-off-by: C=C3=A9dric Le Goater --- hw/vfio/pci.c | 32 +++++++++++++++++++++++++------- 1 file changed, 25 insertions(+), 7 deletions(-) diff --git a/hw/vfio/pci.c b/hw/vfio/pci.c index dcfc92aae1c78d3a803665bcaea1e83f66a6d030..b8c937d4be50091691875f2253c= 4d03ba83df704 100644 --- a/hw/vfio/pci.c +++ b/hw/vfio/pci.c @@ -323,10 +323,16 @@ static void vfio_irqchip_change(Notifier *notify, voi= d *data) static bool vfio_intx_enable(VFIOPCIDevice *vdev, Error **errp) { PCIDevice *pdev =3D PCI_DEVICE(vdev); - uint8_t pin =3D vfio_pci_read_config(pdev, PCI_INTERRUPT_PIN, 1); + uint32_t val =3D vfio_pci_read_config(pdev, PCI_INTERRUPT_PIN, 1); + uint8_t pin; Error *err =3D NULL; int32_t fd; =20 + if (val =3D=3D (uint32_t)-1) { + error_setg(errp, "failed to read PCI_INTERRUPT_PIN"); + return false; + } + pin =3D val; =20 if (!pin) { return true; @@ -2766,6 +2772,7 @@ bool vfio_pci_add_capabilities(VFIOPCIDevice *vdev, E= rror **errp) void vfio_pci_pre_reset(VFIOPCIDevice *vdev) { PCIDevice *pdev =3D PCI_DEVICE(vdev); + uint32_t val; uint16_t cmd; =20 vfio_disable_interrupts(vdev); @@ -2774,23 +2781,34 @@ void vfio_pci_pre_reset(VFIOPCIDevice *vdev) * Stop any ongoing DMA by disconnecting I/O, MMIO, and bus master. * Also put INTx Disable in known state. */ - cmd =3D vfio_pci_read_config(pdev, PCI_COMMAND, 2); - cmd &=3D ~(PCI_COMMAND_IO | PCI_COMMAND_MEMORY | PCI_COMMAND_MASTER | - PCI_COMMAND_INTX_DISABLE); - vfio_pci_write_config(pdev, PCI_COMMAND, cmd, 2); + val =3D vfio_pci_read_config(pdev, PCI_COMMAND, 2); + if (val !=3D (uint32_t)-1) { + cmd =3D val; + cmd &=3D ~(PCI_COMMAND_IO | PCI_COMMAND_MEMORY | PCI_COMMAND_MASTE= R | + PCI_COMMAND_INTX_DISABLE); + vfio_pci_write_config(pdev, PCI_COMMAND, cmd, 2); + } =20 /* Make sure the device is in D0 */ if (pdev->pm_cap) { uint16_t pmcsr; uint8_t state; =20 - pmcsr =3D vfio_pci_read_config(pdev, pdev->pm_cap + PCI_PM_CTRL, 2= ); + val =3D vfio_pci_read_config(pdev, pdev->pm_cap + PCI_PM_CTRL, 2); + if (val =3D=3D (uint32_t)-1) { + return; + } + pmcsr =3D val; state =3D pmcsr & PCI_PM_CTRL_STATE_MASK; if (state) { pmcsr &=3D ~PCI_PM_CTRL_STATE_MASK; vfio_pci_write_config(pdev, pdev->pm_cap + PCI_PM_CTRL, pmcsr,= 2); /* vfio handles the necessary delay here */ - pmcsr =3D vfio_pci_read_config(pdev, pdev->pm_cap + PCI_PM_CTR= L, 2); + val =3D vfio_pci_read_config(pdev, pdev->pm_cap + PCI_PM_CTRL,= 2); + if (val =3D=3D (uint32_t)-1) { + return; + } + pmcsr =3D val; state =3D pmcsr & PCI_PM_CTRL_STATE_MASK; if (state) { error_report("vfio: Unable to power on device, stuck in D%= d", --=20 2.55.0 From nobody Sat Jul 25 09:29:13 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784653641; cv=none; d=zohomail.com; s=zohoarc; b=CpIuq4dInnLi8Ka9J6bQYmnmF6feeFtd8xI6t59yj73ui/5rlhC7DEkh4TYvA5ZWd1eKVUVU+Jb1+3ONO9M6bWMgIwxJb5XNyrP03RikIwqtxdJDopY4Wyl8YIJ9iMkpMFWgB2IPAz0Dz0ATcg71yFm3lwCMPK/PPmrX8Q24TAM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784653641; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=SUl4Ek+CVqxAEoPgmkJ0rxZazVa5azFI4RJVdQd6Lmw=; b=JFEs9haPBPEWRx//Xr5n9kgKpOWUFU9jolCeqPtM9EUhZQiq3MI+MdX6IySje1AqrmX1OqQ0ggQUvg5vYcaDP7nStiEOIPHA6vg1AEDqxIqe2K0gWtOk1OLrqZvqR8wVQLdNSqqmC7Lkod+W0Ds0wt/kBsm5kAcV+XpyCA5kD1o= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784653641151473.02313295292447; Tue, 21 Jul 2026 10:07:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmDv0-0004t7-8O; Tue, 21 Jul 2026 13:06:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuo-0004qg-G5 for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:06:00 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuk-00076i-1q for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:55 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-106-ABtxV4eZNUiMaAr1R6RU0A-1; Tue, 21 Jul 2026 13:05:40 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id F05E6180067C; Tue, 21 Jul 2026 17:05:30 +0000 (UTC) Received: from corto.redhat.com (unknown [10.44.48.82]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 424F71598; Tue, 21 Jul 2026 17:05:29 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784653551; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=SUl4Ek+CVqxAEoPgmkJ0rxZazVa5azFI4RJVdQd6Lmw=; b=HkDOQI5abdTWN0RYXamemrqboRWnynPAHOrphNjKj06xEc44SUDe68vTKdx/azL8ZCtOEF sWSd/wyKVa+W0bTZiicGWme4mltHZnY5QZqWGCDc9ww/KOA3xHv22W0rhqIy/rJkS62lGJ y24s911xEW+CUWC7jlOp1gZ63Af+BUw= X-MC-Unique: ABtxV4eZNUiMaAr1R6RU0A-1 X-Mimecast-MFC-AGG-ID: ABtxV4eZNUiMaAr1R6RU0A_1784653531 From: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= To: qemu-devel@nongnu.org Cc: "Denis V. Lunev" , Alex Williamson , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= Subject: [PULL 04/13] vfio/pci: reject invalid PCI_INTERRUPT_PIN values Date: Tue, 21 Jul 2026 19:05:09 +0200 Message-ID: <20260721170518.4160785-5-clg@redhat.com> In-Reply-To: <20260721170518.4160785-1-clg@redhat.com> References: <20260721170518.4160785-1-clg@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=clg@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784653641686158500 From: "Denis V. Lunev" qemu-kvm aborts a few seconds after starting a VM with a passed-through GPU whose PCI_INTERRUPT_PIN comes back as an out-of-range value: vfio_intx_enable() only guards against pin =3D=3D 0 and stores vdev->intx.pin =3D pin - 1 with no upper-bound check. That value later reaches pci_irq_handler()'s assert(0 <=3D irq_num && irq_num < PCI_NUM_PINS) via pci_irq_deassert() -> pci_set_irq(), aborting the process. Legal PCI_INTERRUPT_PIN values are 0 (no legacy interrupt) or 1-PCI_NUM_PINS (INTA-INTD); reject anything else before it reaches vdev->intx.pin, whether the out-of-range value came from a read failure (now caught by the previous commit) or was handed back as data by the device itself. Signed-off-by: Denis V. Lunev CC: Alex Williamson CC: C=C3=A9dric Le Goater Link: https://lore.kernel.org/qemu-devel/20260717122232.468955-3-den@openvz= .org Reviewed-by: C=C3=A9dric Le Goater Reviewed-by: Philippe Mathieu-Daud=C3=A9 Signed-off-by: C=C3=A9dric Le Goater --- hw/vfio/pci.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/hw/vfio/pci.c b/hw/vfio/pci.c index b8c937d4be50091691875f2253c4d03ba83df704..380dd8c15f8d5bb98b725075978= eef2e4e1e6c2d 100644 --- a/hw/vfio/pci.c +++ b/hw/vfio/pci.c @@ -338,6 +338,11 @@ static bool vfio_intx_enable(VFIOPCIDevice *vdev, Erro= r **errp) return true; } =20 + if (pin > PCI_NUM_PINS) { + error_setg(errp, "invalid PCI interrupt pin %d", pin); + return false; + } + /* * Do not alter interrupt state during vfio_realize and cpr load. * The incoming state is cleared thereafter. --=20 2.55.0 From nobody Sat Jul 25 09:29:13 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784653621; cv=none; d=zohomail.com; s=zohoarc; b=A76c1wHtmUKiK/BdkaPqNgopJUtIUvdxT61U0IW1Zn00WO55F0CN1pJneh4m4gMH3vBSNk/i90ZMXlusLiFdeRHCMWXOos7CCJXZfvy/UWGXr7paC/WMlsvxbqw7lY3iOVpNNiFnhxyj16HVBZkXcHDkjmd+Ipn83D8u0CaXmiU= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784653621; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=blsxiSwTZBU9OljdnlSUcNjUJjFpLVjGvPU4TO4d0KE=; b=LWcwzzsyslipv7v70fgGAgDnTTjxK9WwcJA5CFqnwV3nAozWa3PhAYtNYGY1zQeQw0cHkTNhnxyeixAjzyYpfwCynP13DsLy1VUhn17XRvjk03gi5XG4jcZOes7nHSsnQnhAuVb6pG+hV/LItuDhTzERWhbX42M6sW6TtXOEZG4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784653621071276.14003906766175; Tue, 21 Jul 2026 10:07:01 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmDuf-0004pL-AX; Tue, 21 Jul 2026 13:05:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuU-0004nI-Ei for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:39 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuT-00073l-0q for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:38 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-146-qvl-g8nAOjC13Gfeg_-Jdw-1; Tue, 21 Jul 2026 13:05:33 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id BDFAB19774F7; Tue, 21 Jul 2026 17:05:32 +0000 (UTC) Received: from corto.redhat.com (unknown [10.44.48.82]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 8AC4F1599; Tue, 21 Jul 2026 17:05:31 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784653536; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=blsxiSwTZBU9OljdnlSUcNjUJjFpLVjGvPU4TO4d0KE=; b=a4cG84OaVGZHGP87WI7NG01zNVj2cMMaX0yfKcRlSqEChcaCnfQF9NbBgPt0fsSq8vUN5D A+aHl6TGOoNNB5HUtsCeuKsYVq6T5ZDGIIxXe56I+gYhI4RLwHcl8hhlBhECzBgsTU45Vx NsZbHy05HmqS1og4JTM6MO2eohKZKDo= X-MC-Unique: qvl-g8nAOjC13Gfeg_-Jdw-1 X-Mimecast-MFC-AGG-ID: qvl-g8nAOjC13Gfeg_-Jdw_1784653532 From: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= To: qemu-devel@nongnu.org Cc: Thanos Makatos , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= Subject: [PULL 05/13] vfio-user: vfio_user_get_region_info: prevent buffer overflow Date: Tue, 21 Jul 2026 19:05:10 +0200 Message-ID: <20260721170518.4160785-6-clg@redhat.com> In-Reply-To: <20260721170518.4160785-1-clg@redhat.com> References: <20260721170518.4160785-1-clg@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=clg@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784653621421158500 From: Thanos Makatos If the vfio-user responds with a value large enough such that adding the header size to it overflows, a smaller buffer would be inadvertently allocated, leading to buffer overflow. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3867 Signed-off-by: Thanos Makatos Fixes: 667866d66620 ("vfio-user: implement VFIO_USER_DEVICE_GET_REGION_INFO= ") Reviewed-by: C=C3=A9dric Le Goater Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-2-thanos.maka= tos@nutanix.com Signed-off-by: C=C3=A9dric Le Goater --- hw/vfio-user/device.c | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/hw/vfio-user/device.c b/hw/vfio-user/device.c index b8d2b7c1a84bb1914a71fdccbbdff675373cef3b..e58167a81879e94520bda247172= 80e2347422e77 100644 --- a/hw/vfio-user/device.c +++ b/hw/vfio-user/device.c @@ -128,12 +128,21 @@ static int vfio_user_get_region_info(VFIOUserProxy *p= roxy, error_printf("vfio_user_get_region_info argsz too small\n"); return -E2BIG; } + + /* + * Ensure that size doesn't overflow, otherwise we'll allocate a much + * smaller buffer than we need. + */ + if (__builtin_add_overflow(info->argsz, sizeof(VFIOUserHdr), &size)) { + error_printf("vfio_user_get_region_info argsz too large\n"); + return -E2BIG; + } + if (fds !=3D NULL && fds->send_fds !=3D 0) { error_printf("vfio_user_get_region_info can't send FDs\n"); return -EINVAL; } =20 - size =3D info->argsz + sizeof(VFIOUserHdr); msgp =3D g_malloc0(size); =20 vfio_user_request_msg(&msgp->hdr, VFIO_USER_DEVICE_GET_REGION_INFO, --=20 2.55.0 From nobody Sat Jul 25 09:29:13 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784653605; cv=none; d=zohomail.com; s=zohoarc; b=IN21uC81CXdBgL27Ebm+i07yDv3FQMJX0ne7ZBdfjzQ1J79a5V3pzaeFrPlAXIUs4Yw9QkErFvckjGt9ak1YOr/eROAljsM/WjYiHzfWcC48FokTY1qADs66NZdO90o8hPFBaw8h/5dkjLnYSPYWQl3iRMwz7+WjfQ92ez4c26Y= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784653605; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=lFqxfGrtfUBaPOuR6IwU6BlM+WiwbpjS7TP9c4so1Rk=; b=R+rogtW4mKMG+hLwZVJ6kP7npO+eUAfHXbK1GmG37e2jWKfH44Z5Mll1pBbIM425KkxdbAS8NWr8el9pfvPpO1s3P4u8pH4hPO0O4eV2e/ctdS0pBhmbhzANhIvbMRWfeHclSCy7j37ZCyBYTJgXsFFjbMIik0YCU9ZQP+TPXaE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784653605167652.1901250577242; Tue, 21 Jul 2026 10:06:45 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmDub-0004oJ-W7; Tue, 21 Jul 2026 13:05:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuV-0004nK-Ac for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:39 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuT-00073q-Tn for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:39 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-668-WiFRhmrnMj-xoCs1Dr76eg-1; Tue, 21 Jul 2026 13:05:35 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 75683180895E; Tue, 21 Jul 2026 17:05:34 +0000 (UTC) Received: from corto.redhat.com (unknown [10.44.48.82]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 38C981598; Tue, 21 Jul 2026 17:05:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784653537; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=lFqxfGrtfUBaPOuR6IwU6BlM+WiwbpjS7TP9c4so1Rk=; b=BzmCTbPPiXAGSGO59dp9MMWLgLHpmYOvwjgnmri6vtPJWSAdjw8Gn1ofLmf2ZmoumalReM JdAu/yrwIDWImgvOSwTgPVgIE2gZc0mrfDXzUyEikDJXM7n6lW8L5gANSGSSjo7VHBUbKy lnuGNlCbSUhBWg0aYMv41YOjT0LlPtw= X-MC-Unique: WiFRhmrnMj-xoCs1Dr76eg-1 X-Mimecast-MFC-AGG-ID: WiFRhmrnMj-xoCs1Dr76eg_1784653534 From: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= To: qemu-devel@nongnu.org Cc: Thanos Makatos , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= Subject: [PULL 06/13] vfio-user: vfio_user_get_region_info: respect max_xfer_size Date: Tue, 21 Jul 2026 19:05:11 +0200 Message-ID: <20260721170518.4160785-7-clg@redhat.com> In-Reply-To: <20260721170518.4160785-1-clg@redhat.com> References: <20260721170518.4160785-1-clg@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=clg@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784653607576158500 From: Thanos Makatos Signed-off-by: Thanos Makatos Fixes: 667866d66620 ("vfio-user: implement VFIO_USER_DEVICE_GET_REGION_INFO= ") Reviewed-by: C=C3=A9dric Le Goater Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-3-thanos.maka= tos@nutanix.com Signed-off-by: C=C3=A9dric Le Goater --- hw/vfio-user/device.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/hw/vfio-user/device.c b/hw/vfio-user/device.c index e58167a81879e94520bda24717280e2347422e77..8350bb2c018504dbca50a4e9afb= fc6be251f5b2a 100644 --- a/hw/vfio-user/device.c +++ b/hw/vfio-user/device.c @@ -137,6 +137,10 @@ static int vfio_user_get_region_info(VFIOUserProxy *pr= oxy, error_printf("vfio_user_get_region_info argsz too large\n"); return -E2BIG; } + if (size > proxy->max_xfer_size) { + error_printf("vfio_user_get_region_info argsz too large\n"); + return -E2BIG; + } =20 if (fds !=3D NULL && fds->send_fds !=3D 0) { error_printf("vfio_user_get_region_info can't send FDs\n"); --=20 2.55.0 From nobody Sat Jul 25 09:29:13 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784653619; cv=none; d=zohomail.com; s=zohoarc; b=b42ptfclL8J4ik/7+BRygxrh5KHWTG6aPzx3stWpBntO/RW14xjEmMUgeZCxr4COa6tOvlQF+iHcZqbm3jNX0/F5ZPgLe/6JHwKJRtFDMgpcNEnv84YOaYuIplsm5ug7mtlfX9DBMjc6d8Px3Kn+xKEHkcJKl3zvIgV0OZlkvzE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784653619; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=IFRZLrP2Tsi31KJpqkQBmNqY7C+CroUhXMG17npnqxg=; b=UlEMPxF6MkNupbAlbmBDtmkm5G2pic87AJIu4XA8FbclipSvqzhLvsUn3VStUsXXZaXUH0wnJ6H6aZTSWQ7x7dLQegsJVwtjTvPS29SCsqtKPwFv3Qi5w9ffcoay3wUUVhFIxOdRnN9l5Sd6k9Mlt8V3rvEnO5KLFum8jVVLToc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784653619023343.210388421174; Tue, 21 Jul 2026 10:06:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmDuf-0004pG-9F; Tue, 21 Jul 2026 13:05:49 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuZ-0004nq-8m for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:45 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuX-00074N-L4 for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:43 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-459-1zCln9wbN-64U-Fulv5zuQ-1; Tue, 21 Jul 2026 13:05:37 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 2EB651800625; Tue, 21 Jul 2026 17:05:36 +0000 (UTC) Received: from corto.redhat.com (unknown [10.44.48.82]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id E4F07159D; Tue, 21 Jul 2026 17:05:34 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784653540; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=IFRZLrP2Tsi31KJpqkQBmNqY7C+CroUhXMG17npnqxg=; b=H7pOfzX7JJ0Nsn1iyVBpzKrRRxjL6TStsiwUvqfDGTVmy0oPrjTqHLLyBYiBe3a/Rj5Y0z 8ZT46aAW7xFXKtZeL57+4ViIlTmxmk4rGFab4CjVJQr/AFQcjCD1zFRX0PIxQ08ZnhZzwW roiKueYkIMyWBxm4ePDSJ5THxVj3eeg= X-MC-Unique: 1zCln9wbN-64U-Fulv5zuQ-1 X-Mimecast-MFC-AGG-ID: 1zCln9wbN-64U-Fulv5zuQ_1784653536 From: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= To: qemu-devel@nongnu.org Cc: Thanos Makatos , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= Subject: [PULL 07/13] vfio-user: vfio_user_get_region_info: reject unreasonably short struct Date: Tue, 21 Jul 2026 19:05:12 +0200 Message-ID: <20260721170518.4160785-8-clg@redhat.com> In-Reply-To: <20260721170518.4160785-1-clg@redhat.com> References: <20260721170518.4160785-1-clg@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.129.124; envelope-from=clg@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784653619530158500 From: Thanos Makatos While this isn't technically a bug, it's highly unlikely that the server wouldn't be writing an entire struct. Signed-off-by: Thanos Makatos Fixes: 667866d66620 ("vfio-user: implement VFIO_USER_DEVICE_GET_REGION_INFO= ") Reviewed-by: C=C3=A9dric Le Goater Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-4-thanos.maka= tos@nutanix.com Signed-off-by: C=C3=A9dric Le Goater --- hw/vfio-user/device.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/hw/vfio-user/device.c b/hw/vfio-user/device.c index 8350bb2c018504dbca50a4e9afbfc6be251f5b2a..3d12e8b2a20eb96fb1a8a944070= d13bf0e049b67 100644 --- a/hw/vfio-user/device.c +++ b/hw/vfio-user/device.c @@ -165,6 +165,11 @@ static int vfio_user_get_region_info(VFIOUserProxy *pr= oxy, } trace_vfio_user_get_region_info(msgp->index, msgp->flags, msgp->size); =20 + if (msgp->argsz < sizeof(*info)) { + error_printf("vfio_user_get_region_info reply argsz too small\n"); + return -EINVAL; + } + memcpy(info, &msgp->argsz, info->argsz); =20 /* --=20 2.55.0 From nobody Sat Jul 25 09:29:13 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784653663; cv=none; d=zohomail.com; s=zohoarc; b=RU5OQgQThZkZqdjrGMdTUQWZY4THYdtSJ8jb9tXL2uVZYbjQ4m2tCTdiD78Cc3gkvH31jgdpJFK3HOv9t9ekbM5SYL+6nCnAp+3oJ66Pj7+Qkx6QcUTp7TwJklZh05lW57dSo0BrQcqY3dxYDdTzEuY90Fgr0AbhCVyYYcq+iiM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784653663; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=fEJwEoGhO12AmbhN6O3Bb2G+2hsVAlx3B1Qba5SOvGY=; b=ExpYYF9Szgov193F2X2NMQRY21XzJJHvmma1O6poLW8dLbSvrwe93cQgQjiCXLvKFy1F+GFxs3lNuy5bomMdMxZE2iYru2v9HGeNPna6Nr5/EDasvfqY30nBE/I6N++JGVvtmsHr/AArmFXCUSgxcU9k2eh9SfCzY6h/61233RY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178465366358897.21833448162681; Tue, 21 Jul 2026 10:07:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmDuc-0004oh-QP; Tue, 21 Jul 2026 13:05:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDua-0004nt-Sq for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:45 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuZ-00074p-EC for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:44 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-326-x3C2vHO0Pyu__YctxsBDRQ-1; Tue, 21 Jul 2026 13:05:39 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 097221809CB6; Tue, 21 Jul 2026 17:05:38 +0000 (UTC) Received: from corto.redhat.com (unknown [10.44.48.82]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 9F0241598; Tue, 21 Jul 2026 17:05:36 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784653542; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=fEJwEoGhO12AmbhN6O3Bb2G+2hsVAlx3B1Qba5SOvGY=; b=Ys4+NuDyaHiwuY11vAaz2+X/n5by2fKiN9CCvRM9OdhNTKI8sA3rhABbrhOxHqjE1mYiRQ U9TUDNSTN/iWnLI6bS5pieFJjB2sqwdb6phnR/aJbDTbMNOeGDZfSSVvIm4IZnxjm0vPc2 7KiTdZ9rU6BV+wLZHv/ib8Nj4Gzx4u0= X-MC-Unique: x3C2vHO0Pyu__YctxsBDRQ-1 X-Mimecast-MFC-AGG-ID: x3C2vHO0Pyu__YctxsBDRQ_1784653538 From: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= To: qemu-devel@nongnu.org Cc: Thanos Makatos , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= Subject: [PULL 08/13] vfio-user: vfio_user_get_region_info: prevent excessive malloc Date: Tue, 21 Jul 2026 19:05:13 +0200 Message-ID: <20260721170518.4160785-9-clg@redhat.com> In-Reply-To: <20260721170518.4160785-1-clg@redhat.com> References: <20260721170518.4160785-1-clg@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=clg@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784653665870158500 From: Thanos Makatos If the vfio-user server responds with a value larger than max_xfer_size vfio_device_get_region_info() blindly uses it in the next loop in g_realloc. An value larger than max_xfer_size is anyway rejected by the check at the beginning of vfio_user_get_region_info(), however that only happens _after_ the g_realloc, and if that value is excessively large it can cause g_realloc to fail, so check it here. Signed-off-by: Thanos Makatos Fixes: 667866d66620 ("vfio-user: implement VFIO_USER_DEVICE_GET_REGION_INFO= ") Reviewed-by: C=C3=A9dric Le Goater Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-5-thanos.maka= tos@nutanix.com Signed-off-by: C=C3=A9dric Le Goater --- hw/vfio-user/device.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/hw/vfio-user/device.c b/hw/vfio-user/device.c index 3d12e8b2a20eb96fb1a8a944070d13bf0e049b67..008e5cf6877c84c3d0cf33f25a6= ac9a4cf231e06 100644 --- a/hw/vfio-user/device.c +++ b/hw/vfio-user/device.c @@ -170,6 +170,16 @@ static int vfio_user_get_region_info(VFIOUserProxy *pr= oxy, return -EINVAL; } =20 + /* + * The server can respond with a larger argsz in the reply to request a + * larger buffer on the next iteration via vfio_device_get_region_info= (). + * Reject values that would trigger an oversized realloc. + */ + if (msgp->argsz > proxy->max_xfer_size) { + error_printf("vfio_user_get_region_info reply argsz too large\n"); + return -E2BIG; + } + memcpy(info, &msgp->argsz, info->argsz); =20 /* --=20 2.55.0 From nobody Sat Jul 25 09:29:13 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784653639; cv=none; d=zohomail.com; s=zohoarc; b=QmGnKm6zSxTkGcj6iqBKdtv6R7IBRO0SsuWqnNZb1g2JjsC6sWkHh0nYmInOPtveaFG+oMCd/3Y0OyYEHfCGU/ePGfIqcnHB8rRTQd7T8WSLioLvBHlA895Xh9fL7ZHEJm0lfcoAQXPO2EE4ntz3q2uVYu9oc7AOU7Xlz97ZQWI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784653639; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=72LDf8tRSV+qu76UEUgi0OAWOeK8FqkegTE9xqDiYgM=; b=YBdJ5dpSd4e5oRS2puDJT7C3RPB1QrRUqjSoig7UFYvUPRNkFAEYR2heij30cpQdZ2EJbyN9gBJrBkiFrwUtPfzr/HqJ7bdthkLCq8rLalGNQoNeKJGEUkK7Uv5tDTwEK5rZcNN2y3N3ssQq/9b8CHsT+boIi5xJPHjUIZS8QZE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784653639587689.4852196272157; Tue, 21 Jul 2026 10:07:19 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmDuy-0004sO-M0; Tue, 21 Jul 2026 13:06:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDud-0004pF-GK for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:49 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDub-00075G-9F for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:47 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-481-NHl82gxxMlmst1EFAIGg5Q-1; Tue, 21 Jul 2026 13:05:40 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id AFBB4180ABD8; Tue, 21 Jul 2026 17:05:39 +0000 (UTC) Received: from corto.redhat.com (unknown [10.44.48.82]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 78EEE1599; Tue, 21 Jul 2026 17:05:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784653544; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=72LDf8tRSV+qu76UEUgi0OAWOeK8FqkegTE9xqDiYgM=; b=JwRazvoZGXhqRwOoOj6O0hoG5S6zMO3/EKqDLiEwXuHfl8vtjw3eF1ESAltttnd7VrSzZG uV6RcmBdELdu0nViQFl2bVY6VIFevoVy/VBfCGJA+fXNE0jeVMXZY4AvWiOVVU/sDG7Reh dEMwzi7c0t3Iv+8kv1XpQ8OS/csf2R8= X-MC-Unique: NHl82gxxMlmst1EFAIGg5Q-1 X-Mimecast-MFC-AGG-ID: NHl82gxxMlmst1EFAIGg5Q_1784653539 From: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= To: qemu-devel@nongnu.org Cc: Thanos Makatos , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= Subject: [PULL 09/13] vfio-user: vfio_user_device_io_get_region_info: fix capability check Date: Tue, 21 Jul 2026 19:05:14 +0200 Message-ID: <20260721170518.4160785-10-clg@redhat.com> In-Reply-To: <20260721170518.4160785-1-clg@redhat.com> References: <20260721170518.4160785-1-clg@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.129.124; envelope-from=clg@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784653641713158500 From: Thanos Makatos The existing check for PCI capabilities misses the case where info->cap_offset =3D=3D info->argsz, which results in accessing unallocated memory. Fix the comparison. Fixes: 667866d66620 ("vfio-user: implement VFIO_USER_DEVICE_GET_REGION_INFO= ") Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3865 Signed-off-by: Thanos Makatos Reviewed-by: C=C3=A9dric Le Goater Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-6-thanos.maka= tos@nutanix.com Signed-off-by: C=C3=A9dric Le Goater --- hw/vfio-user/device.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/hw/vfio-user/device.c b/hw/vfio-user/device.c index 008e5cf6877c84c3d0cf33f25a6ac9a4cf231e06..3d0dbe840649b7b678b79afd3db= c7f9caaeb947b 100644 --- a/hw/vfio-user/device.c +++ b/hw/vfio-user/device.c @@ -214,7 +214,8 @@ static int vfio_user_device_io_get_region_info(VFIODevi= ce *vbasedev, =20 /* cap_offset in valid area */ if ((info->flags & VFIO_REGION_INFO_FLAG_CAPS) && - (info->cap_offset < sizeof(*info) || info->cap_offset > info->args= z)) { + (info->cap_offset < sizeof(*info) + || info->cap_offset + sizeof(struct vfio_info_cap_header) > info-= >argsz)) { return -EINVAL; } =20 --=20 2.55.0 From nobody Sat Jul 25 09:29:13 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784653605; cv=none; d=zohomail.com; s=zohoarc; b=HM1JQiK5O+C7g7KEyzS4dOaE7KAFtPGP/du3swV3f8XOYhf2gMjLh/A5/B3KTUNU2SFiwhgxE1p0gykGXgeoTb90rj6GV/XNYYW4CAOLRk86xHYUXHsZJM37P/Td8PLRr2Gy7oFop4WYji/K0Ddm5v0hu8W3skGuzSqZtS1C9FA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784653605; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=QO1NczH/4k1f0SNAeCpXjrvDyiEJh3c0/Uw+bvxfXJY=; b=aDldJ1GCtCwWX8UIgB110ZHftZTYzmTe/E4cubhPHWire9lEX96UEI+WDLRntnB/WU0gl+x6R0nOowys9FURyOHVP7fcmE3zn/uqGg01lAuYAaLgjEPUAY97ZG0hNQDKJtOOGW9Z5Rjq5A6mkEuur1OQjALG72xA84a9tBDfmsk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784653605097690.7976917841347; Tue, 21 Jul 2026 10:06:45 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmDuz-0004sg-O7; Tue, 21 Jul 2026 13:06:09 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuc-0004oc-LY for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:46 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDub-00075D-4G for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:46 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-376-sMIBuzjjOlW33axxPlGq7g-1; Tue, 21 Jul 2026 13:05:42 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 7644D1955F30; Tue, 21 Jul 2026 17:05:41 +0000 (UTC) Received: from corto.redhat.com (unknown [10.44.48.82]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 2D26E1599; Tue, 21 Jul 2026 17:05:39 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784653544; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=QO1NczH/4k1f0SNAeCpXjrvDyiEJh3c0/Uw+bvxfXJY=; b=V/6C8ayvP0Cfml6vqtXxR7CssWM6zsP9GRffODP9nNvInPfzeWrM8Odp9zPC9n84mUm/hd AiHP8pDHPmsOtXANs7uK6LmJXIv82BHjL/uhT3vDzH/iNBP+ywAvGXvSuJtQMUqJCwgkb1 mLs582l7Ch2TImwqonOnU7KDd33AlpY= X-MC-Unique: sMIBuzjjOlW33axxPlGq7g-1 X-Mimecast-MFC-AGG-ID: sMIBuzjjOlW33axxPlGq7g_1784653541 From: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= To: qemu-devel@nongnu.org Cc: Thanos Makatos , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= Subject: [PULL 10/13] vfio-user: vfio_user_device_io_device_feature: prevent buffer overflow Date: Tue, 21 Jul 2026 19:05:15 +0200 Message-ID: <20260721170518.4160785-11-clg@redhat.com> In-Reply-To: <20260721170518.4160785-1-clg@redhat.com> References: <20260721170518.4160785-1-clg@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=clg@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784653607574158500 From: Thanos Makatos This isn't in practise a problem since feature->argsz is not externally provided, it's a good hardening step nonetheless. Fixes: e2358af5838d ("vfio-user: support VFIO_USER_DEVICE_FEATURE") Signed-off-by: Thanos Makatos Reviewed-by: C=C3=A9dric Le Goater Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-7-thanos.maka= tos@nutanix.com Signed-off-by: C=C3=A9dric Le Goater --- hw/vfio-user/device.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/hw/vfio-user/device.c b/hw/vfio-user/device.c index 3d0dbe840649b7b678b79afd3dbc7f9caaeb947b..353fa5ee21e34a88bcd0eff9de4= 0d9757387a616 100644 --- a/hw/vfio-user/device.c +++ b/hw/vfio-user/device.c @@ -79,9 +79,14 @@ vfio_user_device_io_device_feature(VFIODevice *vbasedev, struct vfio_device_feature *feature) { g_autofree VFIOUserDeviceFeature *msgp =3D NULL; - int size =3D sizeof(VFIOUserHdr) + feature->argsz; VFIOUserProxy *proxy =3D vbasedev->proxy; Error *local_err =3D NULL; + int size; + + if (__builtin_add_overflow(feature->argsz, sizeof(VFIOUserHdr), &size)= ) { + error_printf("vfio_user_device_io_device_feature argsz too large\n= "); + return -E2BIG; + } =20 msgp =3D g_malloc0(size); =20 --=20 2.55.0 From nobody Sat Jul 25 09:29:13 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784653592; cv=none; d=zohomail.com; s=zohoarc; b=O94WP7Ik4yd0VT8OCJ3eT33CtQ3YBB/01S/6NbOKOrT144s1iB5oAg3LgR16G7MxNRLM8Sj70ZG5ZNMrU2t2pJnCdhOftDD7hsFGcSuGshPQhJUNP3X7UwTFAQ4dNq7+Kfet1LLHj8+T+bw5RgVCNXomUJnPWhbSih9VS4HiO5o= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784653592; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Ir9B4jQffkIFCiCSvXqtyzQcTJDUup9v+RuKijd/L7k=; b=ex1GMcxBxf+h7YqjU+ML1A7D+fhL3EsCZWLKNY7UVkcv0GQEhDsDt3qb2y2A143UCVz2JUjn6GARL9e6xu5kOHqxc7/ohE3Xx6v0UsJ4Hsk3rK9Fly8BGYHys40Pu99Dp0Yc1Gu4dtPRR2He3kC01+XJUYIibuSGwjFTs37naJc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784653592208606.3920510535033; Tue, 21 Jul 2026 10:06:32 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmDuz-0004si-Sl; Tue, 21 Jul 2026 13:06:09 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuf-0004pe-NI for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:54 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDue-00075y-8N for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:49 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-412-ajA9hPucNk6pPquoh1tg1A-1; Tue, 21 Jul 2026 13:05:43 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 17E9B1800631; Tue, 21 Jul 2026 17:05:43 +0000 (UTC) Received: from corto.redhat.com (unknown [10.44.48.82]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id D007C1598; Tue, 21 Jul 2026 17:05:41 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784653547; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Ir9B4jQffkIFCiCSvXqtyzQcTJDUup9v+RuKijd/L7k=; b=OT5FmwUZazeG7J6bWHYcDnpu5/wMGkvjtRwSfc3t2wi27aODNV/HFYjudpD4itAO4woVMx cCKvQJATZZyIwLLvboJ3P24NwDwTIE2H19EpMBn0rd7Q2416o+eUEuuaqoDtk6jn9Zo9+B 0Y4b1YiKqdk5JXlI7JsciWcIUfTJnTA= X-MC-Unique: ajA9hPucNk6pPquoh1tg1A-1 X-Mimecast-MFC-AGG-ID: ajA9hPucNk6pPquoh1tg1A_1784653543 From: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= To: qemu-devel@nongnu.org Cc: Thanos Makatos , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= Subject: [PULL 11/13] vfio-user: vfio_user_device_io_device_feature: prevent excessive malloc Date: Tue, 21 Jul 2026 19:05:16 +0200 Message-ID: <20260721170518.4160785-12-clg@redhat.com> In-Reply-To: <20260721170518.4160785-1-clg@redhat.com> References: <20260721170518.4160785-1-clg@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.133.124; envelope-from=clg@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784653593840158500 From: Thanos Makatos This isn't in practise a problem since feature->argsz is not externally provided, it's a good hardening step nonetheless. Fixes: e2358af5838d ("vfio-user: support VFIO_USER_DEVICE_FEATURE") Signed-off-by: Thanos Makatos Reviewed-by: C=C3=A9dric Le Goater Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-8-thanos.maka= tos@nutanix.com Signed-off-by: C=C3=A9dric Le Goater --- hw/vfio-user/device.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/hw/vfio-user/device.c b/hw/vfio-user/device.c index 353fa5ee21e34a88bcd0eff9de40d9757387a616..8feaa568750ed1978dbc273da20= 54c89ad3bcc96 100644 --- a/hw/vfio-user/device.c +++ b/hw/vfio-user/device.c @@ -87,6 +87,10 @@ vfio_user_device_io_device_feature(VFIODevice *vbasedev, error_printf("vfio_user_device_io_device_feature argsz too large\n= "); return -E2BIG; } + if (size > proxy->max_xfer_size) { + error_printf("vfio_user_device_io_device_feature argsz too large\n= "); + return -E2BIG; + } =20 msgp =3D g_malloc0(size); =20 --=20 2.55.0 From nobody Sat Jul 25 09:29:13 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784653640; cv=none; d=zohomail.com; s=zohoarc; b=iqMg/D2NRhZmNiDWNyVWiAOi8WH+Bfpp16wmrF/8rjGr956b7//tk97vmW4nV7OBNaaXpOetZkfAetRRrOkRwjjNjsS8Wlp6cfjBoWu3VF8lSQKplL/ecDQyDacZ3RROw+oib2CXvSSJgh5r/2N5gwh9FFmH+TZEfptTOWk07og= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784653640; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=g0jBy6SZGJcXblGb2I+iw4ks+eCKtsrQfT1HnyvcLgw=; b=eq+hxJ5L0NHghbLaDN7n7XZ0cX2Qnt1HIcC9Pb26+qA/7vRHJmrH9e5uliV161V2Uq8KPg7y2dE3aYtx1FvjuQLnZ6vMu5tjHnW1ikplJevePf/5dlFDi3RyJIys/dTTqs1UPC1htXQ8kVHpid5eP7hcnpGeSCHbGaAtx2h6zhI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784653640656325.66908790150956; Tue, 21 Jul 2026 10:07:20 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmDv3-0004tm-6v; Tue, 21 Jul 2026 13:06:13 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuh-0004pk-B3 for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:54 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuf-00076G-Vx for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:51 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-527-kKL_fC5JO5aonfgSQ6n8GQ-1; Tue, 21 Jul 2026 13:05:45 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id BC4F1193532D; Tue, 21 Jul 2026 17:05:44 +0000 (UTC) Received: from corto.redhat.com (unknown [10.44.48.82]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 8943E1598; Tue, 21 Jul 2026 17:05:43 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784653549; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=g0jBy6SZGJcXblGb2I+iw4ks+eCKtsrQfT1HnyvcLgw=; b=NdQvQDZH56CvL2aFBboX2rAWM4g2ai1CsCGVbSHS7jV0pF2LfBai3s6S/Ff5rsXFqNbpmE PkMtITO+EK+nwobFACkrGL/q2maB32eMfcxVvr1cEdlXbTRUM3a1DKWakU3MQ5BeWwuUY8 scs5bOUnL3cZc6CMfyp4kiPUOzN37X4= X-MC-Unique: kKL_fC5JO5aonfgSQ6n8GQ-1 X-Mimecast-MFC-AGG-ID: kKL_fC5JO5aonfgSQ6n8GQ_1784653544 From: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= To: qemu-devel@nongnu.org Cc: Thanos Makatos , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= Subject: [PULL 12/13] vfio-user: vfio_user_device_io_set_irqs: prevent buffer overflow Date: Tue, 21 Jul 2026 19:05:17 +0200 Message-ID: <20260721170518.4160785-13-clg@redhat.com> In-Reply-To: <20260721170518.4160785-1-clg@redhat.com> References: <20260721170518.4160785-1-clg@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.129.124; envelope-from=clg@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784653641718158500 From: Thanos Makatos This isn't in practise a problem since irq->argsz is not externally provided, it's a good hardening step nonetheless. Fixes: ca1add1696 ("vfio-user: implement VFIO_USER_DEVICE_GET/SET_IRQ*") Signed-off-by: Thanos Makatos Reviewed-by: C=C3=A9dric Le Goater Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-9-thanos.maka= tos@nutanix.com Signed-off-by: C=C3=A9dric Le Goater --- hw/vfio-user/device.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/hw/vfio-user/device.c b/hw/vfio-user/device.c index 8feaa568750ed1978dbc273da2054c89ad3bcc96..daac0e21b6b8fd5f91e3bb52044= 871b18021d337 100644 --- a/hw/vfio-user/device.c +++ b/hw/vfio-user/device.c @@ -293,7 +293,10 @@ static int vfio_user_device_io_set_irqs(VFIODevice *vb= asedev, * Handle simple case */ if ((irq->flags & VFIO_IRQ_SET_DATA_EVENTFD) =3D=3D 0) { - size =3D sizeof(VFIOUserHdr) + irq->argsz; + if (__builtin_add_overflow(irq->argsz, sizeof(VFIOUserHdr), &size)= ) { + error_printf("vfio_user_set_irqs argsz too large\n"); + return -E2BIG; + } msgp =3D g_malloc0(size); =20 vfio_user_request_msg(&msgp->hdr, VFIO_USER_DEVICE_SET_IRQS, size,= 0); --=20 2.55.0 From nobody Sat Jul 25 09:29:13 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1784653620; cv=none; d=zohomail.com; s=zohoarc; b=gI7KPXfiYciTR261cteFuqoPZKE3EYnr4jugarLPhUd0ljI1bYvy31TRzVkmydw82/cNpxBJW8q5epvyekXEmCK91LNehxEiL5wrB262YcTEiWlNth/l0aIcefazWsD/pfjSoQyD3+BzQD7T8NQkzQdOAnGh/0hdV112BZx1fHE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1784653620; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=wMoD6iqK1wu+TgRJjxcl3VN9qo7MyHMpGeXR6ihAqGI=; b=TIMLmumW3Og6K0TQXMKsYGvNC9HKVSW659/zGRJ/AfxDOpA3jJfx5t2Bon7r4YRJW8sZoVnJfT+AdG6OiGjcGi/5yoQmh5S0nm0it7k6dfos0arscigtBdY8Zvd7B4DUt2UT7N4OgGcvZJFVTEDV6JZTWJFXEx2nt65nrETl2Qg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1784653620514256.0025748858004; Tue, 21 Jul 2026 10:07:00 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wmDuz-0004se-E2; Tue, 21 Jul 2026 13:06:09 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuh-0004pj-7a for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:54 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wmDuf-00076B-St for qemu-devel@nongnu.org; Tue, 21 Jul 2026 13:05:50 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-583-iP89sCxQO1STJyOTD-A0UA-1; Tue, 21 Jul 2026 13:05:47 -0400 Received: from mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.95]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 7481419774FA; Tue, 21 Jul 2026 17:05:46 +0000 (UTC) Received: from corto.redhat.com (unknown [10.44.48.82]) by mx-prod-int-10.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 37B2A1598; Tue, 21 Jul 2026 17:05:44 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1784653549; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=wMoD6iqK1wu+TgRJjxcl3VN9qo7MyHMpGeXR6ihAqGI=; b=PXOw/elIu62B7+xQb4Nm8ztznVib8RLYrRNuVuSCXPGdZeASei20cZP7phY6mmkZgSST/3 tMm2MP30br/cIJ9N+hycVWujWXSxJ8NP0EggeQgvErFQBBPiavXgKpOoxkxDaKOb4QOiwr Qn/c9k+V3jHnmOrGmuQQyhyLQUO1NOs= X-MC-Unique: iP89sCxQO1STJyOTD-A0UA-1 X-Mimecast-MFC-AGG-ID: iP89sCxQO1STJyOTD-A0UA_1784653546 From: =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= To: qemu-devel@nongnu.org Cc: Thanos Makatos , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= Subject: [PULL 13/13] vfio-user: vfio_user_device_io_set_irqs: prevent excessive malloc Date: Tue, 21 Jul 2026 19:05:18 +0200 Message-ID: <20260721170518.4160785-14-clg@redhat.com> In-Reply-To: <20260721170518.4160785-1-clg@redhat.com> References: <20260721170518.4160785-1-clg@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.6 on 10.30.177.95 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: permerror client-ip=170.10.129.124; envelope-from=clg@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.01, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, T_SPF_PERMERROR=0.01 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1784653621413158500 From: Thanos Makatos This isn't in practise a problem since irq->argsz is not externally provided, it's a good hardening step nonetheless. Fixes: ca1add1696 ("vfio-user: implement VFIO_USER_DEVICE_GET/SET_IRQ*") Signed-off-by: Thanos Makatos Reviewed-by: C=C3=A9dric Le Goater Link: https://lore.kernel.org/qemu-devel/20260721122643.30985-10-thanos.mak= atos@nutanix.com Signed-off-by: C=C3=A9dric Le Goater --- hw/vfio-user/device.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/hw/vfio-user/device.c b/hw/vfio-user/device.c index daac0e21b6b8fd5f91e3bb52044871b18021d337..1a01e748cd43311cea65c749288= fc2003064db09 100644 --- a/hw/vfio-user/device.c +++ b/hw/vfio-user/device.c @@ -297,6 +297,11 @@ static int vfio_user_device_io_set_irqs(VFIODevice *vb= asedev, error_printf("vfio_user_set_irqs argsz too large\n"); return -E2BIG; } + if (size > proxy->max_xfer_size) { + error_printf("vfio_user_device_io_set_irqs argsz too large\n"); + return -E2BIG; + } + msgp =3D g_malloc0(size); =20 vfio_user_request_msg(&msgp->hdr, VFIO_USER_DEVICE_SET_IRQS, size,= 0); --=20 2.55.0