From nobody Mon Sep 28 02:05:32 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=kernel.org ARC-Seal: i=1; a=rsa-sha256; t=1785166099; cv=none; d=zohomail.com; s=zohoarc; b=jyUYRvb7VT6otUxK1LPw1YV7+38zS/n9p0HHOManq6xhIQcq+R+VRxzeuHuixYXassRdCX4zQrH5hRySWN51Pnzbig3wdiq2Z2dUC3GfL/CWmRRsckMdyWtX/98vM3thKVr4AZjdLse6OOvMLYdZWU5w6rySUXFjgotiJ7KyEhM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785166099; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=OS5YQV4o6NpBgijEakeJsKx4uhqE5N3Wqh0IvH+4hPE=; b=aelLv2TLKJ2tGsDaQzSKyaqDz80pApqdYjng/CwRrf86OaU8as4U9zWGJeluN7g0cCtrB83/hnzcwtWkFKUHCu2T1hS0FJuWrwLDpHNQznyzpGqzbyMXsijRWLN8NoMdDAjH0QXi7aMQ/dQuMWW4XaC1mr/mzVVwr+eS/zpPpqc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785166099624334.09131140724; Mon, 27 Jul 2026 08:28:19 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1woNFD-0005f1-6U; Mon, 27 Jul 2026 11:27:56 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1woMrH-0006m0-OV for qemu-devel@nongnu.org; Mon, 27 Jul 2026 11:03:12 -0400 Received: from tor.source.kernel.org ([2600:3c04:e001:324:0:1991:8:25]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1woMrG-0007B3-4x for qemu-devel@nongnu.org; Mon, 27 Jul 2026 11:03:11 -0400 Received: from smtp.kernel.org (quasi.space.kernel.org [100.103.45.18]) by tor.source.kernel.org (Postfix) with ESMTP id 7EACD601DE; Mon, 27 Jul 2026 15:03:05 +0000 (UTC) Received: by smtp.kernel.org (Postfix) with ESMTPSA id 823011F000E9; Mon, 27 Jul 2026 15:03:04 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1785164585; bh=OS5YQV4o6NpBgijEakeJsKx4uhqE5N3Wqh0IvH+4hPE=; h=From:To:Cc:Subject:Date; b=QB6vZI8LSpwYL2I+eFH+tKvolvWv/hBQqYjf05GWAafPSC7kOXHqXPgGJa6KzLhpj lrIC7uSCqfmfKOWPgckiw0X87WmtDTtc98CSPBcXHGboFTNr1N9URwty7GOUAY4Mku GjJaIqUSVD8uB8S7f1fW6EkfjahpKVBTpZrHvV/t6yJYE5eWqNPDDHXOQzp4UVeC24 81WHhMowPGn2Sgj3qee6aE5ZXUOTUYIOWlnYzYmFr9KTxjxL6Q6ee8Q4nRlEqDr+6r odz5eLRvX4tCEL8+oaMq5d2bYTWec3c+qZn3E9HZoDDqxiX/qq8qCkj+lDzrtMfuK9 hnjDm9sVfH4Ng== From: Tycho Andersen To: qemu-devel@nongnu.org Cc: Alex Williamson , =?UTF-8?q?C=C3=A9dric=20Le=20Goater?= , Steve Sistare , "Tycho Andersen (AMD)" Subject: [PATCH v1] hw/vfio: Fix liveness check in vfio_connect_kvm_msi_virq() Date: Mon, 27 Jul 2026 09:00:38 -0600 Message-ID: <20260727150038.2684512-1-tycho@kernel.org> X-Mailer: git-send-email 2.55.0 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=2600:3c04:e001:324:0:1991:8:25; envelope-from=tycho@kernel.org; helo=tor.source.kernel.org X-Spam_score_int: -36 X-Spam_score: -3.7 X-Spam_bar: --- X-Spam_report: (-3.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-Mailman-Approved-At: Mon, 27 Jul 2026 11:27:47 -0400 X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @kernel.org) X-ZM-MESSAGEID: 1785166101302158500 Content-Type: text/plain; charset="utf-8" From: "Tycho Andersen (AMD)" While working on savevm/loadvm for a new vfio device, I encountered the crash below. Since vfio_connect_kvm_msi_virq() didn't check the ->use flag for the vector, it would pass an unused vector down to vfio_cpr_load_vector_fd() which would crash. Fix this by checking the ->use flag along with the virq number to detect whether a vector is valid or not. Thread 1 "qemu-system-x86" received signal SIGSEGV, Segmentation fault. 0x0000555555a891ef in vfio_cpr_load_vector_fd (vdev=3Dvdev@entry=3D0x0, name=3Dname@entry=3D0x555555eeb27e "kvm_interrupt", nr=3Dnr@entry=3D1) = at ../hw/vfio/cpr.c:44 44 g_autofree char *fdname =3D STRDUP_VECTOR_FD_NAME(vdev, name); (gdb) bt #0 0x0000555555a891ef in vfio_cpr_load_vector_fd (vdev=3Dvdev@entry=3D0x0, name=3Dname@entry=3D0x555555eeb27e "kvm_inter= rupt", nr=3Dnr@entry=3D1) at ../hw/vfio/cpr.c:44 #1 0x0000555555ce64a1 in vfio_notifier_init (vdev=3D0x0, e=3De@entry=3D0x5555586971b4, name=3Dname@entry=3D0x555555= eeb27e "kvm_interrupt", nr=3Dnr@entry=3D1, errp=3Derrp@entry=3D0x0) at ../h= w/vfio/pci.c:79 #2 0x0000555555ce721e in vfio_connect_kvm_msi_virq (vector=3D0x5555586971a= 8, nr=3Dnr@entry=3D1) at ../hw/vfio/pci.c:601 #3 0x0000555555cea5a5 in vfio_connect_kvm_msi_virq (nr=3D1, vector=3D) at ../hw/vfio/pci.c:597 #4 vfio_pci_commit_kvm_msi_virq_batch (vdev=3D0x55555906de40) at ../hw/vfi= o/pci.c:822 #5 0x0000555555cea9f2 in vfio_msix_enable (vdev=3Dvdev@entry=3D0x55555906d= e40) at ../hw/vfio/pci.c:850 #6 0x0000555555ceb152 in vfio_pci_load_config (vbasedev=3D0x55555906e900, = f=3D) at ../hw/vfio/pci.c:3088 #7 0x0000555555a8c765 in vfio_load_device_config_state (f=3D0x5555574a43d0= , opaque=3D0x55555906e900) at ../hw/vfio/migration.c:278 #8 0x0000555555b3a522 in vmstate_load (f=3Df@entry=3D0x5555574a43d0, se=3Dse@entry=3D0x5555591edd40, errp=3De= rrp@entry=3D0x7fffffffe130) at ../migration/savevm.c:971 #9 0x0000555555b3ab1a in qemu_loadvm_section_start_full (f=3Df@entry=3D0x5555574a43d0, type=3Dtype@entry=3D4 '\004', errp=3Derr= p@entry=3D0x7fffffffe130) at ../migration/savevm.c:2654 #10 0x0000555555b3e1ee in qemu_loadvm_state_main (f=3Df@entry=3D0x5555574a43d0, mis=3Dmis@entry=3D0x5555571de5a0, errp= =3D0x7fffffffe130, errp@entry=3D0x555557157c10 ) at ../migration/savevm.c:2973 #11 0x0000555555b3f7b7 in qemu_loadvm_state (f=3Df@entry=3D0x5555574a43d0, errp=3Derrp@entry=3D0x555557157c10 ) at ../migration/savevm.c:3058 #12 0x0000555555b40863 in load_snapshot (name=3D0x7fffffffecc9 "foo", vmstate=3Dvmstate@entry=3D0x0, has_device= s=3Dhas_devices@entry=3Dfalse, devices=3Ddevices@entry=3D0x0, errp=3Derrp@e= ntry=3D0x555557157c10 ) at ../migration/savevm.c:3452 #13 0x0000555555adc211 in qmp_x_exit_preconfig (errp=3D0x555557157c10 ) at ../system/vl.c:2817 #14 qmp_x_exit_preconfig (errp=3D0x555557157c10 ) at ../system= /vl.c:2802 #15 0x0000555555adf8ed in qemu_init (argc=3D, argv=3D) at ../system/vl.c:3849 #16 0x00005555558903fd in main (argc=3D, argv=3D) at ../system/main.c:71 Fixes: 30edcb4d4e7a ("vfio-pci: preserve MSI") Signed-off-by: Tycho Andersen (AMD) Acked-by: Maciej S. Szmigiero # for CPR Reviewed-by: C=C3=A9dric Le Goater --- An alternative implementation of this would be to set ->virq =3D -1 after the allocation in vfio_msix_enable(), but since other locations that checks ->virq >=3D 0 also check ->use, I added it here too. Maybe it would be useful to do both. --- hw/vfio/pci.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hw/vfio/pci.c b/hw/vfio/pci.c index 380dd8c15f..b5280c3d2a 100644 --- a/hw/vfio/pci.c +++ b/hw/vfio/pci.c @@ -589,7 +589,7 @@ static void vfio_connect_kvm_msi_virq(VFIOMSIVector *ve= ctor, int nr) { const char *name =3D "kvm_interrupt"; =20 - if (vector->virq < 0) { + if (!vector->use || vector->virq < 0) { return; } =20 base-commit: 300438ffbb8d9430cac2fcc15cba6f482b2c0587 --=20 2.55.0