From nobody Mon Sep 28 02:01:08 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785253223; cv=none; d=zohomail.com; s=zohoarc; b=lCtRB6++ViNHVB1tRbWdzPvyJfxzO0uhrPRWTTjfhg7wsCfTx9yvhFLLwhTUg9o4a0Br9x34bZ6YcEwSXto/38CGwFS5ksufI71/ZJK1A1W+/zrvSlgCgjdyPI7zTaghnIoubZAzoCYwfAT3DJnGzKPXK/JdXEMl5rWxekwmrQg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785253223; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=dKgIX1Wog//EVWZwPllS3MiXsHvu6/rPB595bN/eOZI=; b=T7hmFuRWlTpnCI81VoM1/234wdpdHkUjHMbdgWaD4KKTgnq053ugPNIh0pjYwUtKBVxgkFjzpofm+Ee28AhzgkbkPBN3iEqcIwl6kJow7siaEZ+EDwL9xeBwgS7X7Gxkz+4wsuXiefJJjWfKTgu7JByXtaeF6KRNfshKD11VNOM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785253223773629.7162785567673; Tue, 28 Jul 2026 08:40:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wojuc-0006PA-2u; Tue, 28 Jul 2026 11:40:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wojuW-0006FL-8Q for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:40:05 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wojuT-0002wR-Ve for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:40:03 -0400 Received: from mail-qk1-f199.google.com (mail-qk1-f199.google.com [209.85.222.199]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-404-UusUzVdtNry_ts19halrRw-1; Tue, 28 Jul 2026 11:39:58 -0400 Received: by mail-qk1-f199.google.com with SMTP id af79cd13be357-9308eafb465so1687985a.2 for ; Tue, 28 Jul 2026 08:39:58 -0700 (PDT) Received: from x1.com ([174.91.117.74]) by smtp.gmail.com with ESMTPSA id af79cd13be357-932de676a41sm867274085a.46.2026.07.28.08.39.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 08:39:56 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785253200; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=dKgIX1Wog//EVWZwPllS3MiXsHvu6/rPB595bN/eOZI=; b=RT4MjHhyokvlndoqcZQxk6s4xFTMbn81KsGmdUpS0LhBBR+MJMYRtQ4nxRDA0iZ3qC9K4G fHbXV+4AADCkq5l5L+tanNi6cySdNr0Ba4lYlmZ/7AJe7tOh2Eazc6J9vnBVoqCO1y8MQK AiaPQP09elRpQYrJnYXqxiLCI6QtY9k= X-MC-Unique: UusUzVdtNry_ts19halrRw-1 X-Mimecast-MFC-AGG-ID: UusUzVdtNry_ts19halrRw_1785253198 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1785253198; x=1785857998; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:from:to:cc:subject:date:message-id:reply-to :content-type; bh=dKgIX1Wog//EVWZwPllS3MiXsHvu6/rPB595bN/eOZI=; b=Gz7CNF8vtsFHgXOB67K0CKYBpx8scPB986NM7lXnquzCPHRm7Zd5SJMsbLHa+fikFs uXBNetK2vZMTBw6aCqVBkqojdLZaynlt+hm5vCBtu6Jsfa9O3rlqcyITBDWtyRcIQqzF 9AdGSfZR1Hbwp776rBGe6bfy3Xdwg35Tsn3bFbxrSLwKHVrxshCPrBsdyoHAsVD/++pv 7WFBDkFSRdGWxaNrjNVuF/AnMackq1u+m5qjylOrDORV2u8J1BZd8UDorMhDWyF+pPZr S/VVnW82X071Sjxq6BHeepzHYv4ek8ItUFfiWBKRkqY1UBx+JrLxJDOxhcH4JEeqzxW4 kzDA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785253198; x=1785857998; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=dKgIX1Wog//EVWZwPllS3MiXsHvu6/rPB595bN/eOZI=; b=rVKz9F+Pv0BEYTRY8CQF1Hjuwep5GJ866NYEmmHvjYDk9I58yFZWblf85SczioztX6 JHeST2HH9pmMMp/EsPPdcBZ9ziga45NvDSk96LM48S54VgeMWsGmROu8UWZnLNoBcZd8 pamBLxyZeNDSf65vdNoeuguoZPaDt/YtG2k5GFw8NaGyUXOUeCmNVluHqfvC6mTS/rCa VPZTfOmhucBaQcp+2EopEmswJlR+bsq//4bfNhogzGlzU9a4YRcylC5S6VLv6rXSMI9N GYWigrmRnxIaV3xBCNIs1FprFqzHKcSS63/C0DZjAe9J1OrVYZKiCINpLmJuJxzY7sIS oz5g== X-Gm-Message-State: AOJu0YweX41zAi8THbEMWSDI5tFcS98gNTvXicJCy98bSMTa5dOmIDwj 3NHUtetCG7CQX+WyOTVH1SsC4zVDR/Cl+Zqcxbx8Rwez1gCZ+Nzy7ZgMN0AoNTWJQmAUfTB7WO4 dsszOHVIw45ec5CnqFT2rfBDcDJqqpA4+KUIN4VgxEku/rDj8Imvf8Tk0QR+mdqWT25oYcG1TP4 NVBYuA0pPe9TAG2sXuA4FsioLw4Gs0jl8NSeK8Gw== X-Gm-Gg: AR+sD13Af80aju06Irk60h13AZ1Dxn+san+SiIxTGvg74rY9OqymwbIDG5FP53hCGl9 +v0Edpghb3oqHotIiofMuNBBwWaIAx5lf5FT8LD/dSMY35vgm1x0Eu45S0cZuJfAvd/go+DHvUC 8ujALYIw2Cf5BBLuHNuaD8os8UzO0Ud+J3cn1+etn5Cv6AFKfNPWbXvNZDYdCPnsbESdtbzNfOJ GkiXgYQK49hofuCvfNL7WsuaOp3XSqfW0ws6+qsVwSdUdyVJ4lZHfvo+MeLIQUeTQ8hqlGQa6Ps /k0sUr+5kJc7X5oBnWX7xyE9Ey6hj7PEt16elZX/zx0hjOiCEHoSfg9Co8RBHUIIWQ== X-Received: by 2002:a05:620a:3910:b0:92b:6805:91bc with SMTP id af79cd13be357-9330270bd62mr323675885a.68.1785253198164; Tue, 28 Jul 2026 08:39:58 -0700 (PDT) X-Received: by 2002:a05:620a:3910:b0:92b:6805:91bc with SMTP id af79cd13be357-9330270bd62mr323668285a.68.1785253197329; Tue, 28 Jul 2026 08:39:57 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: peterx@redhat.com, "Michael S. Tsirkin" , Fabiano Rosas , Stefano Garzarella , =?UTF-8?q?=EA=B9=80=EC=8A=B9=EC=A4=91?= , Alexandr Moshkov Subject: [PATCH] vhost/migration: Fix incorrect size used in inflight->addr in VMSD Date: Tue, 28 Jul 2026 11:39:42 -0400 Message-ID: <20260728153942.1891677-1-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -36 X-Spam_score: -3.7 X-Spam_bar: --- X-Spam_report: (-3.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785253225343158500 It was overlooked that VMSTATE_VBUFFER_UINT64() won't really work with an uint64_t, as vmstate core only treats the size as 32bits, and maximum INT32_MAX (see vmstate_size()). Considering that we do not need real 64bits for the size, stick with the 2G limit, converting the size field into 32bits. Since we can't touch the wire protocol on migration from an old QEMU, we can't directly modify the type of size to uint32_t. Instead, we need to introduce a temporary variable for this extremely rare issue __size_32bits to be used only for VMSTATE_VBUFFER_UINT32(). Document it and name it weird enough so people won't get confused on having two size variables. Remove VMSTATE_VBUFFER_UINT64() altogether, because it was never going to be used right. It means QEMU will only support 2G max for VMS_VBUFFER. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3675 Reported-by: =EA=B9=80=EC=8A=B9=EC=A4=91 Cc: Alexandr Moshkov Cc: Michael S. Tsirkin Cc: Fabiano Rosas Fixes: 3a80ff0721 ("vhost: add vmstate for inflight region with inner buffe= r") Signed-off-by: Peter Xu --- PS1: I only did smoke test as I'm not fluent with vhost inflight feature. Please kindly try it out if possible. In general, migrations from older QEMU should work even after applied. One can also treat this as partly-RFC from that. PS2: Michael, we have just discussed what we should define as CVE for migration, and this one shouldn't fall into CVE category, please refer to: https://lore.kernel.org/r/20260721131457.3062767-1-farosas@suse.de So I didn't yet attach CVE tag. Please correct if I'm wrong, thanks. --- include/hw/virtio/vhost.h | 5 +++++ include/migration/vmstate.h | 10 ---------- hw/virtio/vhost.c | 19 ++++++++++++++----- 3 files changed, 19 insertions(+), 15 deletions(-) diff --git a/include/hw/virtio/vhost.h b/include/hw/virtio/vhost.h index 684bafcaad..1d1cc24c04 100644 --- a/include/hw/virtio/vhost.h +++ b/include/hw/virtio/vhost.h @@ -17,6 +17,11 @@ struct vhost_inflight { int fd; void *addr; uint64_t size; + /* + * This is a temporary variable only used during migration loading to + * satisfy VMSTATE_VBUFFER_UINT32() typing. Please use @size otherwise. + */ + uint32_t __size_32bits; uint64_t offset; uint16_t queue_size; }; diff --git a/include/migration/vmstate.h b/include/migration/vmstate.h index 1b7f295417..a349b2d84a 100644 --- a/include/migration/vmstate.h +++ b/include/migration/vmstate.h @@ -782,16 +782,6 @@ extern const VMStateInfo vmstate_info_g_byte_array; .offset =3D offsetof(_state, _field), \ } =20 -#define VMSTATE_VBUFFER_UINT64(_field, _state, _version, _test, _field_siz= e) { \ - .name =3D (stringify(_field)), \ - .version_id =3D (_version), \ - .field_exists =3D (_test), \ - .size_offset =3D vmstate_offset_value(_state, _field_size, uint64_t),\ - .info =3D &vmstate_info_buffer, \ - .flags =3D VMS_VBUFFER | VMS_POINTER, \ - .offset =3D offsetof(_state, _field), \ -} - #define VMSTATE_VBUFFER_ALLOC_UINT32(_field, _state, _version, \ _test, _field_size) { \ .name =3D (stringify(_field)), \ diff --git a/hw/virtio/vhost.c b/hw/virtio/vhost.c index af41841b52..e7c570d0f5 100644 --- a/hw/virtio/vhost.c +++ b/hw/virtio/vhost.c @@ -2022,15 +2022,24 @@ void vhost_get_features_ex(struct vhost_dev *hdev, static bool vhost_inflight_buffer_pre_load(void *opaque, Error **errp) { struct vhost_inflight *inflight =3D opaque; - int fd =3D -1; - void *addr =3D qemu_memfd_alloc("vhost-inflight", inflight->size, - F_SEAL_GROW | F_SEAL_SHRINK | F_SEAL_SEA= L, - &fd, errp); + void *addr; + + if (inflight->size > INT32_MAX) { + error_setg(errp, "inflight size '%"PRIu64"' exceeds " + "migration limit '%"PRIu32"'", inflight->size, INT32_MA= X); + return false; + } + + addr =3D qemu_memfd_alloc("vhost-inflight", inflight->size, + F_SEAL_GROW | F_SEAL_SHRINK | F_SEAL_SEAL, + &fd, errp); if (!addr) { return false; } =20 + /* Only used in VMSTATE_VBUFFER_UINT32() */ + inflight->__size_32bits =3D inflight->size; inflight->offset =3D 0; inflight->addr =3D addr; inflight->fd =3D fd; @@ -2042,7 +2051,7 @@ const VMStateDescription vmstate_vhost_inflight_regio= n_buffer =3D { .name =3D "vhost-inflight-region/buffer", .pre_load_errp =3D vhost_inflight_buffer_pre_load, .fields =3D (const VMStateField[]) { - VMSTATE_VBUFFER_UINT64(addr, struct vhost_inflight, 0, NULL, size), + VMSTATE_VBUFFER_UINT32(addr, struct vhost_inflight, 0, NULL, __siz= e_32bits), VMSTATE_END_OF_LIST() } }; --=20 2.54.0