[PATCH] cryptodev: reject queue counts above the array limit

GuoHan Zhao posted 1 patch 2 months ago
Patches applied successfully (tree, apply log)
git fetch https://github.com/patchew-project/qemu tags/patchew/20260728111135.572426-1-zhaoguohan@kylinos.cn
Maintainers: "Gonglei (Arei)" <arei.gonglei@huawei.com>, zhenwei pi <zhenwei.pi@linux.dev>
backends/cryptodev.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
[PATCH] cryptodev: reject queue counts above the array limit
Posted by GuoHan Zhao 2 months ago
The queues property accepts any non-zero uint32_t, but
CryptoDevBackendPeers::ccs only has MAX_CRYPTO_QUEUE_NUM entries.

This can make even an error path crash.  For example, a builtin backend
with queues=65 first reports that it only supports one queue.  When the
half-created object is finalized, cleanup walks all 65 entries and reads
ccs[64].

Reject queue counts that do not fit in ccs[].

Fixes: 46fd17054548 ("cryptodev: introduce a new is_used property")
Signed-off-by: GuoHan Zhao <zhaoguohan@kylinos.cn>
---
 backends/cryptodev.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/backends/cryptodev.c b/backends/cryptodev.c
index e8f2b18f2017..84f00313e925 100644
--- a/backends/cryptodev.c
+++ b/backends/cryptodev.c
@@ -309,9 +309,9 @@ cryptodev_backend_set_queues(Object *obj, Visitor *v, const char *name,
     if (!visit_type_uint32(v, name, &value, errp)) {
         return;
     }
-    if (!value) {
-        error_setg(errp, "Property '%s.%s' doesn't take value '%" PRIu32 "'",
-                   object_get_typename(obj), name, value);
+    if (!value || value > MAX_CRYPTO_QUEUE_NUM) {
+        error_setg(errp, "Property '%s.%s' must be between 1 and %d",
+                   object_get_typename(obj), name, MAX_CRYPTO_QUEUE_NUM);
         return;
     }
     backend->conf.peers.queues = value;
-- 
2.43.0
Re: [PATCH] cryptodev: reject queue counts above the array limit
Posted by Philippe Mathieu-Daudé 2 months ago
On 28/7/26 13:11, GuoHan Zhao wrote:
> The queues property accepts any non-zero uint32_t, but
> CryptoDevBackendPeers::ccs only has MAX_CRYPTO_QUEUE_NUM entries.
> 
> This can make even an error path crash.  For example, a builtin backend
> with queues=65 first reports that it only supports one queue.  When the
> half-created object is finalized, cleanup walks all 65 entries and reads
> ccs[64].
> 
> Reject queue counts that do not fit in ccs[].
> 
> Fixes: 46fd17054548 ("cryptodev: introduce a new is_used property")
> Signed-off-by: GuoHan Zhao <zhaoguohan@kylinos.cn>
> ---
>   backends/cryptodev.c | 6 +++---
>   1 file changed, 3 insertions(+), 3 deletions(-)

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>