From nobody Mon Sep 28 01:59:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785254047; cv=none; d=zohomail.com; s=zohoarc; b=BlGoEuAbgl2Vv/NEIUYbnjPzgGM9Id9008251nZ3+5pXvjiQgkB+CuFTKrFLpK/Ut6MnhUykMOTALyeRMHp+xYwQcS/nts7212/rdGMUjNCax23JssqjueIz98VK9+5JbXpkS0v9a7CUpZKSD5LIQqwB14l8zxY28os9eU2bKGE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785254047; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=BKwNCkad/nDAoxO3VtxghR8FEOqxqC88f/O9yJcu0uI=; b=QTOAje74e3FZpD/9EyiC8iOAWIWUtBZ0PjSdDg8SWyJbADVhtPVfV31gxk0EUxjGhYC9D3rHoCWYm2b+SFg1HhRcmtshT59H5FZCbgmw8iCihnLFqECKuVKHwCuNpVRUls53gA86Ozp08NjfYEcZf/Td+OyVb/NG7KrPzZ1MR1E= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785254047066546.8632070641706; Tue, 28 Jul 2026 08:54:07 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wok7A-0002cY-3J; Tue, 28 Jul 2026 11:53:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wok78-0002bl-QQ for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:53:06 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wok76-0005dN-JB for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:53:06 -0400 Received: from mail-qt1-f199.google.com (mail-qt1-f199.google.com [209.85.160.199]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-79-e4Eu831-Meqj6ZfVO3S_WA-1; Tue, 28 Jul 2026 11:53:01 -0400 Received: by mail-qt1-f199.google.com with SMTP id d75a77b69052e-51bff5c7035so85504421cf.2 for ; Tue, 28 Jul 2026 08:53:01 -0700 (PDT) Received: from x1.com ([174.91.117.74]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-529e2dd54dbsm492481cf.23.2026.07.28.08.52.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 08:52:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785253983; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=BKwNCkad/nDAoxO3VtxghR8FEOqxqC88f/O9yJcu0uI=; b=B37QSVJ73bJ2KC5lLmYSLCV2cCvm1WiiWMV+wMbSUraa132M58To85jQJfeJ6d+MqGpn5t ULGagBC4QZ/Zx8KEgz0+qCiWV9gFfwUcacNi7vNMz+MInZ2C7Kah+JNBp7YW/Dx+ZQTzmA MkBZvdA0THw2iZJLO298vkO7DlPaQ0k= X-MC-Unique: e4Eu831-Meqj6ZfVO3S_WA-1 X-Mimecast-MFC-AGG-ID: e4Eu831-Meqj6ZfVO3S_WA_1785253981 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1785253981; x=1785858781; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=BKwNCkad/nDAoxO3VtxghR8FEOqxqC88f/O9yJcu0uI=; b=XpqC07RfDwoDuqzLnnlHuos07Kv29VVHzkBcfqqZure39khtiUfd99PhUUUR646Kfv OA1WkS2/zIKAOQDZAPjnGbGfJM0INFJ7pW9bEoZrUdmv32axXPfzUaNHMsZ9zjcenOOk YbsAtIWGfKfOxAtafeRPAeU8Naj4r4w/cqDdDs9b5FLk4lOuHJwBKtUPwhfnIxv7oizj LZjaNmshwHroqQlwNyvz0bWRbu25rhyGaTzSCMo5jALAuznItCN4hcLxUNA3abbkAUlT 9qPd0sR+ytG9CIoFalNZ1+yn9qIMRQ1H0uAv0VYWnnbnlXVNGlMR2QoN0yXtKUNUgKbu RmBA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785253981; x=1785858781; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=BKwNCkad/nDAoxO3VtxghR8FEOqxqC88f/O9yJcu0uI=; b=sU2Cm4RBzxQZiDunDEG0qM9fFLRY75fqnuSfnF+UWc1XNP4uUZtA2K0A8VhXZMlpwk BzKCnT1q5qa0eTwIOCEA1ER8S1i5XZhh2OfMcQITB8JMHcXBv8hUDHeHGSvimp2fx22r Z1M/WVZNSBjZbgQksJmLAVoXPCbcXG+zDvxmCeGITbqwpZr9RRAgkit6dA2HVcg8mEtz 3YMlwD1PO58XK+AmarAZOwtzOgNT9CcIF9GqpA06Oxt3EtJklSx+ejmB96ccyr9js4DV OjXb32EC+14aZ7VKsuHs8/LVnMMV8Tl+bockht4WbLCly3cIJHzBzVZm8a+ZDNYEAlVZ ylPw== X-Gm-Message-State: AOJu0Yy5tFwK5egWn8Pjbia/Y5+WA2KSmxsMzUKomycrhMumLt10KscB Q2YjizXc+QrK9F3axduCFXbD1GN8rXfC1iHGKzGAHrW/nms9nSDx04dRCcxTMRMyccKEsZPwSph crSkCH1pvA/VQIMvhbJVhrQOwFZeQ4PUsZLPL5E5+iAIWdydTrBIetxObYiKUFDHNtDJe128ou+ ewBhVN+GwyS5hBJCrNtL77wPNdu/k0PQ4Pfpkm2A== X-Gm-Gg: AR+sD10ijNy9zKoA98Gpk689rapaOIMqeE/Vzky6p0FVe/wbbpC7F2iyeVbN0PI/YhZ qRQg3llFjzPdxPXvOXg25U8FkzJKLyVvII8XMqR/09e2xO+n46B8a/utoCB5cEA8wZ2pTg6KwNm YwU1yv0aSLNcDIOxXcmUzQBBzRk3LDEHWZ4rhZvJDMVFFxd3+C0MedlrkQf6hgFXk/rf22X/1MD Rehz+RBzk314XJRZy6vThdpRWvgBWTlFHsCr9wBE2nBXlV91l0rPoWXnilMSQY2srjDGORKvSlx PhwBqfvW+tabhXnzy3nuI0qy3f4O29lek+paa39SNpmgLxNn9Htx1Ykr5LyxA8AJeg== X-Received: by 2002:a05:622a:111:b0:51c:1811:6eae with SMTP id d75a77b69052e-529d70eb754mr26494701cf.47.1785253980840; Tue, 28 Jul 2026 08:53:00 -0700 (PDT) X-Received: by 2002:a05:622a:111:b0:51c:1811:6eae with SMTP id d75a77b69052e-529d70eb754mr26494471cf.47.1785253980342; Tue, 28 Jul 2026 08:53:00 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: peterx@redhat.com, Fabiano Rosas , Juraj Marcin , Feifan Qian , qemu-stable , Peter Maydell Subject: [PATCH 1/5] migration: Fix possible overflow in vmstate_handle_alloc() Date: Tue, 28 Jul 2026 11:52:43 -0400 Message-ID: <20260728155247.1894355-2-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260728155247.1894355-1-peterx@redhat.com> References: <20260728155247.1894355-1-peterx@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -36 X-Spam_score: -3.7 X-Spam_bar: --- X-Spam_report: (-3.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785254048280158500 Content-Type: text/plain; charset="utf-8" Migration incoming side almost always trusted the stream data and allows allocation to happen with whatever size received. With it, malicious migration stream can manipulate destination QEMU behavior on g_malloc(), in path of vmstate_handle_alloc() on specific VMSD fields. Fix it by limiting all sizes with int32_t positive values (INT_MAX) explicitly. We have quite a few bug reports recently leveraging this defect. It can be reproduced in many ways for (I think) all archs binaries, but the simplest reproducer is: $ hexdump -C ./vm.img 00000000 51 45 56 4d 00 00 00 03 07 80 00 00 00 00 00 00 |QEVM........= ....| $ ./qemu-system-x86_64 -incoming file:./vm.img VNC server running on ::1:5900 qemu-system-x86_64: GLib: ../glib/gmem.c:106: failed to allocate 18446744= 071562067968 bytes Aborted (core dumped) ./qemu-system-x86_64 -incoming f= ile:./vm.img We could assert here, but since we have errp right above the stack this patch routes the errp over to allow destination QEMU fail gracefully. This means there's no way to DoS coredumpctl as well because we don't generate core dumps at all. The output message could also hopefully help triage issues when it's not a malicious stream but only wrong image used. When at this, making sure multiplex also won't overflow. After patched: $ ./qemu-system-x86_64 -incoming file:./vm.img VNC server running on ::1:5900 qemu-system-x86_64: load of migration failed: Invalid argument: vmstate_s= ize: VMState field 'name' overflow Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3805 Reported-by: Feifan Qian Reported-by: dong ling (@dongling226655) Cc: qemu-stable Cc: Peter Maydell Cc: Fabiano Rosas Signed-off-by: Peter Xu Reviewed-by: Fabiano Rosas --- migration/vmstate.c | 91 ++++++++++++++++++++++++++++++++++++++------- 1 file changed, 77 insertions(+), 14 deletions(-) diff --git a/migration/vmstate.c b/migration/vmstate.c index 50ebe37845..7bf0c2bae5 100644 --- a/migration/vmstate.c +++ b/migration/vmstate.c @@ -78,9 +78,10 @@ vmsd_init_ptr_marker_field(VMStateField *fake, const VMS= tateField *field) }; } =20 -static int vmstate_n_elems(void *opaque, const VMStateField *field) +static int32_t vmstate_n_elems(void *opaque, const VMStateField *field, + Error **errp) { - int n_elems =3D 1; + int32_t n_elems =3D 1; =20 if (field->flags & VMS_ARRAY) { n_elems =3D field->num; @@ -94,18 +95,35 @@ static int vmstate_n_elems(void *opaque, const VMStateF= ield *field) n_elems =3D *(uint8_t *)(opaque + field->num_offset); } =20 + if (n_elems < 0) { + error_setg(errp, "%s: VMState field '%s' num_offset overflow", + __func__, field->name); + return -EINVAL; + } + trace_vmstate_n_elems(field->name, n_elems); + return n_elems; } =20 -static int vmstate_size(void *opaque, const VMStateField *field) +static int32_t vmstate_size(void *opaque, const VMStateField *field, + Error **errp) { - int size; + int32_t size; =20 if (field->flags & VMS_VBUFFER) { + /* For both int32_t/uint32_t we only allow 2GB limit for VBUFFER */ size =3D *(int32_t *)(opaque + field->size_offset); + + /* Check this explicitly for untrusted length input first */ + if (size < 0) { + goto overflow; + } + if (field->flags & VMS_MULTIPLY) { - size *=3D field->size; + if (smul32_overflow(field->size, size, &size)) { + goto overflow; + } } } else if (field->flags & VMS_ARRAY_OF_POINTER) { /* @@ -115,21 +133,45 @@ static int vmstate_size(void *opaque, const VMStateFi= eld *field) size =3D sizeof(void *); } else { size =3D field->size; + assert(size >=3D 0); } =20 return size; + +overflow: + error_setg(errp, "%s: VMState field '%s' overflow", + __func__, field->name); + return -EINVAL; } =20 -static void vmstate_handle_alloc(void *ptr, const VMStateField *field, - void *opaque) +static bool vmstate_handle_alloc(void *ptr, const VMStateField *field, + void *opaque, Error **errp) { if (field->flags & VMS_POINTER && field->flags & VMS_ALLOC) { - gsize size =3D vmstate_size(opaque, field); - size *=3D vmstate_n_elems(opaque, field); + int32_t size, n; + + size =3D vmstate_size(opaque, field, errp); + if (size < 0) { + return false; + } + + n =3D vmstate_n_elems(opaque, field, errp); + if (n < 0) { + return false; + } + + if (smul32_overflow(size, n, &size)) { + error_setg(errp, "%s: VMState field '%s' multiply overflow", + __func__, field->name); + return false; + } + if (size) { *(void **)ptr =3D g_malloc(size); } } + + return true; } =20 static bool vmstate_ptr_marker_load(QEMUFile *f, bool *load_field, @@ -335,10 +377,22 @@ bool vmstate_load_vmsd(QEMUFile *f, const VMStateDesc= ription *vmsd, =20 if (exists) { void *first_elem =3D opaque + field->offset; - int i, n_elems =3D vmstate_n_elems(opaque, field); - int size =3D vmstate_size(opaque, field); + int i, n_elems =3D vmstate_n_elems(opaque, field, errp); + int size; + + if (n_elems < 0) { + return false; + } + + size =3D vmstate_size(opaque, field, errp); + if (size < 0) { + return false; + } + + if (!vmstate_handle_alloc(first_elem, field, opaque, errp)) { + return false; + } =20 - vmstate_handle_alloc(first_elem, field, opaque); if (field->flags & VMS_POINTER) { first_elem =3D *(void **)first_elem; assert(first_elem || !n_elems || !size); @@ -650,8 +704,7 @@ static bool vmstate_save_vmsd_v(QEMUFile *f, const VMSt= ateDescription *vmsd, while (field->name) { if (vmstate_field_exists(vmsd, field, opaque, version_id)) { void *first_elem =3D opaque + field->offset; - int i, n_elems =3D vmstate_n_elems(opaque, field); - int size =3D vmstate_size(opaque, field); + int i, n_elems =3D vmstate_n_elems(opaque, field, errp); JSONWriter *vmdesc_loop =3D vmdesc; bool is_prev_null =3D false; /* @@ -660,6 +713,16 @@ static bool vmstate_save_vmsd_v(QEMUFile *f, const VMS= tateDescription *vmsd, */ bool use_dynamic_array =3D field->flags & VMS_ARRAY_OF_POINTER_AUTO_ALLOC; + int32_t size; + + if (n_elems < 0) { + return false; + } + + size =3D vmstate_size(opaque, field, errp); + if (size < 0) { + return false; + } =20 trace_vmstate_save_state_loop(vmsd->name, field->name, n_elems= ); if (field->flags & VMS_POINTER) { --=20 2.54.0 From nobody Mon Sep 28 01:59:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785254024; cv=none; d=zohomail.com; s=zohoarc; b=LzT31kwrxsyIj8K8B0uatSl51VLxfpW4f65ZJrJwKlGfy/aPd0YfPc3qNi5cQqIy7nRG/yeAk2zlsHznhNZvXnG1moIqY27kj009BAf0MZ1AOdFbDux7eJEG2ngHah+YdGnMGTGmvDtJG8lV6BAEdoeboYEjAWWndqDr3kkcW48= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785254024; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=tXeiGT0Gtel66vemhZKpUjZ8zu7N7BIdzUq9Sor0hbE=; b=HkWBzrhSKhfnnDmRS4+Gj9XOnVyi3cOP2+0ym90PAAefWpBPy5+eLegQZkm4JBhvR4kSa0EKBIjOcqyLJP0fDJG3FzhRVBbCuy+rMFybvQMWi3Po3cugX3ZzPA0iwURECbjydXrnY3hsB64NLBaqrpPZ1jwnlwpXi+r2yHX5zxc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785254024213543.9612619525514; Tue, 28 Jul 2026 08:53:44 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wok7B-0002dw-TC; Tue, 28 Jul 2026 11:53:09 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wok79-0002cS-TL for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:53:07 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wok78-0005dg-6L for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:53:07 -0400 Received: from mail-qt1-f198.google.com (mail-qt1-f198.google.com [209.85.160.198]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-570-zw60VBUcMKSIC8usMVW0Dg-1; Tue, 28 Jul 2026 11:53:03 -0400 Received: by mail-qt1-f198.google.com with SMTP id d75a77b69052e-5276aa86d00so49000601cf.2 for ; Tue, 28 Jul 2026 08:53:03 -0700 (PDT) Received: from x1.com ([174.91.117.74]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-529e2dd54dbsm492481cf.23.2026.07.28.08.53.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 08:53:00 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785253985; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=tXeiGT0Gtel66vemhZKpUjZ8zu7N7BIdzUq9Sor0hbE=; b=bIfmbBlaQioUSsZClBv3b5Fjx/nLHfYwYvfHVx2m/IxZ90f7fAxxBnnT/SPJZvf0stS7fa eUG1nPRdZDj0JfrGg3Dz9L94FH42LQCqvbYBtSsbHHKQuFKKGKrWrTWG6LyAjE3sQoDGF2 USIs6g7oO5UBBEqOoI+1I61WdgkEQm0= X-MC-Unique: zw60VBUcMKSIC8usMVW0Dg-1 X-Mimecast-MFC-AGG-ID: zw60VBUcMKSIC8usMVW0Dg_1785253983 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1785253983; x=1785858783; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=tXeiGT0Gtel66vemhZKpUjZ8zu7N7BIdzUq9Sor0hbE=; b=C57Hl6wPCaTwF2x39jJRLpCWWyzfJ37ICGuXIWtMy2v56RImao6jRjLP9D8szAkmKe K9ShYRdTB9VcfwMnUHJ8RBu4YH9BPaCyqBnl8KcLOL5ApjiefxW0+xJHcDT8bPR4sUtH Zy8Ns8qeurq+bWWgqI1iO9NopuDKdb//9Q/RvdHUavxStqzFFXnshBogkfRxBKuucW3c OXtYXdYzRxPA808CV90FBpNHDzULiWoXnrl3v5yzzF9hfMjfx/4b4qMLsdGD1hM8aF3g qV4vMcnudAfjZNG1e71pFIgYFI2vvrV4+eoAQ5UNnQBSlbhX4DDCYncu7cZGlj9m+QU0 6nEw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785253983; x=1785858783; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=tXeiGT0Gtel66vemhZKpUjZ8zu7N7BIdzUq9Sor0hbE=; b=sJJjXZW42lJPWBL9iFwnyCdz2DKfby+RnOf8lHX7jObhyTusJ1byNCDqslph8ixKc4 axwCkA1tTmzmzGvMx9EvRwQ7cvRddhZeK/yNhVn84ex/wC/retUNEMzC4ChS3S3y/y1h sHIqA5D6JQewFMtxcWu6Cjlp35YZ+k9+iri2Nsbps8U+Nq7OfMMQNSMNu5woP0cdwzYc IzV3Jc23UEwV1eP/5m0WRJWPXEI2kq1sHRPAJ1tPb3YIpAGBvGUoUp6xMC59PAdzVxvi y89Vf8d2QK3FK+Qn3TONmfhXtXhdpGHBG5ITYGgjO540plHbhlHNF0pYsdqPq57cE+8i G5fQ== X-Gm-Message-State: AOJu0YxYClHOjE/4AwxfQYmfpizoxXFTnNmqsyrviUVgqPOcGvsusljv sG3h9SOCUj95C15cphU3EO+xKYhkvsS96OaZhV7T+/Eqx/BCakxp81GCYA1K52IsawoCZGy1OK5 5lXc+XjHOBAfwSFvmxsTsv+FlJmHPpSWE9OwyJYHGU5KDCRcuqfPwTWpifg+PVck92DzkIGISOM XtvlOz+/G2xbv44MEJjRXYBptZsiLHA4aHnEjlJw== X-Gm-Gg: AR+sD10i8kJafROELK6P49IyMqiAt03iaw3OfWHskCz04pY1rhU2n91nfyFZANlJcbp idu4neaijnXcIJkUqq7R1vfoWx2JV/Vd+y5j/71jEHtNHaTEhklpaZDhFkINliOEb5Ozn1COcbd NrwJPl9S5hpYVe0Y4ocTD3/RhNdnIboQ+ycoimzbv1CJmNOaFMEfQzSYLZ+r4ZLMEoagHZvIEj1 fZ7/sQAiYWDou0MXjbjU0BGvRtKZ5X29fTrTVKx3E6U+uFjjgtkyP7Jyz/htLuGTkAFxkC9RHdg aHNqwYBLyhbVVcMDOxmayj3fL4rrVxxdRhP/oXtOEYXOde8gvYqatQdZwMRHMwjUFw== X-Received: by 2002:a05:622a:1444:b0:517:8711:d466 with SMTP id d75a77b69052e-529d71034aemr26841121cf.56.1785253982912; Tue, 28 Jul 2026 08:53:02 -0700 (PDT) X-Received: by 2002:a05:622a:1444:b0:517:8711:d466 with SMTP id d75a77b69052e-529d71034aemr26840491cf.56.1785253982099; Tue, 28 Jul 2026 08:53:02 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: peterx@redhat.com, Fabiano Rosas , Juraj Marcin , xlabai , Jules Denardou , Tristan Madani , qemu-stable Subject: [PATCH 2/5] migration/multifd: Validate next_packet_size in zlib/zstd recv Date: Tue, 28 Jul 2026 11:52:44 -0400 Message-ID: <20260728155247.1894355-3-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260728155247.1894355-1-peterx@redhat.com> References: <20260728155247.1894355-1-peterx@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -36 X-Spam_score: -3.7 X-Spam_bar: --- X-Spam_report: (-3.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785254026604158500 Content-Type: text/plain; charset="utf-8" The zlib and zstd multifd compression backends read next_packet_size from the incoming migration stream and use it directly as the read length into a fixed-size buffer (MULTIFD_PACKET_SIZE * 2 =3D 1MB). A malicious migration source can set next_packet_size bigger than allocated, causing a heap buffer overflow write on the destination. Add a check against zbuff_len before reading, matching what the qatzip backend already does. Also replace the assert(in_size =3D=3D 0) for empty packets with proper error reporting, since the value is wire-controlled, meanwhile assert() stops working with release builds. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3737 Reported-by: xlabai Reported-by: Jules Denardou Reported-by: Tristan Madani Reported-by: david korczynski (@david1766) Reported-by: huntr bubble (@bubblehuntr) Cc: qemu-stable Cc: Fabiano Rosas Signed-off-by: Peter Xu Reviewed-by: Fabiano Rosas --- migration/multifd-zlib.c | 11 ++++++++++- migration/multifd-zstd.c | 11 ++++++++++- 2 files changed, 20 insertions(+), 2 deletions(-) diff --git a/migration/multifd-zlib.c b/migration/multifd-zlib.c index 8820b2a787..400146566e 100644 --- a/migration/multifd-zlib.c +++ b/migration/multifd-zlib.c @@ -216,10 +216,19 @@ static int multifd_zlib_recv(MultiFDRecvParams *p, Er= ror **errp) return -1; } =20 + if (in_size > z->zbuff_len) { + error_setg(errp, "multifd %u: next_packet_size %"PRIu32 + " exceeds allocated %"PRIu32, p->id, in_size, z->zbuff_= len); + return -1; + } + multifd_recv_zero_page_process(p); =20 if (!p->normal_num) { - assert(in_size =3D=3D 0); + if (in_size !=3D 0) { + error_setg(errp, "multifd %u: expected empty packet", p->id); + return -1; + } return 0; } =20 diff --git a/migration/multifd-zstd.c b/migration/multifd-zstd.c index 3c2dcf76b0..69ef1a5f38 100644 --- a/migration/multifd-zstd.c +++ b/migration/multifd-zstd.c @@ -210,10 +210,19 @@ static int multifd_zstd_recv(MultiFDRecvParams *p, Er= ror **errp) return -1; } =20 + if (in_size > z->zbuff_len) { + error_setg(errp, "multifd %u: next_packet_size %"PRIu32 + " exceeds allocated %"PRIu32, p->id, in_size, z->zbuff_= len); + return -1; + } + multifd_recv_zero_page_process(p); =20 if (!p->normal_num) { - assert(in_size =3D=3D 0); + if (in_size !=3D 0) { + error_setg(errp, "multifd %u: expected empty packet", p->id); + return -1; + } return 0; } =20 --=20 2.54.0 From nobody Mon Sep 28 01:59:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785254035; cv=none; d=zohomail.com; s=zohoarc; b=aiMcoDE+jwkemXRYQWY6W7ASpZo+MizQcB2pf5zz/iwY/IxbyC/+FOkxZQ276T9NWWPVZ9/HVP5qcEyQQRjjk2sGigMBt0kgF7AwqYikeTgSSXB3RS1ZUz0/d3qQwgbrkw9p8oAFSHY35JJkuGhI8dEuL0DmO3mqY+rSLM+ijgc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785254035; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=qsdEC238+EJ4wcu0RMnaKQsB+teECc3qnNE3oYsKC+s=; b=BJVZ2Y8VryYnBPB/Cicx4AMDYaBEMzhgqv+6+UUsKNLOJJzmBP0Ya45ioabtsySkrGMVPmik9ToCb6Ul1rtfjj6GHa7ryyehMgWBRo3ZS/bGqWD01KEYr+LWeN/yn0ur+jxgvjvsuPLGZoonf0NkeozYB0ssbFbQwFAXsH6pxAo= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785254035233419.6556670415796; Tue, 28 Jul 2026 08:53:55 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wok7C-0002ec-4b; Tue, 28 Jul 2026 11:53:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wok7B-0002dI-Jy for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:53:09 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wok79-0005e4-Vi for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:53:09 -0400 Received: from mail-qt1-f198.google.com (mail-qt1-f198.google.com [209.85.160.198]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-634-Qz7NMP1WPPqozj3_En0psQ-1; Tue, 28 Jul 2026 11:53:05 -0400 Received: by mail-qt1-f198.google.com with SMTP id d75a77b69052e-51bfe3fa93bso47665691cf.2 for ; Tue, 28 Jul 2026 08:53:05 -0700 (PDT) Received: from x1.com ([174.91.117.74]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-529e2dd54dbsm492481cf.23.2026.07.28.08.53.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 08:53:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785253987; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=qsdEC238+EJ4wcu0RMnaKQsB+teECc3qnNE3oYsKC+s=; b=bBhxPKSNcAusyYSpRfJBb/eNrMCpNrcQT84+KammZWQ/UqW7fTWP8VSguOr29oFDITomZV QrlWytMNRaflhCOXewY6EhYkVczGN2U+KPju4ZCtX3MTy6MIQzdTCcRWp50iUfDMk2ha9O puOuRintK/mfd4cK/CKCqwRP7gn410w= X-MC-Unique: Qz7NMP1WPPqozj3_En0psQ-1 X-Mimecast-MFC-AGG-ID: Qz7NMP1WPPqozj3_En0psQ_1785253985 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1785253985; x=1785858785; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=qsdEC238+EJ4wcu0RMnaKQsB+teECc3qnNE3oYsKC+s=; b=FoGZOQXENEbqvECyBchhlK8qXaos0GQuN9wyqWOWOv019NftasP2ds348q1VkUh2Y6 zXd0O3gZW1AeA7nrS2nSI97eDCnvir0v0Wt0KY61x3h11LbRC0oB0TPwEkGGFbDldUDi 8YMFLpx50TMI9wZE31kDXG7D5K/pWqx+xtiC2sCkDlppMSA7R1OYyRtYIDOLmNCaPXUC 7tjDfEKb6BkFf5rA9iy41f3TrDxOpfPWU0hSbhZFQ8nMInxUHueiCgKgU5nlii7ZkEIA wvO2rOPxQ9dUB6YaYa+BuNtYR/iEmHUXlsbTw7CP5nlWHCMpWRxZ6mI7As7vFScNHdaE +aWQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785253985; x=1785858785; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=qsdEC238+EJ4wcu0RMnaKQsB+teECc3qnNE3oYsKC+s=; b=WG2jmJjWGmoiyadOBcrpF64WPtC3HuyE9O5nu7cMLCsSdFS6jQ2acgeqC/bGRPgXss 69uGmAUCox6qbw/GAxm1pOzDfkOM/BiyXXmDroWWuu+nFOzld7TfjLyEPztqs0ZiMxS8 tgzG0NxP6kSRvM2ELZclvwdro4/nAIxtskPjFwAC1VPm6EkHBoqlBwaAMTgEm7xghi7d YPesHbD3G+QLhIO9X2RY1vatWdNXfDoELrt4BU4w6oE++NTZtXN1nk0bToOyZkwJgLmi 31TLKXQK21NwS1vLMSa9F+WJGFSamQkXV3GGZrij/a7IKmY9OuUp8S4YVM8D/i0QfdWx QZQw== X-Gm-Message-State: AOJu0YwwNVdhQGHfY4uad36U5xi8SQq23g15NTK0lUs48XmZL3lqRkMl PqCEFY0UA7obO/ur9msbyEcAaOqhjpao4mBdKOby6KJjBTOks6FiWFy8R+6yYhzvevLabPaS6fd xbQI6hmishsJNUZT24PuJuQlvlYwhQGe4VE/3L7ZAuAiwxZ7UAt/nd4NQqZLYxB+AqW36+lW8W0 PE8SNPMlb11LYzUDuUsTGqTGXaX//bSrrgW2R3fg== X-Gm-Gg: AR+sD12PO6Pm+HvTwwdzKyGy/EeBLS3BxnP5iveaw3CNI7wf8SRxjOuYlNZUEvFKota h9AbwyPq3REZzSCmPaAfAnR+b8TqeC19TePqF9Ca5KMbtC60L/gD189P9/aaMjZsOoqkFDOGTEm BxIHz9EXsWu+8d16M1GWgUuoTjIQowdUvyDHMiuESY+Lw8h4f4zN83vJ9ZXq0gVsjIsolVwdAzR KDAOj2xeTnMq6HXtvqo/97I/I3ZFMdAybVxJ/xOj7kM5KwJp6rkhTsgxPawMtkrrHRwUCc/6eUE EV38rfcwIi73Z9keEDGz6U+vRfhKaEiNbVDKwpUGYn3oK8SOm4gRya90eLQh0gOFFw== X-Received: by 2002:a05:622a:5a13:b0:51c:1005:d096 with SMTP id d75a77b69052e-529d6ffc1f2mr27787671cf.24.1785253984766; Tue, 28 Jul 2026 08:53:04 -0700 (PDT) X-Received: by 2002:a05:622a:5a13:b0:51c:1005:d096 with SMTP id d75a77b69052e-529d6ffc1f2mr27787031cf.24.1785253984083; Tue, 28 Jul 2026 08:53:04 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: peterx@redhat.com, Fabiano Rosas , Juraj Marcin , qemu-stable , Yuan Liu , Yichen Wang Subject: [PATCH 3/5] migration/multifd: Replace assert() with error_setg() in recv paths Date: Tue, 28 Jul 2026 11:52:45 -0400 Message-ID: <20260728155247.1894355-4-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260728155247.1894355-1-peterx@redhat.com> References: <20260728155247.1894355-1-peterx@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -36 X-Spam_score: -3.7 X-Spam_bar: --- X-Spam_report: (-3.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785254036169158500 Content-Type: text/plain; charset="utf-8" QPL and UADK multifd backends use assert() to validate wire-controlled fields like per-page compressed lengths and packet size consistency. These asserts will stop working with released version of binaries, so may stop working. Replace all assert() calls in the receive path with proper error_setg() so validation failures are reported gracefully rather than crashing or silently ignored. While at it, touch up an assert() in qatzip recv path too. Cc: qemu-stable Cc: Fabiano Rosas Cc: Yuan Liu Cc: Yichen Wang Signed-off-by: Peter Xu Reviewed-by: Fabiano Rosas --- migration/multifd-qatzip.c | 5 ++++- migration/multifd-qpl.c | 24 ++++++++++++++++++++---- migration/multifd-uadk.c | 24 ++++++++++++++++++++---- 3 files changed, 44 insertions(+), 9 deletions(-) diff --git a/migration/multifd-qatzip.c b/migration/multifd-qatzip.c index 7419e5dc0d..0262e81eac 100644 --- a/migration/multifd-qatzip.c +++ b/migration/multifd-qatzip.c @@ -348,7 +348,10 @@ static int qatzip_recv(MultiFDRecvParams *p, Error **e= rrp) =20 multifd_recv_zero_page_process(p); if (!p->normal_num) { - assert(in_size =3D=3D 0); + if (in_size !=3D 0) { + error_setg(errp, "multifd %u: expected empty packet", p->id); + return -1; + } return 0; } =20 diff --git a/migration/multifd-qpl.c b/migration/multifd-qpl.c index 52902eb00c..3826e7f340 100644 --- a/migration/multifd-qpl.c +++ b/migration/multifd-qpl.c @@ -664,26 +664,42 @@ static int multifd_qpl_recv(MultiFDRecvParams *p, Err= or **errp) } multifd_recv_zero_page_process(p); if (!p->normal_num) { - assert(in_size =3D=3D 0); + if (in_size !=3D 0) { + error_setg(errp, "multifd %u: expected empty packet", p->id); + return -1; + } return 0; } =20 /* read compressed page lengths */ len =3D p->normal_num * sizeof(uint32_t); - assert(len < in_size); + if (len >=3D in_size) { + error_setg(errp, "multifd %u: header len %"PRIu32 + " >=3D packet size %"PRIu32, p->id, len, in_size); + return -1; + } ret =3D qio_channel_read_all(p->c, (void *) qpl->zlen, len, errp); if (ret !=3D 0) { return ret; } for (int i =3D 0; i < p->normal_num; i++) { qpl->zlen[i] =3D be32_to_cpu(qpl->zlen[i]); - assert(qpl->zlen[i] <=3D multifd_ram_page_size()); + if (qpl->zlen[i] > multifd_ram_page_size()) { + error_setg(errp, "multifd %u: page %d compressed len %" + PRIu32" too large", p->id, i, qpl->zlen[i]); + return -1; + } zbuf_len +=3D qpl->zlen[i]; ramblock_recv_bitmap_set_offset(p->block, p->normal[i]); } =20 /* read compressed pages */ - assert(in_size =3D=3D len + zbuf_len); + if (in_size !=3D len + zbuf_len) { + error_setg(errp, "multifd %u: packet size %"PRIu32 + " !=3D header %"PRIu32" + data %"PRIu32, + p->id, in_size, len, zbuf_len); + return -1; + } ret =3D qio_channel_read_all(p->c, (void *) qpl->zbuf, zbuf_len, errp); if (ret !=3D 0) { return ret; diff --git a/migration/multifd-uadk.c b/migration/multifd-uadk.c index fd7cd9b5e8..d373615ba8 100644 --- a/migration/multifd-uadk.c +++ b/migration/multifd-uadk.c @@ -245,12 +245,19 @@ static int multifd_uadk_recv(MultiFDRecvParams *p, Er= ror **errp) =20 multifd_recv_zero_page_process(p); if (!p->normal_num) { - assert(in_size =3D=3D 0); + if (in_size !=3D 0) { + error_setg(errp, "multifd %u: expected empty packet", p->id); + return -1; + } return 0; } =20 /* read compressed data lengths */ - assert(hdr_len < in_size); + if (hdr_len >=3D in_size) { + error_setg(errp, "multifd %u: header len %"PRIu32 + " >=3D packet size %"PRIu32, p->id, hdr_len, in_size); + return -1; + } ret =3D qio_channel_read_all(p->c, (void *) uadk_data->buf_hdr, hdr_len, errp); if (ret !=3D 0) { @@ -259,12 +266,21 @@ static int multifd_uadk_recv(MultiFDRecvParams *p, Er= ror **errp) =20 for (int i =3D 0; i < p->normal_num; i++) { uadk_data->buf_hdr[i] =3D be32_to_cpu(uadk_data->buf_hdr[i]); + if (uadk_data->buf_hdr[i] > page_size) { + error_setg(errp, "multifd %u: page %d compressed len %"PRIu32 + " too large", p->id, i, uadk_data->buf_hdr[i]); + return -1; + } data_len +=3D uadk_data->buf_hdr[i]; - assert(uadk_data->buf_hdr[i] <=3D page_size); } =20 /* read compressed data */ - assert(in_size =3D=3D hdr_len + data_len); + if (in_size !=3D hdr_len + data_len) { + error_setg(errp, "multifd %u: packet size %"PRIu32 + " !=3D header %"PRIu32" + data %"PRIu32, + p->id, in_size, hdr_len, data_len); + return -1; + } ret =3D qio_channel_read_all(p->c, (void *)buf, data_len, errp); if (ret !=3D 0) { return ret; --=20 2.54.0 From nobody Mon Sep 28 01:59:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785254023; cv=none; d=zohomail.com; s=zohoarc; b=l7BYdYqH2tBMXICyJwvV6AJrLfmk0KX7/uEaNEGBc344rWJZE/rvgzEI791VIay5LveIlXaMl8oX2NJTffP6382I/thTI55VNm8xwxoOzdTInNWQytCWFH7efpMaRUdwlJ7uQEUA7QzP7oH9RD+pRr9UGt+Oed3+aZ1CiUoMKnY= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785254023; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=9yDobXnYDvJMRh3IPnfoTjQ6eQkvxTiCfvj1rQ0oHcs=; b=atxTWeT02IXa9+P1SFhfUmjy0s07u2fJzDb4Lx50I9Y63va7y7s0XD2WqBZbCRz+dgDqgtFHKaZ57Dcan+9a97bjvqoGOoc1s8TrtXa05eLgZ9iLJi5Y8byR1YiemwLDw3oM7WIFoLDUFs8WluBxUfYLawOmN1MiGaComZfPBCE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785254023963690.9178494440388; Tue, 28 Jul 2026 08:53:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wok7E-0002gI-LA; Tue, 28 Jul 2026 11:53:12 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wok7C-0002f6-Uu for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:53:10 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wok7A-0005eG-QO for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:53:10 -0400 Received: from mail-qt1-f198.google.com (mail-qt1-f198.google.com [209.85.160.198]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-617-WNCtDoSCNgWIXu4pULzWQw-1; Tue, 28 Jul 2026 11:53:06 -0400 Received: by mail-qt1-f198.google.com with SMTP id d75a77b69052e-5283df62d68so101101cf.0 for ; Tue, 28 Jul 2026 08:53:06 -0700 (PDT) Received: from x1.com ([174.91.117.74]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-529e2dd54dbsm492481cf.23.2026.07.28.08.53.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 08:53:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785253988; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=9yDobXnYDvJMRh3IPnfoTjQ6eQkvxTiCfvj1rQ0oHcs=; b=PLj6HRas0IX54Sj8YtKUv3GV1YByN/wkqzYP5qnBzAUzuqcsW7H1JERrphEjDnoG4xswSE 8I9dmZ1xhs3PhYnUeIsRe7DeFXIMKQ32kBD30sZ/EFCHLCf+z6r8bKWirudk+VQFZUZGfq vRzhpdST8fGjTAYfRwqVdyLvnuBemGc= X-MC-Unique: WNCtDoSCNgWIXu4pULzWQw-1 X-Mimecast-MFC-AGG-ID: WNCtDoSCNgWIXu4pULzWQw_1785253986 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1785253986; x=1785858786; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=9yDobXnYDvJMRh3IPnfoTjQ6eQkvxTiCfvj1rQ0oHcs=; b=m/Do4qV9s6H8Q+MLyVTndb8WMIaV+csMGBZQ8qLCf/B81AI4HX+uQ49KsrkDFsod5e /1FIrIhKSaBP04kXzDdTyqVzn2iatzazEy19CRdE9KkBk7XhXP0vM9G6KpEe6gPiSTvi 0UIZxb5nvJBgD9BUGcbJgh4v4VuZgebh6//GhGl1cPHhqSnlITqk+/emyUvp5+g/hDAq fg4sD9xJnmzu6GlvJcBFfQU7UczT7Ju8Kd7mo6EQYNksfzw8uXhLb6zo1GB1z9nqOpds skfcW7kjjn/kTrwknw4Qr5VUpLSARYPiDo93f+VV0UwTNce7UwGLeUBFqX3Fz8m8mV5S t4Yw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785253986; x=1785858786; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=9yDobXnYDvJMRh3IPnfoTjQ6eQkvxTiCfvj1rQ0oHcs=; b=A/veZVNZIw1N9Pu3BP/D6SVDEDgrbbPlt/f8d+J4jQqgKVa5yg+DQEx3sGsLTJDEJk bbNzUmrLNd/q7x1oAdj8BJNd7aYj2tlRt91SFr/fHAMzzc7avcZT//MZy5zx02uVwrHB ALv3CzYhFMTw4EVaF+1hQWbaF2pPpGWfqCYKxEK6LiuZX6iHlE36aqZJ9sIwSt+OloCI oGD7uROtG+jV19nuYTLY5RU/kG532iSHAs0V3AxOKeYwjrlg83w0z0m7Oqm8SLaB9VGD mADWkB0pG+5rDSSP6p8kEHjOM3INjHRQycDieFPA/r0UWY4wN+TJYhmk3UCGCnDdJkeL Gb/A== X-Gm-Message-State: AOJu0Ywkhrujnj3ICVg5LNDJCP5zpUgLYP2btDM0pUNeY68J0/FQFc/V xG7TK8pLXqLB5h+IahQX0fUyhAn+nvBGS2Fd+oHsF1Sv3ooCKWpBqjSD4wQFLQpw1P0B7dzzPwj sHW4QZm0tDkKeErz+wyUngDlYMHhRlqDCpH+813qt5otTRagv8OpTymiUQXswGdRvBMqx0haqj1 yD7s8P2ZDE5pgrwYcmxSrRY6fGGQKV54hb1zpk8A== X-Gm-Gg: AR+sD12QEjgFZpCMEPvIufXXioySiz4mFtcy0EEabv6DuaR0jyVRVwwv6MBjPVgPjME ubEDR4Ku0AZIla9IZXpmi3YL3Fzc7B+VWX0oZe4/dUMg/eXpgl85h+1kdja24QI90tXydFIoLAF eoxgHhmtA8UD0LC+3SjDvFeFJc0e5KOw8l29fka3ddohjD+1//pN6O8X2NS0lOWrxJ1f7FxLcOt xHocLfOGG31nfuh3xB90jV9YvLFqm9H5I9a/tf76P1MQo3jgoDrVAtQku1tAb0EYOqVSqasrcm+ 6EHO00L5RlrGK2+vH0niKpCipiE1SML0ZybCL4ecXIOTGoeV3AHmSISCPcWNHLeZug== X-Received: by 2002:a05:622a:1f8b:b0:516:dbf6:f8e7 with SMTP id d75a77b69052e-529d6f9cd07mr28864681cf.17.1785253986156; Tue, 28 Jul 2026 08:53:06 -0700 (PDT) X-Received: by 2002:a05:622a:1f8b:b0:516:dbf6:f8e7 with SMTP id d75a77b69052e-529d6f9cd07mr28864151cf.17.1785253985502; Tue, 28 Jul 2026 08:53:05 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: peterx@redhat.com, Fabiano Rosas , Juraj Marcin , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , Feifan Qian Subject: [PATCH 4/5] migration: Fix rare hang of migration_channel_read_peek() Date: Tue, 28 Jul 2026 11:52:46 -0400 Message-ID: <20260728155247.1894355-5-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260728155247.1894355-1-peterx@redhat.com> References: <20260728155247.1894355-1-peterx@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -36 X-Spam_score: -3.7 X-Spam_bar: --- X-Spam_report: (-3.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785254026630158500 In an unlikely case, when a migration stream is attached to the destination QEMU and only send <4 bytes to the channel as magic, it's possible that migration_channel_read_peek() may spin forever without yielding in the main thread causing two unwanted consequences: - CPU will spin 100% waiting for the rest bytes until it reaches 4 - (more importantly..) Main thread is stuck during this process as the qio operation won't really yield the coroutine Fix it by consuming the bytes that arrived. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3889 Cc: Daniel P. Berrang=C3=A9 Reported-by: Feifan Qian Signed-off-by: Peter Xu Reviewed-by: Daniel P. Berrang=C3=A9 --- migration/channel.c | 26 +++++++++++++++++++++++--- 1 file changed, 23 insertions(+), 3 deletions(-) diff --git a/migration/channel.c b/migration/channel.c index 1e2935f926..28fe1d2906 100644 --- a/migration/channel.c +++ b/migration/channel.c @@ -294,11 +294,31 @@ int migration_channel_read_peek(QIOChannel *ioc, return -1; } =20 - if (len =3D=3D buflen) { + if (len =3D=3D iov.iov_len) { break; - } + } else if (len =3D=3D 0) { + qio_channel_wait_cond(ioc, G_IO_IN); + } else { + ssize_t received =3D len; =20 - qio_channel_wait_cond(ioc, G_IO_IN); + /* + * Partially arrived, read out to make qio_channel_wait_cond() + * won't return immediately, causing an unwanted spin on this + * CPU. + */ + iov.iov_len =3D len; + len =3D qio_channel_readv_full(ioc, &iov, 1, NULL, NULL, 0, er= rp); + /* + * QIO_CHANNEL_ERR_BLOCK also shouldn't happen, due to the + * prior peek just happened. We should be pretty sure we will + * read what we peeked, or the channel was broken. + */ + if (len !=3D received) { + return -1; + } + iov.iov_base +=3D received; + iov.iov_len =3D buflen - received; + } } =20 return 0; --=20 2.54.0 From nobody Mon Sep 28 01:59:50 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785254061; cv=none; d=zohomail.com; s=zohoarc; b=Kc0fFGgXVgMcg8TKLNs6Ez0A2rZk7eNVJLasmDA5HvGK6Q4Qpx1n2Gf7HdbU6QwJ/ElwdIw08vPbzOny8k0TPE/IBgOt1YGJCTeKcXOJD+MW8JGggryj0A8dMZoEBUfqR90Oo3PANXjmzJjxD9IEWueUlP27S5znF2GUyqhcTDM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785254061; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=IsC7scSoMMwxbuUHpN2mbAKsPK+vpKAPH5cRD66AqaQ=; b=VmhZZofmuOQ5aT5jjMRbDHO998uGDrAh7a/iaxKYaXBeb1bqKLP3hPvKcbbbLGg7UDV+AZzDL2er8j2kP38/w29lCTBbFA9QG71xBvyP1Pzko3MuOc+2/HdcDHMLQCmhIAzP7qp+NNfvTn/NZzcdlLT4fW7RfQc9xV3nqm5/R5s= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785254061227626.0417614901475; Tue, 28 Jul 2026 08:54:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wok7H-0002gq-LB; Tue, 28 Jul 2026 11:53:15 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wok7G-0002gb-Jo for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:53:14 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wok7F-0005ek-5S for qemu-devel@nongnu.org; Tue, 28 Jul 2026 11:53:14 -0400 Received: from mail-qt1-f200.google.com (mail-qt1-f200.google.com [209.85.160.200]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-361-ocCAiCRFMrK7QV9TDi6YHQ-1; Tue, 28 Jul 2026 11:53:09 -0400 Received: by mail-qt1-f200.google.com with SMTP id d75a77b69052e-51c1eb52e1fso74451991cf.0 for ; Tue, 28 Jul 2026 08:53:08 -0700 (PDT) Received: from x1.com ([174.91.117.74]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-529e2dd54dbsm492481cf.23.2026.07.28.08.53.05 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 08:53:06 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785253992; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=IsC7scSoMMwxbuUHpN2mbAKsPK+vpKAPH5cRD66AqaQ=; b=YLbMZmiIuFi1ERE7gnakgsMkxvxCcZHNACLlvtpkIcEHq8T3nJ+rDGmNoX+oH73mHhvsgj S+tr/hvOzeIVFItLZ3KpT1MaY1xkwrUCUywmRfxIEQ6ruioSmYkST4GVz5XZGRQlR2zci8 +ixEs94kJlymKMKaaOXMZqu8KzLMj3E= X-MC-Unique: ocCAiCRFMrK7QV9TDi6YHQ-1 X-Mimecast-MFC-AGG-ID: ocCAiCRFMrK7QV9TDi6YHQ_1785253988 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1785253988; x=1785858788; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=IsC7scSoMMwxbuUHpN2mbAKsPK+vpKAPH5cRD66AqaQ=; b=iwXAW5Xy/SYs18/K5pHU34L1wX7aGljlMrvnyxIL6i6Q1+SLD5S+Mk1BToqIyIdBPY t5/5Bse6huOWSKo1VI3kwWC1xvsOtW0+PHCMR68j+r+DIxhqOgbV2wwBnYNqm7rcqMLc Hadut+piGIGCrvLuRHKZiIseVLkGDrtP+tXN/TDIoZWtaSrjOR5qX7wfKob61XJur4bg eNhqcKDRt3J/Zg3mQmuCfJUZ97rfRIAk1R8TdYyk5Q0yyN5URwXzwcPM/3RXZ+Fw7CuJ wdXGCcR6heJvKTqYGYXg+VmO7HUvY2j+fh3v3c1u7g2gdfgsV9tssq9+6X+0DI4Z4rkt FL6Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785253988; x=1785858788; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=IsC7scSoMMwxbuUHpN2mbAKsPK+vpKAPH5cRD66AqaQ=; b=WA0efRxmSdl/dT5pfB39wcd9kj28+GtIl8YpNm4ryqzByD5TRtifUi1ou4h9zU56b+ fjVwDfi8dOkln4flyM3n2vjGrBKHTCy5lhR1Nch0VMzk++GXdXyyQ68rtC2QJD4PFOXM l67hnB5cWpZ2+VR4jNI7yefUH2ExK22sa97qRcmftF5COXV/GL3VrOmPymvOyzj1N4Bl bVi3pgBgUSHy0ifG7JnmeUrzLHvJtUpT8dDIQUlW6jsv+ELZxIE9Pt/H4NLEKDrfm5UM LQgi5MqMLonqg1O2Gh70BuKQfPBVKH9XEo9TCudKSBR6RvJy0b4CI1oMSJXmOMBqcNAA 2VPA== X-Gm-Message-State: AOJu0YwRZdtYPET+HdPUesQIwRgWF/2Dc5zICb5WXEw++qkI5zS01kq+ ytGSKQtJsU9fQxVZMJprCNcINItILYhczrv6YhWYPEpt8/R5bDslZlAvnmVbUussyyL98d2ZnSn M39BxG8hFcXxNkZvrk1M6erKPHkFGmZw43dYw5t8cwuc6ZPv3xtSkzUGONHxLwDS3VRMjyUs/v/ V/X1WXQFMAgpS1STY58jWDXX/8X7y24K0wxHA0/g== X-Gm-Gg: AR+sD11BNHmOCtox0csxQ2EyeHjZAdBmU6MuBiuOR24MBzF95m2NtpLIqziEtle7SRE L9hM8E8zqr4GJvcxhrRqEXhlGJRPRSJUumgZnwc8M3CHIs40+guaNNGGRr+IBcxDkhe1GWCHZUt xu0pBbUawTkdrA3nyUmHW2CJr0oMgKFkD7UbqSWc90hm9gFF4ix6xca87qqEuTD6YDxogFYmVUY Ax0DqBSuBDSg8quSPdGVYDWRBhfFHRDOGGouuYnsaNdlzVTkIPits6bZ06kcVASGPZ7KH2Rm2e4 PhKHYiydC5o6fuwSxG//YIT1xI1NhduKfE6nYBV6CLaMIjxJyuFciD1y8aplN4EVWA== X-Received: by 2002:a05:622a:1c07:b0:517:b68a:8d84 with SMTP id d75a77b69052e-529d70eb27emr26288781cf.56.1785253987974; Tue, 28 Jul 2026 08:53:07 -0700 (PDT) X-Received: by 2002:a05:622a:1c07:b0:517:b68a:8d84 with SMTP id d75a77b69052e-529d70eb27emr26288411cf.56.1785253987401; Tue, 28 Jul 2026 08:53:07 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: peterx@redhat.com, Fabiano Rosas , Juraj Marcin , Tristan Madani Subject: [PATCH 5/5] migration/ram: Check for RAMBlock size mismatch when parsing Date: Tue, 28 Jul 2026 11:52:47 -0400 Message-ID: <20260728155247.1894355-6-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260728155247.1894355-1-peterx@redhat.com> References: <20260728155247.1894355-1-peterx@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -36 X-Spam_score: -3.7 X-Spam_bar: --- X-Spam_report: (-3.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785254062337158500 Content-Type: text/plain; charset="utf-8" Add an underflow check for the subtract of total RAMBlock size to make sure it won't underflow. It should not happen in production systems but only if the migration stream was hijacked, which is not a real concern since migration channel is trusted. Still protect against it. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4013 Reported-by: Tristan Madani Signed-off-by: Peter Xu Reviewed-by: Fabiano Rosas --- migration/ram.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/migration/ram.c b/migration/ram.c index 8918b2f03b..85feff578c 100644 --- a/migration/ram.c +++ b/migration/ram.c @@ -4268,7 +4268,7 @@ static int parse_ramblocks(QEMUFile *f, ram_addr_t to= tal_ram_bytes) int ret =3D 0; =20 /* Synchronize RAM block list */ - while (!ret && total_ram_bytes) { + while (total_ram_bytes) { RAMBlock *block; char id[256]; ram_addr_t length; @@ -4285,8 +4285,15 @@ static int parse_ramblocks(QEMUFile *f, ram_addr_t t= otal_ram_bytes) error_report("Unknown ramblock \"%s\", cannot accept " "migration", id); ret =3D -EINVAL; + break; + } + + if (usub64_overflow(total_ram_bytes, length, &total_ram_bytes)) { + error_report("%s: RAMBlock '%s' size underflow total RAM size", + __func__, block->idstr); + ret =3D -EFAULT; + break; } - total_ram_bytes -=3D length; } =20 return ret; --=20 2.54.0