From nobody Mon Sep 28 02:01:19 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785272704; cv=none; d=zohomail.com; s=zohoarc; b=AhSvDQoPN6Bnjj94lKytQ1+dQnuLAYyZxvOnCl59RxPmSqwNyazbZruZ6l2ncOt05AE/sxfg8sLpaYoXA+yMSHb4rb37Pe56l/G/CHzoUA3iY7wzvOjQbMRRvgEV8defkZu5bwQbZ+PRQkOKC7ytJGXrL/wMZR1wFAgAASKe3u4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785272704; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=VoCKTGTB00eE5rGMysylu8v8Cd44pkfWk8gVfgTvXSU=; b=QbKKYXB6UVSdnS+NY6sBUARd7WnDCkQCXJTMu2mJeCtZxxIEkKKrOGwxicimt83OnH/DzcjXobZAHoDbMFYeYMwHIZgR+gaGokjbh87vx50PrfUjBPQbKoZ6+59mpep3AuO2lrwkOY9cnuZ5BilLrBKUUbvdkLiG1DTSH+5NFYM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178527270491644.474831777013605; Tue, 28 Jul 2026 14:05:04 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wooye-0004U2-8P; Tue, 28 Jul 2026 17:04:41 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wooyX-0004TT-Gw for qemu-devel@nongnu.org; Tue, 28 Jul 2026 17:04:33 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wooyS-0003hO-Hm for qemu-devel@nongnu.org; Tue, 28 Jul 2026 17:04:33 -0400 Received: from mail-qk1-f199.google.com (mail-qk1-f199.google.com [209.85.222.199]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-636-ZPMnFipfOFGCbWunkRPqPA-1; Tue, 28 Jul 2026 17:04:25 -0400 Received: by mail-qk1-f199.google.com with SMTP id af79cd13be357-92e7ee64b25so53757985a.0 for ; Tue, 28 Jul 2026 14:04:25 -0700 (PDT) Received: from x1.com (bras-vprn-aurron9134w-lp130-03-174-91-117-74.dsl.bell.ca. [174.91.117.74]) by smtp.gmail.com with ESMTPSA id af79cd13be357-933d3227707sm21277985a.6.2026.07.28.14.04.22 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 14:04:23 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785272666; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=VoCKTGTB00eE5rGMysylu8v8Cd44pkfWk8gVfgTvXSU=; b=WbowbVJScI+uMbG7Tt41fVWThFLSnzmnqGL6Cr5jIMZOAXnSj+VrgaVW7lZvZhg4k8hSEj 4aRS8ODn0bok2kXYxEtheXm80p9SaFXKmC6voLyHj/mw0GkVZjDUosU/0neK7QUII2vR6F D5LtCPkqocolzEp1h5qzKvxFyZBsYvk= X-MC-Unique: ZPMnFipfOFGCbWunkRPqPA-1 X-Mimecast-MFC-AGG-ID: ZPMnFipfOFGCbWunkRPqPA_1785272665 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1785272665; x=1785877465; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VoCKTGTB00eE5rGMysylu8v8Cd44pkfWk8gVfgTvXSU=; b=FCVtdnhHteNYiQ9yzcf/4HNulTGjUgl6d8qMV5ept9eekEz8NSxhPXIB+FkQFff9nB GbfNj2FTcj7w//SAiWeTYNfPyQ2vVlpQpGoH/bObu/mITCL2r1zeDecqJ96iq8GhDnZK qlpLey7Quw2K0CwJ5w3Yg5SnEYmGdzfInCEC6q0X5xjcxl5Dxtpvqa97qR6XIUFuVQ4b WwxJSuptbHZi/sl0hsUs/0BeuLqNbNqTmJgQsYBlm81Xvq7rkLaPVbhHCMvH2vZPFzlU PguFoozSVzQz0lWtAXMuewBeT/2Ds/H5PyMr0fLzQYbcp4vdG5zx3PwVvZ/ujke1jHdr lvZA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785272665; x=1785877465; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=VoCKTGTB00eE5rGMysylu8v8Cd44pkfWk8gVfgTvXSU=; b=FeL8YybcmFJiMUCq1WmAIfP7amS7L4jvjRHPSrgyBM5nAqYipfD+59zYmR62Oqr8TC pINRsG8M+k8ri3BI5STofQKb7fphT00QLWpc1swl4s2NYjp3aCUtJO7XFgw/qNqfv38v S/2p9j2gByw2F+wkLrkKm0t0bTSV5WQ/eOowRPZnNNnCf2SpSb2sHyD7Kk3EtZSuytGw sW5A6lZYTrVvNS9iv038SFC/Maupz+TXy3x7DJfOyYLsjSuTRVgvOcc0XjWl5o/1N5/1 gB+gPBmI9pQnXU1xPzVyTIm+SCnFbF6HSRlC/xJpiA+uW0vKOXg7D2oI5H2y7a+6TTIj uCdQ== X-Gm-Message-State: AOJu0YxM8qu/brHc/HyirH7tdYdzwK9J4A/mOq4pdNxRDKlPM4Sc0gJx l7IlqvCUHBexcqnwGgy/+LvzcWR8UsC1uqLw5mMESgt6StD4aOoeEC0kBaDKG6vqtH4+2pLmnmg okKgru8spFWDF825/ohHuNlawe1O7zzv77W+z6jwMEjps1v6Jy6efq4A/EOHcOerYRXkVi1e/S4 AW66PTNJyrIY9aXgIf58Nt9VSgmILQm6h6mmc44Q== X-Gm-Gg: AR+sD13rhgtihgNE9NWEIh9s8Ur3Ch/jaFdpQvtzF6IgaxuYp3ij9Wp7RSsXlkc7tzh UMle8YectncsjDDsLhWDbZNVfgAS7EAAPAF8WpZkMNHn6ziav0H6s2KrB+LoRWp1C9w/QyGlVSE iA6C2fFsOaPUcYX9K3HEk4uTwZjMMjFsDMUou4hDvSviytKdVA/g+Ovl1ymxzUFWYMhXGLs2dKB bq5R7qycWFjoN+Re4a6h2ouRolINI+3zhd71bPk3qlA4Y5VeInhHQI9XK4kCxtOm7jKfatLmPvM fa7sgmJJ6LWtq1uvaXGTRFqQKdN4f6Ctr+fMwY+nEA36hJOs8gt6L8LR/+c6PkC7L7dCj8PkawX MmH+vo7ipFnmijqQwwZ3Qwpsg/TgQfN+MwbgC6XX78vuW4mXFPidmril/ X-Received: by 2002:a05:620a:2789:b0:930:a3f9:93b0 with SMTP id af79cd13be357-93302afd4cfmr461978085a.86.1785272664812; Tue, 28 Jul 2026 14:04:24 -0700 (PDT) X-Received: by 2002:a05:620a:2789:b0:930:a3f9:93b0 with SMTP id af79cd13be357-93302afd4cfmr461972685a.86.1785272664123; Tue, 28 Jul 2026 14:04:24 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: Fabiano Rosas , Juraj Marcin , peterx@redhat.com, Feifan Qian , qemu-stable , Peter Maydell Subject: [PATCH v2 1/5] migration: Fix possible overflow in vmstate_handle_alloc() Date: Tue, 28 Jul 2026 17:04:13 -0400 Message-ID: <20260728210417.1925078-2-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260728210417.1925078-1-peterx@redhat.com> References: <20260728210417.1925078-1-peterx@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -36 X-Spam_score: -3.7 X-Spam_bar: --- X-Spam_report: (-3.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785272707336158500 Content-Type: text/plain; charset="utf-8" Migration incoming side almost always trusted the stream data and allows allocation to happen with whatever size received. With it, malicious migration stream can manipulate destination QEMU behavior on g_malloc(), in path of vmstate_handle_alloc() on specific VMSD fields. Fix it by limiting all sizes with int32_t positive values (INT_MAX) explicitly. We have quite a few bug reports recently leveraging this defect. It can be reproduced in many ways for (I think) all archs binaries, but the simplest reproducer is: $ hexdump -C ./vm.img 00000000 51 45 56 4d 00 00 00 03 07 80 00 00 00 00 00 00 |QEVM........= ....| $ ./qemu-system-x86_64 -incoming file:./vm.img VNC server running on ::1:5900 qemu-system-x86_64: GLib: ../glib/gmem.c:106: failed to allocate 18446744= 071562067968 bytes Aborted (core dumped) ./qemu-system-x86_64 -incoming f= ile:./vm.img We could assert here, but since we have errp right above the stack this patch routes the errp over to allow destination QEMU fail gracefully. This means there's no way to DoS coredumpctl as well because we don't generate core dumps at all. The output message could also hopefully help triage issues when it's not a malicious stream but only wrong image used. When at this, making sure multiplex also won't overflow. After patched: $ ./qemu-system-x86_64 -incoming file:./vm.img VNC server running on ::1:5900 qemu-system-x86_64: load of migration failed: Invalid argument: vmstate_s= ize: VMState field 'name' overflow Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3805 Reported-by: Feifan Qian Reported-by: dong ling (@dongling226655) Cc: qemu-stable Cc: Peter Maydell Reviewed-by: Fabiano Rosas Signed-off-by: Peter Xu --- migration/vmstate.c | 91 ++++++++++++++++++++++++++++++++++++++------- 1 file changed, 77 insertions(+), 14 deletions(-) diff --git a/migration/vmstate.c b/migration/vmstate.c index 50ebe37845..7bf0c2bae5 100644 --- a/migration/vmstate.c +++ b/migration/vmstate.c @@ -78,9 +78,10 @@ vmsd_init_ptr_marker_field(VMStateField *fake, const VMS= tateField *field) }; } =20 -static int vmstate_n_elems(void *opaque, const VMStateField *field) +static int32_t vmstate_n_elems(void *opaque, const VMStateField *field, + Error **errp) { - int n_elems =3D 1; + int32_t n_elems =3D 1; =20 if (field->flags & VMS_ARRAY) { n_elems =3D field->num; @@ -94,18 +95,35 @@ static int vmstate_n_elems(void *opaque, const VMStateF= ield *field) n_elems =3D *(uint8_t *)(opaque + field->num_offset); } =20 + if (n_elems < 0) { + error_setg(errp, "%s: VMState field '%s' num_offset overflow", + __func__, field->name); + return -EINVAL; + } + trace_vmstate_n_elems(field->name, n_elems); + return n_elems; } =20 -static int vmstate_size(void *opaque, const VMStateField *field) +static int32_t vmstate_size(void *opaque, const VMStateField *field, + Error **errp) { - int size; + int32_t size; =20 if (field->flags & VMS_VBUFFER) { + /* For both int32_t/uint32_t we only allow 2GB limit for VBUFFER */ size =3D *(int32_t *)(opaque + field->size_offset); + + /* Check this explicitly for untrusted length input first */ + if (size < 0) { + goto overflow; + } + if (field->flags & VMS_MULTIPLY) { - size *=3D field->size; + if (smul32_overflow(field->size, size, &size)) { + goto overflow; + } } } else if (field->flags & VMS_ARRAY_OF_POINTER) { /* @@ -115,21 +133,45 @@ static int vmstate_size(void *opaque, const VMStateFi= eld *field) size =3D sizeof(void *); } else { size =3D field->size; + assert(size >=3D 0); } =20 return size; + +overflow: + error_setg(errp, "%s: VMState field '%s' overflow", + __func__, field->name); + return -EINVAL; } =20 -static void vmstate_handle_alloc(void *ptr, const VMStateField *field, - void *opaque) +static bool vmstate_handle_alloc(void *ptr, const VMStateField *field, + void *opaque, Error **errp) { if (field->flags & VMS_POINTER && field->flags & VMS_ALLOC) { - gsize size =3D vmstate_size(opaque, field); - size *=3D vmstate_n_elems(opaque, field); + int32_t size, n; + + size =3D vmstate_size(opaque, field, errp); + if (size < 0) { + return false; + } + + n =3D vmstate_n_elems(opaque, field, errp); + if (n < 0) { + return false; + } + + if (smul32_overflow(size, n, &size)) { + error_setg(errp, "%s: VMState field '%s' multiply overflow", + __func__, field->name); + return false; + } + if (size) { *(void **)ptr =3D g_malloc(size); } } + + return true; } =20 static bool vmstate_ptr_marker_load(QEMUFile *f, bool *load_field, @@ -335,10 +377,22 @@ bool vmstate_load_vmsd(QEMUFile *f, const VMStateDesc= ription *vmsd, =20 if (exists) { void *first_elem =3D opaque + field->offset; - int i, n_elems =3D vmstate_n_elems(opaque, field); - int size =3D vmstate_size(opaque, field); + int i, n_elems =3D vmstate_n_elems(opaque, field, errp); + int size; + + if (n_elems < 0) { + return false; + } + + size =3D vmstate_size(opaque, field, errp); + if (size < 0) { + return false; + } + + if (!vmstate_handle_alloc(first_elem, field, opaque, errp)) { + return false; + } =20 - vmstate_handle_alloc(first_elem, field, opaque); if (field->flags & VMS_POINTER) { first_elem =3D *(void **)first_elem; assert(first_elem || !n_elems || !size); @@ -650,8 +704,7 @@ static bool vmstate_save_vmsd_v(QEMUFile *f, const VMSt= ateDescription *vmsd, while (field->name) { if (vmstate_field_exists(vmsd, field, opaque, version_id)) { void *first_elem =3D opaque + field->offset; - int i, n_elems =3D vmstate_n_elems(opaque, field); - int size =3D vmstate_size(opaque, field); + int i, n_elems =3D vmstate_n_elems(opaque, field, errp); JSONWriter *vmdesc_loop =3D vmdesc; bool is_prev_null =3D false; /* @@ -660,6 +713,16 @@ static bool vmstate_save_vmsd_v(QEMUFile *f, const VMS= tateDescription *vmsd, */ bool use_dynamic_array =3D field->flags & VMS_ARRAY_OF_POINTER_AUTO_ALLOC; + int32_t size; + + if (n_elems < 0) { + return false; + } + + size =3D vmstate_size(opaque, field, errp); + if (size < 0) { + return false; + } =20 trace_vmstate_save_state_loop(vmsd->name, field->name, n_elems= ); if (field->flags & VMS_POINTER) { --=20 2.54.0 From nobody Mon Sep 28 02:01:19 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785272723; cv=none; d=zohomail.com; s=zohoarc; b=K1pl8SW+KE9V/GXTnTWxw6boGsSFFm6pOpnO8YewmqJNa77QQCO7SXHlQE3iiJr6FhUvIeD+qpcyn9ORVXlRzGMBClYeMQoUE06V/4a/sCDr+QOCCYmRVzCEC/VmQ2TjVDpxUOpbHavgDz8Myxri1wZ2BhyN7v/7Sjmcykap2DQ= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785272723; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Wgod9mpBIeEAPuUI2tKpiE28TzA1mnnfyKCqZ3+xNnc=; b=RcqXIWOJGReqOjfabDJ23yaFOjSAMPcSZDeWlkRTKjqTNG9C49xbQlAPadsRaMNv1xOp6W+by70BcUDozqP8hR5d+otIrvAfQYTxxkSm8HZnIb3ya9kcPk8MSDpjo83goc7BqxDru6lm70zi31gWv6dNs5sCx/6ZPLn8clbwQTs= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785272723810192.39673345391714; Tue, 28 Jul 2026 14:05:23 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wooz8-0004kY-V1; Tue, 28 Jul 2026 17:05:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wooyY-0004U1-Rt for qemu-devel@nongnu.org; Tue, 28 Jul 2026 17:04:36 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wooyU-0003hi-M9 for qemu-devel@nongnu.org; Tue, 28 Jul 2026 17:04:34 -0400 Received: from mail-qv1-f69.google.com (mail-qv1-f69.google.com [209.85.219.69]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-509-BvA-K2jEPnOySNDx_XA6XA-1; Tue, 28 Jul 2026 17:04:28 -0400 Received: by mail-qv1-f69.google.com with SMTP id 6a1803df08f44-90284139cceso14484016d6.0 for ; Tue, 28 Jul 2026 14:04:28 -0700 (PDT) Received: from x1.com (bras-vprn-aurron9134w-lp130-03-174-91-117-74.dsl.bell.ca. [174.91.117.74]) by smtp.gmail.com with ESMTPSA id af79cd13be357-933d3227707sm21277985a.6.2026.07.28.14.04.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 14:04:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785272670; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Wgod9mpBIeEAPuUI2tKpiE28TzA1mnnfyKCqZ3+xNnc=; b=LIQxqypYgUCzpbuqt276TPQK8SLm7leckvG83pAXCt/9OMgh+4ObG/BsbaBBiFwi2PR/1Q b81iyG3rJytARfY3fDrvAmZdAwb3CGW1SNVLZtY2iDH8atIYLkCRsNYL+4FIS/7uNj2SSp VwO6njeE1Q7tJ/CIX7vZncDSY4TQrxU= X-MC-Unique: BvA-K2jEPnOySNDx_XA6XA-1 X-Mimecast-MFC-AGG-ID: BvA-K2jEPnOySNDx_XA6XA_1785272668 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1785272668; x=1785877468; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Wgod9mpBIeEAPuUI2tKpiE28TzA1mnnfyKCqZ3+xNnc=; b=SYmCvnjMyVDpC8xTXI4tyqqykqZQoqPdGqJ4Oq6noGLUa6wbLRx36sTW8QIYeOD2rL KGqzyzGaMtXgB1xM7aBsTReoTyulIp5Y57oV+MifbnYJYzFvD6x+ziJCxxct6ipj+CPP 7yS9kB4ByqxEI9hgjzrRP9NtLEIRLexMTWhmxItmZY4XiDAt3bHg6IQwPnlu97CRbDxk w+YjvTJE+bbWiHr0q9vYXBVbWy2jmIrHlcKS+uH1oMUvnoI31aFzG1H9iTaoB6t1+wEV wvWGPhmjz1cJWflExC/FvwwWdBsOmk5fyoNDqsP0pC7HYAQ2RifY/JCFsWVPklgVoyf/ IBXg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785272668; x=1785877468; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=Wgod9mpBIeEAPuUI2tKpiE28TzA1mnnfyKCqZ3+xNnc=; b=tPeVA8W28ZLKWyC2uIV29wbr6qp+xNF+ZPnlA+Pxip/VllFvzgpqklPPici0SfU//h CE22mrM49amxGCF6Gdg6ZPW1WWP8AJ/0apu/XodK8V5ai/ofBMJhE9JJICUXh7Jz5epH JewmDCABoJ2zzuXlyvnmOr+rfiJsOjEc0vmnTojAdRrfJf6r+h0xF4NbcAB+bXsLWGfG 2kIwn7W5TZrZseQlorOWngyoWT1HXEiYhv+YbduAsWjD17EHPgwgWfup1A2x+iobT3FQ +tMh7NFDjJWrG3g7zd/2wYpdWEEg9N1zFTr0wAtuo9cdIrh6vj6towN28UbMM2oKyJ2k VSFQ== X-Gm-Message-State: AOJu0YwIFG+8bFjQuLbS6bl0Sn2jrahIsoySCgwqdhFg/koJt5SV1JjO b8yNAgKG3++Oj8ta858YfB5UqtBb/qUR7WGQcsuuI74IkA9rYRexa5FLRYE68O/O2Nn6N42+jzj f6acBbv2k/XNe7udJ+pbRIMLqHXIBamt8veENh3kfSlG6KCs6QfjGzmekjgROnGCHLx7sVuUD6X /uHdgf2m8o+CqzdDU8APGC8dx9sZJ8wifwcUUoGA== X-Gm-Gg: AR+sD11XMaT/RCqBabf10d231ILvJjOfAHN0O0byMGh1BxrMvP9Dh+NbC+wm0UTbZyM Wn1f+8EG3AaTGTjviipUMHjRFmcDbayJ84B3mOY9eKJixMQID83dFt89skppGitu3YAxgQ4lWlW Bugoy6mpKxWAyYgoHYqeYPXXO1cIzhBjVjn9BVgQS8hLORbZA6j9AQWVi3Nk/GneSdyF5AA9hTO PteEWHka5gmWqSQiQoIA0ah0qAuAMJ5VjgMJixzW36fRJmCVyz09X4oAm9Bga2/1P5xGTU5Y6w6 bHdFa0vrcsG6moxtZuqZ0bxmAWieo0KUuCbapufAyr2R2yLB5f91lAWMfo2DNB/P+YLtfOad+DS uq4Svat0an1RZ8h69h1MFz+TKWmwYOQgXn8pNY+5WoPNZqdf1z16bAzrJ X-Received: by 2002:a05:620a:40c2:b0:8cd:d688:7aef with SMTP id af79cd13be357-93302640f89mr440567885a.19.1785272667686; Tue, 28 Jul 2026 14:04:27 -0700 (PDT) X-Received: by 2002:a05:620a:40c2:b0:8cd:d688:7aef with SMTP id af79cd13be357-93302640f89mr440563685a.19.1785272667038; Tue, 28 Jul 2026 14:04:27 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: Fabiano Rosas , Juraj Marcin , peterx@redhat.com, xlabai , Jules Denardou , Tristan Madani , qemu-stable Subject: [PATCH v2 2/5] migration/multifd: Validate next_packet_size in zlib/zstd recv Date: Tue, 28 Jul 2026 17:04:14 -0400 Message-ID: <20260728210417.1925078-3-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260728210417.1925078-1-peterx@redhat.com> References: <20260728210417.1925078-1-peterx@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -36 X-Spam_score: -3.7 X-Spam_bar: --- X-Spam_report: (-3.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785272725458158500 Content-Type: text/plain; charset="utf-8" The zlib and zstd multifd compression backends read next_packet_size from the incoming migration stream and use it directly as the read length into a fixed-size buffer (MULTIFD_PACKET_SIZE * 2 =3D 1MB). A malicious migration source can set next_packet_size bigger than allocated, causing a heap buffer overflow write on the destination. Add a check against zbuff_len before reading, matching what the qatzip backend already does. Also replace the assert(in_size =3D=3D 0) for empty packets with proper error reporting, since the value is wire-controlled, meanwhile assert() stops working with -DNDEBUG builds. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3737 Reported-by: xlabai Reported-by: Jules Denardou Reported-by: Tristan Madani Reported-by: david korczynski (@david1766) Reported-by: huntr bubble (@bubblehuntr) Cc: qemu-stable Reviewed-by: Fabiano Rosas Signed-off-by: Peter Xu --- migration/multifd-zlib.c | 11 ++++++++++- migration/multifd-zstd.c | 11 ++++++++++- 2 files changed, 20 insertions(+), 2 deletions(-) diff --git a/migration/multifd-zlib.c b/migration/multifd-zlib.c index 8820b2a787..400146566e 100644 --- a/migration/multifd-zlib.c +++ b/migration/multifd-zlib.c @@ -216,10 +216,19 @@ static int multifd_zlib_recv(MultiFDRecvParams *p, Er= ror **errp) return -1; } =20 + if (in_size > z->zbuff_len) { + error_setg(errp, "multifd %u: next_packet_size %"PRIu32 + " exceeds allocated %"PRIu32, p->id, in_size, z->zbuff_= len); + return -1; + } + multifd_recv_zero_page_process(p); =20 if (!p->normal_num) { - assert(in_size =3D=3D 0); + if (in_size !=3D 0) { + error_setg(errp, "multifd %u: expected empty packet", p->id); + return -1; + } return 0; } =20 diff --git a/migration/multifd-zstd.c b/migration/multifd-zstd.c index 3c2dcf76b0..69ef1a5f38 100644 --- a/migration/multifd-zstd.c +++ b/migration/multifd-zstd.c @@ -210,10 +210,19 @@ static int multifd_zstd_recv(MultiFDRecvParams *p, Er= ror **errp) return -1; } =20 + if (in_size > z->zbuff_len) { + error_setg(errp, "multifd %u: next_packet_size %"PRIu32 + " exceeds allocated %"PRIu32, p->id, in_size, z->zbuff_= len); + return -1; + } + multifd_recv_zero_page_process(p); =20 if (!p->normal_num) { - assert(in_size =3D=3D 0); + if (in_size !=3D 0) { + error_setg(errp, "multifd %u: expected empty packet", p->id); + return -1; + } return 0; } =20 --=20 2.54.0 From nobody Mon Sep 28 02:01:19 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785272725; cv=none; d=zohomail.com; s=zohoarc; b=dpI5wU/XejN7ph+vBjKRZ3NdedaSYrhEfsmuj3P0pDWrvqJJXaT86PORQKLG9jDP9QzcHRvgcZd16OysxVn3egFrYmZ4YxxIN+yu78kll37Z8J08aTub3+PFvT8ctwLQYNB8G5jTPVRZ5E6TKUETrNMdi0YCqXeZU7A0H1rhK64= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785272725; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=+pei3vmco7Kz5qqmpc9dFtZ8rmZ+J3fui21id4q3x4w=; b=EAwjOO4Qrq3NmOGfl30uyNBl0JhXfnkDk/4arI3XWO2Cd/WnJDDEaeUqBE7a5XloQbISsI77+v+K3opSWNsSv+n6Wq5BNWyMa8U3EW5e4XEZyDzHWAaVLPsgHk/+Clxup39tfV1Yf+Fi+0LdoTKn6qC4KP0uCupwt2RTPG14EOc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785272725901862.3708279016149; Tue, 28 Jul 2026 14:05:25 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wooyq-0004X6-E1; Tue, 28 Jul 2026 17:04:52 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wooyY-0004U3-Ul for qemu-devel@nongnu.org; Tue, 28 Jul 2026 17:04:36 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wooyW-0003i2-0E for qemu-devel@nongnu.org; Tue, 28 Jul 2026 17:04:34 -0400 Received: from mail-qk1-f198.google.com (mail-qk1-f198.google.com [209.85.222.198]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-209-XGYYBp2dN7yEw31ASmN-VQ-1; Tue, 28 Jul 2026 17:04:29 -0400 Received: by mail-qk1-f198.google.com with SMTP id af79cd13be357-92e4f27f49bso36708685a.0 for ; Tue, 28 Jul 2026 14:04:29 -0700 (PDT) Received: from x1.com (bras-vprn-aurron9134w-lp130-03-174-91-117-74.dsl.bell.ca. [174.91.117.74]) by smtp.gmail.com with ESMTPSA id af79cd13be357-933d3227707sm21277985a.6.2026.07.28.14.04.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 14:04:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785272671; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=+pei3vmco7Kz5qqmpc9dFtZ8rmZ+J3fui21id4q3x4w=; b=TpvRiMA1m+hFDrbF6Ssgt6qYt2u/BUTXwVPQhkQal40r1z9Dt1z6c3l9ajMbGV9jeYkaIa zJBIPr1hkLJHszEIIGoHTfP5V6QnwYhyxXM1gTJ5HHfUH54pLoQC/shKJ+Jxtz3jWLLvRK s8HGGFsCvCj7oJLBNAvQ7KU6xwhrh5U= X-MC-Unique: XGYYBp2dN7yEw31ASmN-VQ-1 X-Mimecast-MFC-AGG-ID: XGYYBp2dN7yEw31ASmN-VQ_1785272669 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1785272669; x=1785877469; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=+pei3vmco7Kz5qqmpc9dFtZ8rmZ+J3fui21id4q3x4w=; b=YeAepEiweQ5jHxk5PFeSTblRZjqfiHI7nXSO5yelQtfwXWR8v4jii54zLHpm+daCVG 7jLErBKXJGFe18Pfe1QbuxNL57KIxGAm1B/0SnkFs/cgTlM6BV8yoKWDqbuGZNUaITzY Ntn+tWgigaRykAg/MDqgq/g9/0sa4p/rNau8qpR0jbRb378hm6qlCI/FJiS4C9StxOxm ExD57V9Emi+XEeiS5E5HKR8h9CZAKPeOijJlzMAyc6CTq7/c7H4RN2a/nSlgSaYQiRTD UTH2Ppo9daElaUOYSxWBOqgvZ4kIXTJbL0f96HoUXei88TWFRmb2tfbU0i5/b8mmyRsK WF3A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785272669; x=1785877469; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=+pei3vmco7Kz5qqmpc9dFtZ8rmZ+J3fui21id4q3x4w=; b=Ac0wmrwKmX//7f38WEkzFsoeZpQJOLpMF/K+d5KzjBJxNLCFFLFXKGaLqHkUly/S4B Bb4RhDAf3jEqHnaerK/NYnDR8lJV1Aekfv7/HtY6QQ10iZkdp/lfQFliFlvuJz1Q7UXk /KdHT9v/5ePviwu1x5gMWiht44MCNVQn2RgBAG7RXJkViasUjX0Qso/Gs+0Is2sXhGXw UWYWavFFmrMbE6jrA7MP7L6lMQ9P47TiRyaDI/wYwZo6gxynpOPOPlaYnVys/6SgbkEW 3z9CEX6RyD33+6qorGrnMSF/f8nxgXja7RX8MIK5g0OgiNZrmFXdeUqFt1K3LNTvzINI ubVg== X-Gm-Message-State: AOJu0Yzk6gsq45f7wDWTA9MxGaBBFhvGruFwRn6DF4bMMY5AWhc2Bdcf Q8XQRkiGfROpyPT+9BPIKUb47wedvLoL+w5kqJsCfxA3ycMopAhqgA1kalYT62+jQRibJ4W+Kks GBvilJ3eTiwIElHR8UCCZImEdlhpAtEWUKX7wpz7TZ4HP8pAZp+Rxd6tbu0BRRf1l+6m1E+5Vri IGG5E6PAsd/VIXGezUdyaZcfiNsi96EStFgjSKTA== X-Gm-Gg: AR+sD136C8hGTUJy1vbzgUq9lFolA0DAQ9Gs9HldIfjvkbALlX7tSRAbeO6wz511gc2 UalXo4dX66QoSWUvjsgbmpqCTVJ0TTvR7ymqyjdhRHeUNthZjq3LYsIHnFa+j7+r9SPnp4bu1dG eYlFvMVIcL7rCv5ISWwu88+XKNS6p5v7FzWyItxk3Cn/N5g09BIhZpT5SJ70JFIHyKSi6EDuuxx sui6jvavPOzvIW60Oev+RqAvoa+QelxuPPKt71FTzUW1ZPyBckh9n5wvVBfBFyAqq0Gd2ke1xZA D7xe08jU57ILEzj8OzeBmgNTaQQDDhHeEcwfGPoG4uYOOKtELi6X2T/GBzFrd9qDjdkpzRvwLQu aJwxWwGqLelejpMbZpjItxKpaGSnUN+xKoZktG+ll4tevF1N94/PuOdzX X-Received: by 2002:a05:620a:1712:b0:930:9c0c:657 with SMTP id af79cd13be357-93302620f6cmr408754785a.60.1785272669086; Tue, 28 Jul 2026 14:04:29 -0700 (PDT) X-Received: by 2002:a05:620a:1712:b0:930:9c0c:657 with SMTP id af79cd13be357-93302620f6cmr408750385a.60.1785272668412; Tue, 28 Jul 2026 14:04:28 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: Fabiano Rosas , Juraj Marcin , peterx@redhat.com, qemu-stable , Yuan Liu , Yichen Wang Subject: [PATCH v2 3/5] migration/multifd: Replace assert() with error_setg() in recv paths Date: Tue, 28 Jul 2026 17:04:15 -0400 Message-ID: <20260728210417.1925078-4-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260728210417.1925078-1-peterx@redhat.com> References: <20260728210417.1925078-1-peterx@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -36 X-Spam_score: -3.7 X-Spam_bar: --- X-Spam_report: (-3.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785272727075158501 Content-Type: text/plain; charset="utf-8" QPL and UADK multifd backends use assert() to validate wire-controlled fields like per-page compressed lengths and packet size consistency. These asserts will stop working with -DNDEBUG builds, so may stop working. Replace all assert() calls in the receive path with proper error_setg() so validation failures are reported gracefully rather than crashing or silently ignored. While at it, touch up an assert() in qatzip recv path too. Cc: qemu-stable Cc: Yuan Liu Cc: Yichen Wang Reviewed-by: Fabiano Rosas Signed-off-by: Peter Xu --- migration/multifd-qatzip.c | 5 ++++- migration/multifd-qpl.c | 24 ++++++++++++++++++++---- migration/multifd-uadk.c | 24 ++++++++++++++++++++---- 3 files changed, 44 insertions(+), 9 deletions(-) diff --git a/migration/multifd-qatzip.c b/migration/multifd-qatzip.c index 7419e5dc0d..0262e81eac 100644 --- a/migration/multifd-qatzip.c +++ b/migration/multifd-qatzip.c @@ -348,7 +348,10 @@ static int qatzip_recv(MultiFDRecvParams *p, Error **e= rrp) =20 multifd_recv_zero_page_process(p); if (!p->normal_num) { - assert(in_size =3D=3D 0); + if (in_size !=3D 0) { + error_setg(errp, "multifd %u: expected empty packet", p->id); + return -1; + } return 0; } =20 diff --git a/migration/multifd-qpl.c b/migration/multifd-qpl.c index 52902eb00c..3826e7f340 100644 --- a/migration/multifd-qpl.c +++ b/migration/multifd-qpl.c @@ -664,26 +664,42 @@ static int multifd_qpl_recv(MultiFDRecvParams *p, Err= or **errp) } multifd_recv_zero_page_process(p); if (!p->normal_num) { - assert(in_size =3D=3D 0); + if (in_size !=3D 0) { + error_setg(errp, "multifd %u: expected empty packet", p->id); + return -1; + } return 0; } =20 /* read compressed page lengths */ len =3D p->normal_num * sizeof(uint32_t); - assert(len < in_size); + if (len >=3D in_size) { + error_setg(errp, "multifd %u: header len %"PRIu32 + " >=3D packet size %"PRIu32, p->id, len, in_size); + return -1; + } ret =3D qio_channel_read_all(p->c, (void *) qpl->zlen, len, errp); if (ret !=3D 0) { return ret; } for (int i =3D 0; i < p->normal_num; i++) { qpl->zlen[i] =3D be32_to_cpu(qpl->zlen[i]); - assert(qpl->zlen[i] <=3D multifd_ram_page_size()); + if (qpl->zlen[i] > multifd_ram_page_size()) { + error_setg(errp, "multifd %u: page %d compressed len %" + PRIu32" too large", p->id, i, qpl->zlen[i]); + return -1; + } zbuf_len +=3D qpl->zlen[i]; ramblock_recv_bitmap_set_offset(p->block, p->normal[i]); } =20 /* read compressed pages */ - assert(in_size =3D=3D len + zbuf_len); + if (in_size !=3D len + zbuf_len) { + error_setg(errp, "multifd %u: packet size %"PRIu32 + " !=3D header %"PRIu32" + data %"PRIu32, + p->id, in_size, len, zbuf_len); + return -1; + } ret =3D qio_channel_read_all(p->c, (void *) qpl->zbuf, zbuf_len, errp); if (ret !=3D 0) { return ret; diff --git a/migration/multifd-uadk.c b/migration/multifd-uadk.c index fd7cd9b5e8..d373615ba8 100644 --- a/migration/multifd-uadk.c +++ b/migration/multifd-uadk.c @@ -245,12 +245,19 @@ static int multifd_uadk_recv(MultiFDRecvParams *p, Er= ror **errp) =20 multifd_recv_zero_page_process(p); if (!p->normal_num) { - assert(in_size =3D=3D 0); + if (in_size !=3D 0) { + error_setg(errp, "multifd %u: expected empty packet", p->id); + return -1; + } return 0; } =20 /* read compressed data lengths */ - assert(hdr_len < in_size); + if (hdr_len >=3D in_size) { + error_setg(errp, "multifd %u: header len %"PRIu32 + " >=3D packet size %"PRIu32, p->id, hdr_len, in_size); + return -1; + } ret =3D qio_channel_read_all(p->c, (void *) uadk_data->buf_hdr, hdr_len, errp); if (ret !=3D 0) { @@ -259,12 +266,21 @@ static int multifd_uadk_recv(MultiFDRecvParams *p, Er= ror **errp) =20 for (int i =3D 0; i < p->normal_num; i++) { uadk_data->buf_hdr[i] =3D be32_to_cpu(uadk_data->buf_hdr[i]); + if (uadk_data->buf_hdr[i] > page_size) { + error_setg(errp, "multifd %u: page %d compressed len %"PRIu32 + " too large", p->id, i, uadk_data->buf_hdr[i]); + return -1; + } data_len +=3D uadk_data->buf_hdr[i]; - assert(uadk_data->buf_hdr[i] <=3D page_size); } =20 /* read compressed data */ - assert(in_size =3D=3D hdr_len + data_len); + if (in_size !=3D hdr_len + data_len) { + error_setg(errp, "multifd %u: packet size %"PRIu32 + " !=3D header %"PRIu32" + data %"PRIu32, + p->id, in_size, hdr_len, data_len); + return -1; + } ret =3D qio_channel_read_all(p->c, (void *)buf, data_len, errp); if (ret !=3D 0) { return ret; --=20 2.54.0 From nobody Mon Sep 28 02:01:19 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785272743; cv=none; d=zohomail.com; s=zohoarc; b=TCXV/BQZbcIusUWmztzD7lQxZLu70neNLnyhwWjr+cKi7f4ODCVYLF+w5eo65xPjRpACUr66hv9aC0x3SqTOkL1UX29O8wdTrn/peC5QmAVu/kwYxIRe8h2odLXlVW1h5OOa48aZ1mW25t8FMhjVU6a4ssxoSB3DQfFUVEnRS2Q= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785272743; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=QTM/N9lbOP8xRMWNN1H0iMPnAMdF9INBG5H3f+egzqw=; b=Xi3Q7rUwxSg2dRI/ZmjLY6dIclcpsNR/aIEQfuJCrQLEfQIB3PJNbNf6MFKfE9+7uSr+ovjhunIJs+j5Ayifz4Lqduzk12wWotsPKmDzsGeSVWjfDh2fNGFkeX3V4rd5sVjmarBHAxoJdNnurDWXUAceckW2UBGJae7wmDnk0DY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785272743249990.2356025450747; Tue, 28 Jul 2026 14:05:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wooz4-0004gK-Rw; Tue, 28 Jul 2026 17:05:08 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wooya-0004UC-IJ for qemu-devel@nongnu.org; Tue, 28 Jul 2026 17:04:38 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wooyX-0003iR-Nr for qemu-devel@nongnu.org; Tue, 28 Jul 2026 17:04:35 -0400 Received: from mail-qk1-f198.google.com (mail-qk1-f198.google.com [209.85.222.198]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-116-Dxo8-o_sMDysM_TWjPMEMA-1; Tue, 28 Jul 2026 17:04:31 -0400 Received: by mail-qk1-f198.google.com with SMTP id af79cd13be357-930b571432fso36455285a.0 for ; Tue, 28 Jul 2026 14:04:31 -0700 (PDT) Received: from x1.com (bras-vprn-aurron9134w-lp130-03-174-91-117-74.dsl.bell.ca. [174.91.117.74]) by smtp.gmail.com with ESMTPSA id af79cd13be357-933d3227707sm21277985a.6.2026.07.28.14.04.28 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 14:04:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785272673; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=QTM/N9lbOP8xRMWNN1H0iMPnAMdF9INBG5H3f+egzqw=; b=RLJuUdrmEEdprB4swlZs4u6v2x0b5tP/ex/7oinDT36tdMMZY8Qj0EPw6q+S662XOycL/F KHKR2/0FbOJuZtY6WtNzMftUJh+E5biMOcVnmPB8bUvhNnCnewqLBh0fgTlqiChKkJkVzF RnGWOEcKVniWzzU+45X50QesAgc+rDE= X-MC-Unique: Dxo8-o_sMDysM_TWjPMEMA-1 X-Mimecast-MFC-AGG-ID: Dxo8-o_sMDysM_TWjPMEMA_1785272671 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1785272671; x=1785877471; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=QTM/N9lbOP8xRMWNN1H0iMPnAMdF9INBG5H3f+egzqw=; b=mnFRSni87qgCHNGU/LZG9ZHd2qKNwgv3viYdnwvAGr+lbtuZv+oWdWQmWoKd2Niy/M xJmoZsxk72Zu8LUSRyDPqsP2ju8/13T6IpPMjm4FLezLiE40E7TUWDu/y1hadAlAVMql FYMkCN77hqj37Gr2LGG3Mj7HvBPlBXAgINPRHc5Ug1dCoFt7LC/nY/ufE1i7Hq8iw+8n WoAxLbnac2Fr73PxCyA8WWFoAxHjQo/fACU+te+/jHi/FUdw2nLIxOKPcyzKq29lhqjX LrAW1FuQMT2tOUHBPGFVz7JbxUAJIx93ZvgENYnJTMr69Ok+7Z0o9Z4FB6mAIk+XVYjo 8+3Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785272671; x=1785877471; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=QTM/N9lbOP8xRMWNN1H0iMPnAMdF9INBG5H3f+egzqw=; b=eGW/GTMhrNYnKMDZkCtJWDFmisbNXjdtdcKAGxdg0FnaE++zLscX05muZZlLe38Lcu N+MGX4YM49s+dgKLFwqiwqwczlKGpdyKBfsZ184JQw7S1NIQvav0WFo02+3H2rP36pbW A23ysVwGFuLjbN+wUPHa4KtmsX6aiem0ddp2+58x9tnDOn9L6E63j0J7zfwVgq8Gqj+/ bJf057vsylUjdqXR9jOawgJnhq3HYHDVOoJpghzhozBM42y/hTju37ixDhSlTg6aSunM qk5bxazF0ylw+H7k8tJa8ZMW2SF6s23ymozf60cNkOJdhUV5nb5zTRxpr0md9MPqurYt 3BGw== X-Gm-Message-State: AOJu0Yz9KKqG+L4w8x0AcjbC9VQhzhGKdQJMHkow7moWRhW83j9pZFhe Y2Uk0mPWLHAW/D8toE7osGlb2OotPSj2OrLNyENMC3EulBLZPWmfb4Dh2NPMznB/foAm0S1Y+LM wxCwBbhUGaurxE9A/EnF36VzGw3l4+f4iIkpTvTHK8BR/0+eD68nPvFYvSvpBW5zyRyani5qFF0 jOVY0MkHLVvgCYNMCJhwXNy/xTNrMg3Yam51j9Ag== X-Gm-Gg: AR+sD13v1JZiMenvWF/Xj/YSnlVjjYELJZx3hEapaYkBzsCgLdTzO50d82kxPdM4pMK 5osyD7eyl6dK8HzfmF+H24Zd5kAtRDGb0DtiXyoNIzoZmjU/gecR3tZ/u1WTSXEpZ/BwI3vlZ3Z /JJ8MLCOX1eS+ToC/CLtcg7ZlDUN6mkOIOs0TeO0Soya26qme5Nj4bk/cuZOvp/Rp6H52BuZRIl +E2CXu8CCPpsfsbNekwF1GOfpS0A/n80QmcTzx3NXWeJgZRdRcH3M6Q1jyH33OCgUKkZSlt/FtC 2tvNrC/1PsftBHzsdBKZ/lPwor8VkjRrpHWw6y3RYWHqPlrWvFT4XgoXDdHuoo7n2D++cxaYAbe zVqbl70LCCqTFUvatBxB/fqu6uzUwVifm8Ihc7UhrpmSL02YUevT5qegw X-Received: by 2002:a05:620a:2683:b0:92e:c0ac:aeb6 with SMTP id af79cd13be357-9330270951emr375409785a.40.1785272671006; Tue, 28 Jul 2026 14:04:31 -0700 (PDT) X-Received: by 2002:a05:620a:2683:b0:92e:c0ac:aeb6 with SMTP id af79cd13be357-9330270951emr375405685a.40.1785272670440; Tue, 28 Jul 2026 14:04:30 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: Fabiano Rosas , Juraj Marcin , peterx@redhat.com, Feifan Qian , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH v2 4/5] migration: Fix rare hang of migration_channel_read_peek() Date: Tue, 28 Jul 2026 17:04:16 -0400 Message-ID: <20260728210417.1925078-5-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260728210417.1925078-1-peterx@redhat.com> References: <20260728210417.1925078-1-peterx@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -36 X-Spam_score: -3.7 X-Spam_bar: --- X-Spam_report: (-3.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785272745168158500 In an unlikely case, when a migration stream is attached to the destination QEMU and only send <4 bytes to the channel as magic, it's possible that migration_channel_read_peek() may spin forever. Fix it by adding a manual sleep for partial read. Since the path isn't attached to a coroutine, it means when partial read happens, there's yet not much we can do but hang the main thread, it will happen even for len=3D=3D0 case. It means monitors can hang due to this, either partial read or no data arrived (but connection established). Leave this for later, the hope is this is extremely rare in production. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3889 Reported-by: Feifan Qian Cc: Daniel P. Berrang=C3=A9 Signed-off-by: Peter Xu --- migration/channel.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/migration/channel.c b/migration/channel.c index 1e2935f926..f446561b59 100644 --- a/migration/channel.c +++ b/migration/channel.c @@ -296,9 +296,16 @@ int migration_channel_read_peek(QIOChannel *ioc, =20 if (len =3D=3D buflen) { break; + } else if (len =3D=3D 0) { + qio_channel_wait_cond(ioc, G_IO_IN); + } else { + /* + * When partially ready, we can't use qio_channel_wait_cond() + * because it will return immediately. Apply a manual wait. + */ + assert(!qemu_in_coroutine()); + g_usleep(1000); } - - qio_channel_wait_cond(ioc, G_IO_IN); } =20 return 0; --=20 2.54.0 From nobody Mon Sep 28 02:01:19 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785272718; cv=none; d=zohomail.com; s=zohoarc; b=nApHxCk2KuA7OTiTYyXA7IjwHywRXYaoNAQ4TKP0CPXsU7PB0wFNcha6X42+y6BK1OaOXPSYjoJvuqA2tiKoUV3Ug2UPS0dpEut452ynaStJiFJE1UfIptMWRR5PabeuVXtgMs5QUpZoKYWOddu9w0wror6IVyeThDiEEhMMgQI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785272718; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=6FT8OgjVcYPi7/KqauWOXOjhtabKrcCzvRSC05e9FEY=; b=g70wG/sGy0PiyMQ297PAMHpl0soannUimLtnnI7hyjwpS7j74/Cp47vWaqOvhoLimD9Vo6PiGqxIhozkSfOsjg6Jnw+EGMpNNasiNwTC+yeuJX+mhQhiZubYSEdD0f45Z25CyHFcH8CuMbwFmbEu+faVuwGDCkFZ90Y0dvrCmsw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178527271816534.17881394042422; Tue, 28 Jul 2026 14:05:18 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wooyw-0004XS-7f; Tue, 28 Jul 2026 17:05:02 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wooyb-0004UE-OF for qemu-devel@nongnu.org; Tue, 28 Jul 2026 17:04:38 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wooyZ-0003j3-LP for qemu-devel@nongnu.org; Tue, 28 Jul 2026 17:04:37 -0400 Received: from mail-qk1-f200.google.com (mail-qk1-f200.google.com [209.85.222.200]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-114-JFne_50zMGeLv_PvboYa1Q-1; Tue, 28 Jul 2026 17:04:33 -0400 Received: by mail-qk1-f200.google.com with SMTP id af79cd13be357-91931144870so42738185a.1 for ; Tue, 28 Jul 2026 14:04:33 -0700 (PDT) Received: from x1.com (bras-vprn-aurron9134w-lp130-03-174-91-117-74.dsl.bell.ca. [174.91.117.74]) by smtp.gmail.com with ESMTPSA id af79cd13be357-933d3227707sm21277985a.6.2026.07.28.14.04.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 28 Jul 2026 14:04:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785272675; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=6FT8OgjVcYPi7/KqauWOXOjhtabKrcCzvRSC05e9FEY=; b=LxAusN11SuYnNIgKzZR56xe4TZql9rbfLUhmse2Pb4p6wRC2ZtGfFUoiOmN3hs8pbxQKYF uYSPFQFIZyAjIIvmZ0JrwLrw807sx99mbr+uvbZOytKAlEgxmewxkQXKDsa3WHkA9LPGhd vSFbnCdY2jvYdcOOhtq/CsevloDIVk4= X-MC-Unique: JFne_50zMGeLv_PvboYa1Q-1 X-Mimecast-MFC-AGG-ID: JFne_50zMGeLv_PvboYa1Q_1785272673 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1785272673; x=1785877473; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=6FT8OgjVcYPi7/KqauWOXOjhtabKrcCzvRSC05e9FEY=; b=iA8oaYGYHjvCyjpd/sa1JSZ8p2WRw1rxEwybopzFDqvxcEBkyq582ijiU0V4EDqAwV ildpTbGL/f3SqdlN1OZEmKRP5JdAuctm8YbgUYLA7zttjC8iiuXrIvXA9ncTfaXZq1C+ vkboAQKAThsicercCFLekqygMHGm2N/hsNTxYBG/3Gap5lrI6LAwnBkW866nyDqA/2hX 0Obq5p0IKIb3t6lnj0B/bCzP3n07/4XiFLIC8JQosAGrkp9orj6jsmANdwVjED+tVPqc bIcV48TyE0L4QNiRMpPgUCuXrhAsOtKAuqY9n1fF8aJC7/1xbZExgbPWYFjCazfi25/J ycCQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785272673; x=1785877473; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=6FT8OgjVcYPi7/KqauWOXOjhtabKrcCzvRSC05e9FEY=; b=AzN8OjNeQoR+FWCajuDhqctj/8cW3QJLfA0n8U4o/uDdrW4GQ5l1/qz1AGMAg9XqVw Veh8W+wLj4M6EKaH4CFnHNdzorkKk0e7R/y4XTHqAcBsy9Vv3t1v8jFalDwPPd1GVUYz 33PwOC1A8rC7+7N8taW8xFfeE7E10ZNQFM1mLa9olnUe301SnajGYhyM3oCKYecfdmpr F4P2XeRhxCxk8oeUQ8ORbI8I76r2jMxEtFzfKvjPcEeYrIggSAKuhFMyKJLxXyd1Fz92 NyEO77ubhMbfUBmCjVWmBIHdm1TtXo7ZymDeY7uF4EPsqwBLc/7lYKtpJ+dE9TYwPR7C wYaw== X-Gm-Message-State: AOJu0YxKFcOxch7uv82bQ+4+U92EAZnvH7tW4Q+zJYGwLjc+/T6FlH6Z 0q/PTqOKhKKEOZ4ImK4GFE9yor1WB0undYT1QXt/0ogL2OCHtRHZdo6DgQoereaZ85PFpfdJmKL DJdw1sk1dTGCnNwzKSi4SjQdOOezwowypWunQWJd73s9BimZS5kzQDkD3why4iBfbX2D3HNoONw /0nlWtkhcHQmTa1mgNQcUfhaf+RUqw+TC+OQXJpg== X-Gm-Gg: AR+sD11YVwKAl+E1TQZ6pEmlIsgs4xXVlgG0OBUHw4dtLYOVIbMuMudEUeH3XqG0vMT x++TSUFZhL9Cnmr8ZMCxZDSIs01fjnj1l5Th1nmeaK1JY4KT8WAT7HwOuBaTZSwYH8W+pHwJ3Cp aZrRV+Ci/iAtY+ltxIei7mH3sQIeA9wykQnPXvMaxfExwXgU1ZzBqIwwEDIAGY+LTzvVynfmpW7 FGQQ7Kt/LpuJbLWuhIfuuiSUJoNNacPMSl1FbAoCMv5tfxHAwIJfwnA77hTl6kEoA+az2tfO0Ie yZXyjcoKjN3zA2kKqH0A0+0fA9BzGfuNVU/gwWAFrffAvTQjDTMyMX8CLW+kuzddtRxgfR7Kqru aIQDE1qFLuSypgtTkz0oUDXOWj5KMDF7pROoR12dQ1g26gYPEExTsZx9+ X-Received: by 2002:a05:620a:7006:b0:92e:c117:5ed6 with SMTP id af79cd13be357-933027b20fbmr440073685a.86.1785272672999; Tue, 28 Jul 2026 14:04:32 -0700 (PDT) X-Received: by 2002:a05:620a:7006:b0:92e:c117:5ed6 with SMTP id af79cd13be357-933027b20fbmr440068185a.86.1785272672299; Tue, 28 Jul 2026 14:04:32 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: Fabiano Rosas , Juraj Marcin , peterx@redhat.com, Tristan Madani Subject: [PATCH v2 5/5] migration/ram: Check for RAMBlock size mismatch when parsing Date: Tue, 28 Jul 2026 17:04:17 -0400 Message-ID: <20260728210417.1925078-6-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260728210417.1925078-1-peterx@redhat.com> References: <20260728210417.1925078-1-peterx@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -36 X-Spam_score: -3.7 X-Spam_bar: --- X-Spam_report: (-3.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785272719066158500 Content-Type: text/plain; charset="utf-8" Add an underflow check for the subtract of total RAMBlock size to make sure it won't underflow. It should not happen in production systems but only if the migration stream was hijacked, which is not a real concern since migration channel is trusted. Still protect against it. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4013 Reported-by: Tristan Madani Reviewed-by: Fabiano Rosas Signed-off-by: Peter Xu --- migration/ram.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/migration/ram.c b/migration/ram.c index 8918b2f03b..85feff578c 100644 --- a/migration/ram.c +++ b/migration/ram.c @@ -4268,7 +4268,7 @@ static int parse_ramblocks(QEMUFile *f, ram_addr_t to= tal_ram_bytes) int ret =3D 0; =20 /* Synchronize RAM block list */ - while (!ret && total_ram_bytes) { + while (total_ram_bytes) { RAMBlock *block; char id[256]; ram_addr_t length; @@ -4285,8 +4285,15 @@ static int parse_ramblocks(QEMUFile *f, ram_addr_t t= otal_ram_bytes) error_report("Unknown ramblock \"%s\", cannot accept " "migration", id); ret =3D -EINVAL; + break; + } + + if (usub64_overflow(total_ram_bytes, length, &total_ram_bytes)) { + error_report("%s: RAMBlock '%s' size underflow total RAM size", + __func__, block->idstr); + ret =3D -EFAULT; + break; } - total_ram_bytes -=3D length; } =20 return ret; --=20 2.54.0