From nobody Mon Sep 28 02:06:11 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785367177; cv=none; d=zohomail.com; s=zohoarc; b=D72GR8hZC+cURglSsATVVaFhTESsxj7i+gpKd/d2SAQT5HC9V4DIilhPJQms0b9e5DkU7W9XeSPJ8LxHWV2TV8RTBdkxJ17Lw7ljNShbv1/9XB8hJtbNY7bwFbwajs3gSZ8nGPH9/5z5dtuPY4lGLNfsv1Vwo+LCUe+a9YWQ0Lk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785367177; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=2U04ygb5A0LYjIKGN2pPN05EfGJxWffpsepBkk0yBCc=; b=m6RyX5IMg4cirJ0tF1Pi7poQuNzo4y7bY3azkgaVTGxpHpRWofR7CWlrp3tOeswWk8/wdyo9Cj75dDEauErtglT5qzp1y0Bn4X8UbGeDLzVSGk/3fGs2CoamRctRkpYUIOm5+xf/o6Z70Y+dLneLFPLS0hjfmOaGM2LaWisSDnc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785367177121122.68476583915844; Wed, 29 Jul 2026 16:19:37 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpDYf-0002us-EG; Wed, 29 Jul 2026 19:19:29 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpDYd-0002sx-CT for qemu-devel@nongnu.org; Wed, 29 Jul 2026 19:19:27 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpDYa-0008Ci-Gm for qemu-devel@nongnu.org; Wed, 29 Jul 2026 19:19:27 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-675-n5CbBHkdM-at4ycylzcpuQ-1; Wed, 29 Jul 2026 19:19:15 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 7AC661956043; Wed, 29 Jul 2026 23:19:13 +0000 (UTC) Received: from lenovo-t14s.redhat.corp (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id DE7BA30001A4; Wed, 29 Jul 2026 23:19:09 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785367163; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=2U04ygb5A0LYjIKGN2pPN05EfGJxWffpsepBkk0yBCc=; b=YWbo8XIECTl/N36FmS/6OHKndcwAagwHPS037BvYXgSWG1brI9N0GMQSDt5kIVAKHyWFGV 8/zy53TxQ8UZKhbOJRGvZU25/soLVO1Vx+qzse7Qh7Z3A7ZtyshX0W/4pPSnZpc/2WRChE phNVHrmrfGFaSQW2AHOLntFVpvtFI4Y= X-MC-Unique: n5CbBHkdM-at4ycylzcpuQ-1 X-Mimecast-MFC-AGG-ID: n5CbBHkdM-at4ycylzcpuQ_1785367154 From: Laurent Vivier To: qemu-devel@nongnu.org Cc: Amit Shah , qemu-ppc@nongnu.org, Harsh Prateek Bora , Hanna Reitz , Nicholas Piggin , "Michael S. Tsirkin" , Kevin Wolf , Paolo Bonzini , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Fam Zheng , qemu-block@nongnu.org, Stefan Hajnoczi , Laurent Vivier Subject: [PATCH v3 1/7] VirtioDeviceClass: Add an Error parameter to vmstate load member Date: Thu, 30 Jul 2026 01:18:58 +0200 Message-ID: <20260729231904.775331-2-lvivier@redhat.com> In-Reply-To: <20260729231904.775331-1-lvivier@redhat.com> References: <20260729231904.775331-1-lvivier@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=lvivier@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -2 X-Spam_score: -0.3 X-Spam_bar: / X-Spam_report: (-0.3 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785367178921158500 Content-Type: text/plain; charset="utf-8" Replace error_report() by error_setg() when it's possible. In scsi-bus, check if error has been set by load_request, and propagate it to caller. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3888 Signed-off-by: Laurent Vivier Reviewed-by: Michael S. Tsirkin --- Notes: v2: new patch to propagate errors properly through the load_request cha= in includes changes made by Michael S. Tsirkin in https://lore.kernel.org/qemu-devel/3777347521a12252e228e4a6243c7525= 0bf76626.1784898250.git.mst@redhat.com hw/block/virtio-blk.c | 7 ++++--- hw/char/virtio-serial-bus.c | 20 +++++++++++--------- hw/scsi/esp.c | 2 +- hw/scsi/mptsas.c | 2 +- hw/scsi/scsi-bus.c | 18 ++++++++++++++++-- hw/scsi/scsi-disk.c | 7 ++++--- hw/scsi/scsi-generic.c | 3 ++- hw/scsi/spapr_vscsi.c | 7 ++++--- hw/scsi/virtio-scsi.c | 3 ++- hw/usb/dev-storage.c | 2 +- hw/virtio/virtio.c | 5 +++-- include/hw/scsi/scsi.h | 4 ++-- include/hw/usb/msd.h | 2 +- include/hw/virtio/virtio.h | 2 +- 14 files changed, 53 insertions(+), 31 deletions(-) diff --git a/hw/block/virtio-blk.c b/hw/block/virtio-blk.c index 6b92066aff4c..352b897c4ae5 100644 --- a/hw/block/virtio-blk.c +++ b/hw/block/virtio-blk.c @@ -1364,7 +1364,7 @@ static void virtio_blk_save_device(VirtIODevice *vdev= , QEMUFile *f) } =20 static int virtio_blk_load_device(VirtIODevice *vdev, QEMUFile *f, - int version_id) + int version_id, Error **errp) { VirtIOBlock *s =3D VIRTIO_BLK(vdev); =20 @@ -1377,8 +1377,9 @@ static int virtio_blk_load_device(VirtIODevice *vdev,= QEMUFile *f, vq_idx =3D qemu_get_be32(f); =20 if (vq_idx >=3D nvqs) { - error_report("Invalid virtqueue index in request list: %#x= ", - vq_idx); + error_setg(errp, + "Invalid virtqueue index in request list: 0x%x", + vq_idx); return -EINVAL; } } diff --git a/hw/char/virtio-serial-bus.c b/hw/char/virtio-serial-bus.c index c1973f0248fc..87bfe51b6e93 100644 --- a/hw/char/virtio-serial-bus.c +++ b/hw/char/virtio-serial-bus.c @@ -725,8 +725,8 @@ static void virtio_serial_post_load_timer_cb(void *opaq= ue) s->post_load =3D NULL; } =20 -static int fetch_active_ports_list(QEMUFile *f, - VirtIOSerial *s, uint32_t nr_active_por= ts) +static int fetch_active_ports_list(QEMUFile *f, VirtIOSerial *s, + uint32_t nr_active_ports, Error **errp) { VirtIODevice *vdev =3D VIRTIO_DEVICE(s); uint32_t i; @@ -749,6 +749,7 @@ static int fetch_active_ports_list(QEMUFile *f, id =3D qemu_get_be32(f); port =3D find_port_by_id(s, id); if (!port) { + error_setg(errp, "Invalid port id %u", id); return -EINVAL; } =20 @@ -776,7 +777,7 @@ static int fetch_active_ports_list(QEMUFile *f, } =20 static int virtio_serial_load_device(VirtIODevice *vdev, QEMUFile *f, - int version_id) + int version_id, Error **errp) { VirtIOSerial *s =3D VIRTIO_SERIAL(vdev); uint32_t max_nr_ports, nr_active_ports, ports_map; @@ -794,10 +795,8 @@ static int virtio_serial_load_device(VirtIODevice *vde= v, QEMUFile *f, qemu_get_be32s(f, &ports_map); =20 if (ports_map !=3D s->ports_map[i]) { - /* - * Ports active on source and destination don't - * match. Fail migration. - */ + error_setg(errp, "Ports active on source (%u) and destination = (%u)" + " don't match", ports_map, s->ports_map[i]); return -EINVAL; } } @@ -805,8 +804,11 @@ static int virtio_serial_load_device(VirtIODevice *vde= v, QEMUFile *f, qemu_get_be32s(f, &nr_active_ports); =20 if (nr_active_ports) { - ret =3D fetch_active_ports_list(f, s, nr_active_ports); - if (ret) { + Error *local_err =3D NULL; + + ret =3D fetch_active_ports_list(f, s, nr_active_ports, &local_err); + if (local_err) { + error_propagate(errp, local_err); return ret; } } diff --git a/hw/scsi/esp.c b/hw/scsi/esp.c index 933271431ba0..a99bfe8e9428 100644 --- a/hw/scsi/esp.c +++ b/hw/scsi/esp.c @@ -1539,7 +1539,7 @@ static uint64_t sysbus_esp_pdma_read(void *opaque, hw= addr addr, return val; } =20 -static void *esp_load_request(QEMUFile *f, SCSIRequest *req) +static void *esp_load_request(QEMUFile *f, SCSIRequest *req, Error **errp) { ESPState *s =3D container_of(req->bus, ESPState, bus); =20 diff --git a/hw/scsi/mptsas.c b/hw/scsi/mptsas.c index 5df124c0ce50..45638af0afc3 100644 --- a/hw/scsi/mptsas.c +++ b/hw/scsi/mptsas.c @@ -1230,7 +1230,7 @@ static void mptsas_save_request(QEMUFile *f, SCSIRequ= est *sreq) } } =20 -static void *mptsas_load_request(QEMUFile *f, SCSIRequest *sreq) +static void *mptsas_load_request(QEMUFile *f, SCSIRequest *sreq, Error **e= rrp) { SCSIBus *bus =3D sreq->bus; MPTSASState *s =3D container_of(bus, MPTSASState, bus); diff --git a/hw/scsi/scsi-bus.c b/hw/scsi/scsi-bus.c index deb43d5560e3..9e9bb977bee3 100644 --- a/hw/scsi/scsi-bus.c +++ b/hw/scsi/scsi-bus.c @@ -1921,10 +1921,24 @@ static int get_scsi_requests(QEMUFile *f, void *pv,= size_t size, req =3D scsi_req_new(s, tag, lun, buf, sizeof(buf), NULL); req->retry =3D (sbyte =3D=3D 1); if (bus->info->load_request) { - req->hba_private =3D bus->info->load_request(f, req); + Error *local_err =3D NULL; + + req->hba_private =3D bus->info->load_request(f, req, &local_er= r); + if (local_err) { + error_report_err(local_err); + scsi_req_unref(req); + return -1; + } } if (req->ops->load_request) { - req->ops->load_request(f, req); + Error *local_err =3D NULL; + + req->ops->load_request(f, req, &local_err); + if (local_err) { + error_report_err(local_err); + scsi_req_unref(req); + return -1; + } } =20 /* Just restart it later. */ diff --git a/hw/scsi/scsi-disk.c b/hw/scsi/scsi-disk.c index 1b0cce128c5e..00f12439d1b6 100644 --- a/hw/scsi/scsi-disk.c +++ b/hw/scsi/scsi-disk.c @@ -181,7 +181,7 @@ static void scsi_disk_emulate_save_request(QEMUFile *f,= SCSIRequest *req) } } =20 -static void scsi_disk_load_request(QEMUFile *f, SCSIRequest *req) +static void scsi_disk_load_request(QEMUFile *f, SCSIRequest *req, Error **= errp) { SCSIDiskReq *r =3D DO_UPCAST(SCSIDiskReq, req, req); =20 @@ -204,12 +204,13 @@ static void scsi_disk_load_request(QEMUFile *f, SCSIR= equest *req) qemu_iovec_init_external(&r->qiov, &r->iov, 1); } =20 -static void scsi_disk_emulate_load_request(QEMUFile *f, SCSIRequest *req) +static void scsi_disk_emulate_load_request(QEMUFile *f, SCSIRequest *req, + Error **errp) { SCSIDiskState *s =3D DO_UPCAST(SCSIDiskState, qdev, req->dev); =20 if (s->migrate_emulated_scsi_request) { - scsi_disk_load_request(f, req); + scsi_disk_load_request(f, req, errp); } } =20 diff --git a/hw/scsi/scsi-generic.c b/hw/scsi/scsi-generic.c index 8999f3b72006..20deb9a21250 100644 --- a/hw/scsi/scsi-generic.c +++ b/hw/scsi/scsi-generic.c @@ -53,7 +53,8 @@ static void scsi_generic_save_request(QEMUFile *f, SCSIRe= quest *req) } } =20 -static void scsi_generic_load_request(QEMUFile *f, SCSIRequest *req) +static void scsi_generic_load_request(QEMUFile *f, SCSIRequest *req, + Error **errp) { SCSIGenericReq *r =3D DO_UPCAST(SCSIGenericReq, req, req); =20 diff --git a/hw/scsi/spapr_vscsi.c b/hw/scsi/spapr_vscsi.c index b4c8f94d22ad..7768ec0bdd49 100644 --- a/hw/scsi/spapr_vscsi.c +++ b/hw/scsi/spapr_vscsi.c @@ -642,7 +642,7 @@ static void vscsi_save_request(QEMUFile *f, SCSIRequest= *sreq) req->cur_desc_offset); } =20 -static void *vscsi_load_request(QEMUFile *f, SCSIRequest *sreq) +static void *vscsi_load_request(QEMUFile *f, SCSIRequest *sreq, Error **er= rp) { SCSIBus *bus =3D sreq->bus; VSCSIState *s =3D VIO_SPAPR_VSCSI_DEVICE(bus->qbus.parent); @@ -657,8 +657,9 @@ static void *vscsi_load_request(QEMUFile *f, SCSIReques= t *sreq) memset(req, 0, sizeof(*req)); rc =3D vmstate_load_state(f, &vmstate_spapr_vscsi_req, req, 1, &local_= err); if (rc) { - fprintf(stderr, "VSCSI: failed loading request tag#%u\n", sreq->ta= g); - error_report_err(local_err); + error_propagate_prepend(errp, local_err, + "VSCSI: failed loading request tag#%u: ", + sreq->tag); return NULL; } assert(req->active); diff --git a/hw/scsi/virtio-scsi.c b/hw/scsi/virtio-scsi.c index bf64d1231a81..54667dc4f51d 100644 --- a/hw/scsi/virtio-scsi.c +++ b/hw/scsi/virtio-scsi.c @@ -261,7 +261,8 @@ static void virtio_scsi_save_request(QEMUFile *f, SCSIR= equest *sreq) qemu_put_virtqueue_element(vdev, f, &req->elem); } =20 -static void *virtio_scsi_load_request(QEMUFile *f, SCSIRequest *sreq) +static void *virtio_scsi_load_request(QEMUFile *f, SCSIRequest *sreq, + Error **errp) { SCSIBus *bus =3D sreq->bus; VirtIOSCSI *s =3D container_of(bus, VirtIOSCSI, bus); diff --git a/hw/usb/dev-storage.c b/hw/usb/dev-storage.c index 040cf1505181..d74aa087de66 100644 --- a/hw/usb/dev-storage.c +++ b/hw/usb/dev-storage.c @@ -556,7 +556,7 @@ static void usb_msd_handle_data(USBDevice *dev, USBPack= et *p) } } =20 -void *usb_msd_load_request(QEMUFile *f, SCSIRequest *req) +void *usb_msd_load_request(QEMUFile *f, SCSIRequest *req, Error **errp) { MSDState *s =3D DO_UPCAST(MSDState, dev.qdev, req->bus->qbus.parent); =20 diff --git a/hw/virtio/virtio.c b/hw/virtio/virtio.c index daa5607338c9..64d780b1336e 100644 --- a/hw/virtio/virtio.c +++ b/hw/virtio/virtio.c @@ -3610,8 +3610,9 @@ virtio_load(VirtIODevice *vdev, QEMUFile *f, int vers= ion_id) virtio_notify_vector(vdev, VIRTIO_NO_VECTOR); =20 if (vdc->load !=3D NULL) { - ret =3D vdc->load(vdev, f, version_id); - if (ret) { + ret =3D vdc->load(vdev, f, version_id, &local_err); + if (local_err) { + error_report_err(local_err); return ret; } } diff --git a/include/hw/scsi/scsi.h b/include/hw/scsi/scsi.h index c60c6e8810ea..51ccd02951c6 100644 --- a/include/hw/scsi/scsi.h +++ b/include/hw/scsi/scsi.h @@ -134,7 +134,7 @@ struct SCSIReqOps { uint8_t *(*get_buf)(SCSIRequest *req); =20 void (*save_request)(QEMUFile *f, SCSIRequest *req); - void (*load_request)(QEMUFile *f, SCSIRequest *req); + void (*load_request)(QEMUFile *f, SCSIRequest *req, Error **errp); }; =20 struct SCSIBusInfo { @@ -150,7 +150,7 @@ struct SCSIBusInfo { QEMUSGList *(*get_sg_list)(SCSIRequest *req); =20 void (*save_request)(QEMUFile *f, SCSIRequest *req); - void *(*load_request)(QEMUFile *f, SCSIRequest *req); + void *(*load_request)(QEMUFile *f, SCSIRequest *req, Error **errp); void (*free_request)(SCSIBus *bus, void *priv); =20 /* diff --git a/include/hw/usb/msd.h b/include/hw/usb/msd.h index 125d2c218f6d..167e7d3f2fe0 100644 --- a/include/hw/usb/msd.h +++ b/include/hw/usb/msd.h @@ -51,5 +51,5 @@ DECLARE_INSTANCE_CHECKER(MSDState, USB_STORAGE_DEV, void usb_msd_transfer_data(SCSIRequest *req, uint32_t len); void usb_msd_command_complete(SCSIRequest *req, size_t resid); void usb_msd_request_cancelled(SCSIRequest *req); -void *usb_msd_load_request(QEMUFile *f, SCSIRequest *req); +void *usb_msd_load_request(QEMUFile *f, SCSIRequest *req, Error **errp); void usb_msd_handle_reset(USBDevice *dev); diff --git a/include/hw/virtio/virtio.h b/include/hw/virtio/virtio.h index c99cb19d8865..bcb03154e243 100644 --- a/include/hw/virtio/virtio.h +++ b/include/hw/virtio/virtio.h @@ -268,7 +268,7 @@ struct VirtioDeviceClass { * use vmsd for new devices. */ void (*save)(VirtIODevice *vdev, QEMUFile *f); - int (*load)(VirtIODevice *vdev, QEMUFile *f, int version_id); + int (*load)(VirtIODevice *vdev, QEMUFile *f, int version_id, Error **e= rrp); /* Post load hook in vmsd is called early while device is processed, a= nd * when VirtIODevice isn't fully initialized. Devices should use this= instead, * unless they specifically want to verify the migration stream as it's --=20 2.54.0 From nobody Mon Sep 28 02:06:11 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785367198; cv=none; d=zohomail.com; s=zohoarc; b=J17NfkXCUAY4HAccVR9/u3wNhIsyBJ7/TABHw4CUwxmakj+Fe6QTLq5j8Q/nCxpE/XGQZaz2pT6McftcRZs1e+GNAmzC67MH+PwkLfErLn2lCVsumed+kK1gRL5bTC5PB+Ici7OJde+9MG1DRZN/s6mXT/OM2l/jwlBjiOUZ6LI= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785367198; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=DJwXA5fhz3UpXRGEEgItusWtCzmiEOpXllTR2/JfArM=; b=jT3W9RKy0ZddjFH0ONmlxlW8fSaR45HBb9dLO+/+ocg3qlI23aXLs9g/cfbdTBy77gMh42QUBfVsc7CrsVsExflWqf+iE76LROlylTMqHi+Vfmf7YN1YUjoE2y0zfkU/nreUIj1iA2BaWD+OylhjhLKIBQJuI0FckNIsuVVq1zg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785367198549613.8216715524294; Wed, 29 Jul 2026 16:19:58 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpDYd-0002sw-CE; Wed, 29 Jul 2026 19:19:27 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpDYb-0002qe-8Q for qemu-devel@nongnu.org; Wed, 29 Jul 2026 19:19:25 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpDYZ-0008CF-8t for qemu-devel@nongnu.org; Wed, 29 Jul 2026 19:19:24 -0400 Received: from mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-186-luHvFdHeOtSZm-GsEIdfDQ-1; Wed, 29 Jul 2026 19:19:19 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-08.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id A391018002C7; Wed, 29 Jul 2026 23:19:17 +0000 (UTC) Received: from lenovo-t14s.redhat.corp (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id CDCBD300019F; Wed, 29 Jul 2026 23:19:13 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785367162; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=DJwXA5fhz3UpXRGEEgItusWtCzmiEOpXllTR2/JfArM=; b=Wd/Ab3hOMv0TPaU1S8SlhT2rPsSR1c+OsePWD2weZM3LEPMZaj7n2V3St1oFAwe9VgDGiP WU2rcx2UHbC5k8MKxhMpO0qc/QMsa4yGHtfn4iWtyJURb0GddDatNvP0vI6Pu78jGCBnPZ eqCmiq4jtcdf7Eh//7TloL9jEmCOpkE= X-MC-Unique: luHvFdHeOtSZm-GsEIdfDQ-1 X-Mimecast-MFC-AGG-ID: luHvFdHeOtSZm-GsEIdfDQ_1785367158 From: Laurent Vivier To: qemu-devel@nongnu.org Cc: Amit Shah , qemu-ppc@nongnu.org, Harsh Prateek Bora , Hanna Reitz , Nicholas Piggin , "Michael S. Tsirkin" , Kevin Wolf , Paolo Bonzini , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Fam Zheng , qemu-block@nongnu.org, Stefan Hajnoczi , Laurent Vivier , qemu-stable@nongnu.org, =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= , Thomas Huth Subject: [PATCH v3 2/7] hw/char/virtio-serial-bus: validate nr_active_ports from migration stream Date: Thu, 30 Jul 2026 01:18:59 +0200 Message-ID: <20260729231904.775331-3-lvivier@redhat.com> In-Reply-To: <20260729231904.775331-1-lvivier@redhat.com> References: <20260729231904.775331-1-lvivier@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=lvivier@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -36 X-Spam_score: -3.7 X-Spam_bar: --- X-Spam_report: (-3.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785367199158158500 The migration restore path reads nr_active_ports from the incoming stream and passes it directly to fetch_active_ports_list(), which uses it to size a heap allocation. A crafted migration stream can set this field to a very large value, causing QEMU to attempt a multi-gigabyte allocation and abort. Fix this by checking nr_active_ports against the configured max_virtserial_ports before calling fetch_active_ports_list(). Cc: qemu-stable@nongnu.org Fixes: 6663a1956eb6 ("virtio-serial-bus: Maintain guest and host port open/= close state") Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3801 Signed-off-by: Laurent Vivier Reviewed-by: Daniel P. Berrang=C3=A9 Reviewed-by: Thomas Huth Acked-by: Michael S. Tsirkin Reviewed-by: Michael S. Tsirkin --- Notes: v2: add error_setg() call with descriptive error message hw/char/virtio-serial-bus.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/hw/char/virtio-serial-bus.c b/hw/char/virtio-serial-bus.c index 87bfe51b6e93..4a5507e2f755 100644 --- a/hw/char/virtio-serial-bus.c +++ b/hw/char/virtio-serial-bus.c @@ -803,6 +803,12 @@ static int virtio_serial_load_device(VirtIODevice *vde= v, QEMUFile *f, =20 qemu_get_be32s(f, &nr_active_ports); =20 + if (nr_active_ports > max_nr_ports) { + error_setg(errp, "Invalid number of active ports %u > %u", nr_acti= ve_ports, + max_nr_ports); + return -EINVAL; + } + if (nr_active_ports) { Error *local_err =3D NULL; =20 --=20 2.54.0 From nobody Mon Sep 28 02:06:11 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785367224; cv=none; d=zohomail.com; s=zohoarc; b=I0gLxPqBrZnAQEBm+NXVUro0Xl1Ag1CAf0AeKpIZnfnfQkggYNzxZj2FhrNU2re/nWgS+VjctB4Hhkc9VzDCz+HdbCDmIHDmVwYS/hG11H7Kd+enVWaTmtHnVf3B5bWggg036hecsDagM1whdlDu8++yF443okOPgmnfpyFABLw= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785367224; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=kYhAW+MmremG0AzEeRTehlTgSHTPIg2EzLiHUHZj2S0=; b=ElM+NTKew6udMpGm7pBD8psA8VJhwTvycS/rVtjUrgk6jQTnvIIzM70aMHukOBt8kPNE5i/IJ7nXzDU4E/Zfg49iTGvz+cI5viOX3asQvZXOA2IcJll6jsH+n7/WziV6qbsyaCExPynWn08vrnslPxN0RxlhI66p8hK4NO/YdSg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785367224650706.5120334557305; Wed, 29 Jul 2026 16:20:24 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpDYf-0002um-AS; Wed, 29 Jul 2026 19:19:29 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpDYe-0002tV-Fd for qemu-devel@nongnu.org; Wed, 29 Jul 2026 19:19:28 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpDYc-0008Db-J7 for qemu-devel@nongnu.org; Wed, 29 Jul 2026 19:19:28 -0400 Received: from mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-550-Y9ONrybsP3-Wzgu2qa53oQ-1; Wed, 29 Jul 2026 19:19:22 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-05.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 528731956096; Wed, 29 Jul 2026 23:19:21 +0000 (UTC) Received: from lenovo-t14s.redhat.corp (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 024DD300019F; Wed, 29 Jul 2026 23:19:17 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785367166; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=kYhAW+MmremG0AzEeRTehlTgSHTPIg2EzLiHUHZj2S0=; b=Ovb7ig2vzlsfHFC4cHhcAwoivbdi+rAIGymiCz6AMfPRCEuqHe7X+dvkw5jAaR2Td/CMCh BFzGoEUYriEClezl0QhFzCUWYKasWqetpjfRQesxizzXn0ECx5fS4F+ATubAaQMoUQh7+d GGdYeB+vCu3F72vHUc5My+/h+edwd7g= X-MC-Unique: Y9ONrybsP3-Wzgu2qa53oQ-1 X-Mimecast-MFC-AGG-ID: Y9ONrybsP3-Wzgu2qa53oQ_1785367161 From: Laurent Vivier To: qemu-devel@nongnu.org Cc: Amit Shah , qemu-ppc@nongnu.org, Harsh Prateek Bora , Hanna Reitz , Nicholas Piggin , "Michael S. Tsirkin" , Kevin Wolf , Paolo Bonzini , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Fam Zheng , qemu-block@nongnu.org, Stefan Hajnoczi , Laurent Vivier Subject: [PATCH v3 3/7] virtio: do not crash QEMU on migration errors Date: Thu, 30 Jul 2026 01:19:00 +0200 Message-ID: <20260729231904.775331-4-lvivier@redhat.com> In-Reply-To: <20260729231904.775331-1-lvivier@redhat.com> References: <20260729231904.775331-1-lvivier@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=lvivier@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -2 X-Spam_score: -0.3 X-Spam_bar: / X-Spam_report: (-0.3 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785367225095158500 Content-Type: text/plain; charset="utf-8" From: "Michael S. Tsirkin" Currently virtio-blk, virtio-serial and virtio-scsi all crash on invalid migration streams because qemu_get_virtqueue_element has no way to detect and report mapping failures. Not nice. Let's propagate mapping errors through qemu_get_virtqueue_element and fail migration instead. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3888 Signed-off-by: Michael S. Tsirkin [lvivier: use errp rather than qemu_file_set_error() to report error] Signed-off-by: Laurent Vivier Reviewed-by: Michael S. Tsirkin --- Notes: v2: new patch from Michael S. Tsirkin https://lore.kernel.org/qemu-devel/a0afc9ea82d68f3447c9f58d89c9b46f= a074d6c3.1784898250.git.mst@redhat.com/ Modified to use errp parameter with error_setg() instead of qemu_file_set_error() to report errors in virtio-blk, virtio-serial, and virtio-scsi hw/block/virtio-blk.c | 4 ++++ hw/char/virtio-serial-bus.c | 4 ++++ hw/scsi/virtio-scsi.c | 4 ++++ hw/virtio/virtio.c | 48 +++++++++++++++++++++++++++---------- include/hw/virtio/virtio.h | 2 +- 5 files changed, 48 insertions(+), 14 deletions(-) diff --git a/hw/block/virtio-blk.c b/hw/block/virtio-blk.c index 352b897c4ae5..ccd6ad404ca0 100644 --- a/hw/block/virtio-blk.c +++ b/hw/block/virtio-blk.c @@ -1385,6 +1385,10 @@ static int virtio_blk_load_device(VirtIODevice *vdev= , QEMUFile *f, } =20 req =3D qemu_get_virtqueue_element(vdev, f, sizeof(VirtIOBlockReq)= ); + if (!req) { + error_setg(errp, "Failed to restore virtio-blk request"); + return -EINVAL; + } virtio_blk_init_request(s, virtio_get_queue(vdev, vq_idx), req); =20 WITH_QEMU_LOCK_GUARD(&s->rq_lock) { diff --git a/hw/char/virtio-serial-bus.c b/hw/char/virtio-serial-bus.c index 4a5507e2f755..ecb7c5c7e507 100644 --- a/hw/char/virtio-serial-bus.c +++ b/hw/char/virtio-serial-bus.c @@ -764,6 +764,10 @@ static int fetch_active_ports_list(QEMUFile *f, VirtIO= Serial *s, =20 port->elem =3D qemu_get_virtqueue_element(vdev, f, sizeof(VirtQueueElemen= t)); + if (!port->elem) { + error_setg(errp, "Failed to restore virtio-serial element"= ); + return -EINVAL; + } =20 /* * Port was throttled on source machine. Let's diff --git a/hw/scsi/virtio-scsi.c b/hw/scsi/virtio-scsi.c index 54667dc4f51d..10eee3a4cff8 100644 --- a/hw/scsi/virtio-scsi.c +++ b/hw/scsi/virtio-scsi.c @@ -275,6 +275,10 @@ static void *virtio_scsi_load_request(QEMUFile *f, SCS= IRequest *sreq, assert(n < vs->conf.num_queues); req =3D qemu_get_virtqueue_element(vdev, f, sizeof(VirtIOSCSIReq) + vs->cdb_size); + if (!req) { + error_setg(errp, "Failed to restore virtio-scsi request"); + return NULL; + } virtio_scsi_init_req(s, vs->cmd_vqs[n], req); =20 if (virtio_scsi_parse_req(req, sizeof(VirtIOSCSICmdReq) + vs->cdb_size, diff --git a/hw/virtio/virtio.c b/hw/virtio/virtio.c index 64d780b1336e..02f75a5e281b 100644 --- a/hw/virtio/virtio.c +++ b/hw/virtio/virtio.c @@ -1680,36 +1680,55 @@ static void virtqueue_undo_map_desc(AddressSpace *a= s, } } =20 -static void virtqueue_map_iovec(VirtIODevice *vdev, struct iovec *sg, +static bool virtqueue_map_iovec(VirtIODevice *vdev, struct iovec *sg, hwaddr *addr, unsigned int num_sg, bool is_write) { unsigned int i; hwaddr len; + DMADirection dir =3D is_write ? DMA_DIRECTION_FROM_DEVICE : + DMA_DIRECTION_TO_DEVICE; =20 for (i =3D 0; i < num_sg; i++) { len =3D sg[i].iov_len; - sg[i].iov_base =3D dma_memory_map(vdev->dma_as, - addr[i], &len, is_write ? - DMA_DIRECTION_FROM_DEVICE : - DMA_DIRECTION_TO_DEVICE, - MEMTXATTRS_UNSPECIFIED); + sg[i].iov_base =3D dma_memory_map(vdev->dma_as, addr[i], &len, + dir, MEMTXATTRS_UNSPECIFIED); if (!sg[i].iov_base) { error_report("virtio: error trying to map MMIO memory"); - exit(1); + goto err_undo_map; } if (len !=3D sg[i].iov_len) { error_report("virtio: unexpected memory split"); - exit(1); + dma_memory_unmap(vdev->dma_as, sg[i].iov_base, len, dir, 0); + goto err_undo_map; } } + return true; + +err_undo_map: + while (i-- > 0) { + dma_memory_unmap(vdev->dma_as, sg[i].iov_base, sg[i].iov_len, + dir, 0); + } + return false; } =20 -void virtqueue_map(VirtIODevice *vdev, VirtQueueElement *elem) +bool virtqueue_map(VirtIODevice *vdev, VirtQueueElement *elem) { - virtqueue_map_iovec(vdev, elem->in_sg, elem->in_addr, elem->in_num, tr= ue); - virtqueue_map_iovec(vdev, elem->out_sg, elem->out_addr, elem->out_num, - fa= lse); + if (!virtqueue_map_iovec(vdev, elem->in_sg, elem->in_addr, + elem->in_num, true)) { + return false; + } + if (!virtqueue_map_iovec(vdev, elem->out_sg, elem->out_addr, + elem->out_num, false)) { + for (unsigned int i =3D 0; i < elem->in_num; i++) { + dma_memory_unmap(vdev->dma_as, elem->in_sg[i].iov_base, + elem->in_sg[i].iov_len, + DMA_DIRECTION_FROM_DEVICE, 0); + } + return false; + } + return true; } =20 static void *virtqueue_alloc_element(size_t sz, unsigned out_num, unsigned= in_num) @@ -2206,7 +2225,10 @@ void *qemu_get_virtqueue_element(VirtIODevice *vdev,= QEMUFile *f, size_t sz) qemu_get_be32s(f, &elem->ndescs); } =20 - virtqueue_map(vdev, elem); + if (!virtqueue_map(vdev, elem)) { + g_free(elem); + return NULL; + } return elem; } =20 diff --git a/include/hw/virtio/virtio.h b/include/hw/virtio/virtio.h index bcb03154e243..d0c63500a58d 100644 --- a/include/hw/virtio/virtio.h +++ b/include/hw/virtio/virtio.h @@ -320,7 +320,7 @@ bool virtqueue_rewind(VirtQueue *vq, unsigned int num); void virtqueue_fill(VirtQueue *vq, const VirtQueueElement *elem, unsigned int len, unsigned int idx); =20 -void virtqueue_map(VirtIODevice *vdev, VirtQueueElement *elem); +bool virtqueue_map(VirtIODevice *vdev, VirtQueueElement *elem); void *virtqueue_pop(VirtQueue *vq, size_t sz); unsigned int virtqueue_drop_all(VirtQueue *vq); void *qemu_get_virtqueue_element(VirtIODevice *vdev, QEMUFile *f, size_t s= z); --=20 2.54.0 From nobody Mon Sep 28 02:06:11 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785367259; cv=none; d=zohomail.com; s=zohoarc; b=L/h+gzRtleEX5N+h830XHZl/Vj3Cpn61JnY63Y4vQ2VVNnIglbap25ZMbnbzUYGH8ktrCP2oYEIQNlPODqIjuzHA3tVZadrw10MgTR2Ao//+44ECiAe0OkMCg5TUfyovOZrk1ZOqT4zSo9NU2l1tjLNBfavu5fhwiaPMS+2cPu0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785367259; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=cTq/hPF0C9ov5KjJJKOg7tFlOqIq8jY9QRhMEBgsKIA=; b=a9QHPee6HYs8iBy9nEH9kk2BeTDB4Ua0dRoGDsiFlmL6rB0bWdnlNTtF62kKH0aYvdsK85oFvQmjLEwvXn1jYS9b5Cc6GKqjY5h0/YOhI4o13WCr9YuUz4Jx0hg3S+2B4RX3HLn7TjmHS7fNw7qBtHcwt6OyAgHwFGBq8RJyU3A= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785367259521595.1141901599027; Wed, 29 Jul 2026 16:20:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpDYq-0003Ea-NN; Wed, 29 Jul 2026 19:19:40 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpDYo-00037D-Pq for qemu-devel@nongnu.org; Wed, 29 Jul 2026 19:19:38 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpDYn-0008Fb-0g for qemu-devel@nongnu.org; Wed, 29 Jul 2026 19:19:38 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-251-haFmibY8Puer8I2-XGRlUg-1; Wed, 29 Jul 2026 19:19:26 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id C807219560B2; Wed, 29 Jul 2026 23:19:24 +0000 (UTC) Received: from lenovo-t14s.redhat.corp (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 8E44F300019F; Wed, 29 Jul 2026 23:19:21 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785367176; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=cTq/hPF0C9ov5KjJJKOg7tFlOqIq8jY9QRhMEBgsKIA=; b=h5lmEZO4ugdNpofXELLqhKVOXmTEZGnx8JBfkhcC4eDJMgIcz3Wz8IdSRnEIYA5n4VQWDR JybsGvr1aAXKvXhdDQzWzvPPluupG02m/5LkFDIZcBCKO/of5N7T0ex0TW5VR7uXUCsMtw pdFrrzIf0fYjvhINuQ5Wne4Lp9gIb7w= X-MC-Unique: haFmibY8Puer8I2-XGRlUg-1 X-Mimecast-MFC-AGG-ID: haFmibY8Puer8I2-XGRlUg_1785367165 From: Laurent Vivier To: qemu-devel@nongnu.org Cc: Amit Shah , qemu-ppc@nongnu.org, Harsh Prateek Bora , Hanna Reitz , Nicholas Piggin , "Michael S. Tsirkin" , Kevin Wolf , Paolo Bonzini , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Fam Zheng , qemu-block@nongnu.org, Stefan Hajnoczi , Laurent Vivier , qemu-stable@nongnu.org Subject: [PATCH v3 4/7] hw/virtio: return NULL from qemu_get_virtqueue_element() on invalid state Date: Thu, 30 Jul 2026 01:19:01 +0200 Message-ID: <20260729231904.775331-5-lvivier@redhat.com> In-Reply-To: <20260729231904.775331-1-lvivier@redhat.com> References: <20260729231904.775331-1-lvivier@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=lvivier@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -2 X-Spam_score: -0.3 X-Spam_bar: / X-Spam_report: (-0.3 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785367261238158500 Content-Type: text/plain; charset="utf-8" qemu_get_virtqueue_element() uses assert() to check that the in_num and out_num fields deserialized from the migration stream do not exceed VIRTQUEUE_MAX_SIZE. A crafted migration stream can set these fields to invalid values, hitting the assertion and aborting the destination QEMU process. Replace the assertions with a bounds check that returns NULL on failure. Cc: qemu-stable@nongnu.org Fixes: 6bdc21c050a2 ("virtio: fix up max size checks") Resolves: https://gitlab.com/qemu-project/qemu/-/issues/3802 Signed-off-by: Laurent Vivier Reviewed-by: Michael S. Tsirkin --- Notes: v2: remove caller updates (now handled by patch 3 from Michael) hw/virtio/virtio.c | 11 ++++------- 1 file changed, 4 insertions(+), 7 deletions(-) diff --git a/hw/virtio/virtio.c b/hw/virtio/virtio.c index 02f75a5e281b..c37ef01bf513 100644 --- a/hw/virtio/virtio.c +++ b/hw/virtio/virtio.c @@ -2190,13 +2190,10 @@ void *qemu_get_virtqueue_element(VirtIODevice *vdev= , QEMUFile *f, size_t sz) =20 qemu_get_buffer(f, (uint8_t *)&data, sizeof(VirtQueueElementOld)); =20 - /* TODO: teach all callers that this can fail, and return failure inst= ead - * of asserting here. - * This is just one thing (there are probably more) that must be - * fixed before we can allow NDEBUG compilation. - */ - assert(ARRAY_SIZE(data.in_addr) >=3D data.in_num); - assert(ARRAY_SIZE(data.out_addr) >=3D data.out_num); + if (data.in_num > ARRAY_SIZE(data.in_addr) || + data.out_num > ARRAY_SIZE(data.out_addr)) { + return NULL; + } =20 elem =3D virtqueue_alloc_element(sz, data.out_num, data.in_num); elem->index =3D data.index; --=20 2.54.0 From nobody Mon Sep 28 02:06:11 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785367257; cv=none; d=zohomail.com; s=zohoarc; b=dUI1alKd4u05i69Um32hZ5dJ1X9/7ICK3el+USfpk8mM2hAooaM0VmGqvQ4rJdhl5nVrThFgylmP5r9f8NsrhLKPHW0bkexuboBy3e8rag4WObjjFoVmv9aFUPJPSNDwhbRVpbO/KrJU8EDRlj4abIeqODFAwVv7QFeD9JJ/Vts= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785367257; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=Fpn1QAset08EX22OWWgA+5utTHpUdP9lkZAeuaAvzbk=; b=bsm9U/zNu3HB4VyE313/5G3oeAbG/VcFDI4+J2M8R0yGzYeHM1z3naF3WkasUsJtXojcOhBkmqV2ZxXGWtFJdGPp2OX6jcyC2eEZSxXmEc2B99mDiiRlvENldcb5EbHum0zHrsjBPqFA+efu9VAEslYtKgZnA+nkA4+ZoMrDTTA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785367257280389.7905366820678; Wed, 29 Jul 2026 16:20:57 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpDYp-0003A1-Q7; Wed, 29 Jul 2026 19:19:39 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpDYo-000375-M9 for qemu-devel@nongnu.org; Wed, 29 Jul 2026 19:19:38 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpDYm-0008FI-09 for qemu-devel@nongnu.org; Wed, 29 Jul 2026 19:19:38 -0400 Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-608-CyRn6ecHMT6yxdz1WDdzKg-1; Wed, 29 Jul 2026 19:19:29 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 8449018004BB; Wed, 29 Jul 2026 23:19:28 +0000 (UTC) Received: from lenovo-t14s.redhat.corp (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 27B9230001A4; Wed, 29 Jul 2026 23:19:24 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785367175; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=Fpn1QAset08EX22OWWgA+5utTHpUdP9lkZAeuaAvzbk=; b=A5ybB+gtXx44y57AIkc3SL/4xp9NR/YUaJlxsTIgsjy/upgL8MIhbxyF148Lmrx5vMuXcU kHBlBd++c+yhQDDoQnaME8K3RbDCfN9dW3+XU/SiKFkkPSPH/c9XVZE43R+yXQsZU0kzPO cejUXcHg/VpzfqB5Tjkg5SofUfQ8YA0= X-MC-Unique: CyRn6ecHMT6yxdz1WDdzKg-1 X-Mimecast-MFC-AGG-ID: CyRn6ecHMT6yxdz1WDdzKg_1785367168 From: Laurent Vivier To: qemu-devel@nongnu.org Cc: Amit Shah , qemu-ppc@nongnu.org, Harsh Prateek Bora , Hanna Reitz , Nicholas Piggin , "Michael S. Tsirkin" , Kevin Wolf , Paolo Bonzini , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Fam Zheng , qemu-block@nongnu.org, Stefan Hajnoczi , Laurent Vivier Subject: [PATCH v3 5/7] mptsas: do not crash QEMU on migration errors Date: Thu, 30 Jul 2026 01:19:02 +0200 Message-ID: <20260729231904.775331-6-lvivier@redhat.com> In-Reply-To: <20260729231904.775331-1-lvivier@redhat.com> References: <20260729231904.775331-1-lvivier@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=lvivier@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -36 X-Spam_score: -3.7 X-Spam_bar: --- X-Spam_report: (-3.7 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785367259313158500 Content-Type: text/plain; charset="utf-8" From: "Michael S. Tsirkin" Currently mptsas asserts on invalid sg list count in the migration stream. Fail migration gracefully instead. Signed-off-by: Michael S. Tsirkin [lvivier: use errp rather than qemu_file_set_error() to report error] Signed-off-by: Laurent Vivier Reviewed-by: Michael S. Tsirkin --- Notes: v2: new patch from Michael S. Tsirkin https://lore.kernel.org/qemu-devel/258d84f5af807e0103bf6f59165dd745= 0918e58c.1784898250.git.mst@redhat.com/ Modified to use errp parameter with error_setg() instead of qemu_file_set_error() to report error hw/scsi/mptsas.c | 14 ++++++++------ 1 file changed, 8 insertions(+), 6 deletions(-) diff --git a/hw/scsi/mptsas.c b/hw/scsi/mptsas.c index 45638af0afc3..34ceb6b5d25e 100644 --- a/hw/scsi/mptsas.c +++ b/hw/scsi/mptsas.c @@ -36,6 +36,8 @@ #include "qapi/error.h" #include "mptsas.h" #include "migration/qemu-file-types.h" +#include "migration/qemu-file.h" +#include "qemu/error-report.h" #include "migration/vmstate.h" #include "mpi.h" =20 @@ -1242,12 +1244,12 @@ static void *mptsas_load_request(QEMUFile *f, SCSIR= equest *sreq, Error **errp) qemu_get_buffer(f, (unsigned char *)&req->scsi_io, sizeof(req->scsi_io= )); =20 n =3D qemu_get_be32(f); - /* TODO: add a way for SCSIBusInfo's load_request to fail, - * and fail migration instead of asserting here. - * This is just one thing (there are probably more) that must be - * fixed before we can allow NDEBUG compilation. - */ - assert(n >=3D 0); + if (n < 0) { + error_setg(errp, "mptsas: invalid sg list count %d in migration st= ream", + n); + g_free(req); + return NULL; + } =20 pci_dma_sglist_init(&req->qsg, pci, n); for (i =3D 0; i < n; i++) { --=20 2.54.0 From nobody Mon Sep 28 02:06:11 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785367256; cv=none; d=zohomail.com; s=zohoarc; b=ZQxKqesIOmDfuqz43eBpDP7dfwZeaCFniYZXhqtVhHDomwLVQQjUCkGU009+iPr627m4adVinNMU/S5nx8iPgs7Rv8TtqWxaF579TR3FuKnvfUcgzAPBXXIVTjy0cc8t2eR1tK15K6ZuxK1ZfA3U/uEuL5rDcwJsu7nMNkZp0uA= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785367256; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=67WWBnFN4tlYKgPOBmTHpTwUwrzSTt9DuZyEdwHvf+I=; b=lKELWSZ21SNRU6GIeSTEoUOA9SEVJAbcjVsHFBPzbC+KaMT6lmKSl13/M0R3l0i029ay4wUEUynso5rpSgGWroOdNz8de0XnBU35DnAYwqyW+2A4M6mLIWiHHiE0GGCFA4Rq0B/bP6p5RxXrquU5sIZx3LVA17oMiCfqxldqPH0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785367256533721.526627055253; Wed, 29 Jul 2026 16:20:56 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpDYs-0003PE-SM; Wed, 29 Jul 2026 19:19:42 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpDYo-00037K-Sd for qemu-devel@nongnu.org; Wed, 29 Jul 2026 19:19:38 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpDYn-0008Fi-CE for qemu-devel@nongnu.org; Wed, 29 Jul 2026 19:19:38 -0400 Received: from mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-131-056JzQU3PYm8lXXVMxVFMA-1; Wed, 29 Jul 2026 19:19:33 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 189C619560B2; Wed, 29 Jul 2026 23:19:32 +0000 (UTC) Received: from lenovo-t14s.redhat.corp (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id D7A2230001A4; Wed, 29 Jul 2026 23:19:28 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785367176; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=67WWBnFN4tlYKgPOBmTHpTwUwrzSTt9DuZyEdwHvf+I=; b=OPo5k4wyt15CjwJ4Rc6nAwH6M/hpHEFp9agetlsskcNva69VAhivKMAJeL2tJ122Rs1+fE IAejBNmpPG+pLKSFg8SOGZx4lGNZDwWLRtuBuJeNgiRP6J8vxr6JbENpByVlKTV2dxzXyS BqSLFtsse/B1EpoMRRJttueLsCPqlHo= X-MC-Unique: 056JzQU3PYm8lXXVMxVFMA-1 X-Mimecast-MFC-AGG-ID: 056JzQU3PYm8lXXVMxVFMA_1785367172 From: Laurent Vivier To: qemu-devel@nongnu.org Cc: Amit Shah , qemu-ppc@nongnu.org, Harsh Prateek Bora , Hanna Reitz , Nicholas Piggin , "Michael S. Tsirkin" , Kevin Wolf , Paolo Bonzini , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Fam Zheng , qemu-block@nongnu.org, Stefan Hajnoczi , Laurent Vivier , qemu-stable@nongnu.org Subject: [PATCH v3 6/7] hw/scsi/virtio-scsi: harden virtio_scsi_load_request() against invalid stream Date: Thu, 30 Jul 2026 01:19:03 +0200 Message-ID: <20260729231904.775331-7-lvivier@redhat.com> In-Reply-To: <20260729231904.775331-1-lvivier@redhat.com> References: <20260729231904.775331-1-lvivier@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=lvivier@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -2 X-Spam_score: -0.3 X-Spam_bar: / X-Spam_report: (-0.3 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785367257302158500 Content-Type: text/plain; charset="utf-8" virtio_scsi_load_request() uses assert() and exit(1) for conditions that can be triggered by a crafted migration stream: an out-of-range queue index, a malformed SCSI request, or a command mode mismatch. Replace these with proper error returns so the migration fails gracefully instead of aborting the destination QEMU process. Cc: qemu-stable@nongnu.org Fixes: 5db1764cc1f6 ("virtio-scsi: add migration support") Fixes: d2ad7dd46e72 ("virtio-scsi: add multiqueue capability") Fixes: 36b15c79aa1b ("virtio-scsi: start preparing for any_layout") Signed-off-by: Laurent Vivier Reviewed-by: Michael S. Tsirkin Reviewed-by: Stefan Hajnoczi --- Notes: v2: add error_setg() calls with descriptive error messages for all three error paths hw/scsi/virtio-scsi.c | 21 ++++++++++++++++----- 1 file changed, 16 insertions(+), 5 deletions(-) diff --git a/hw/scsi/virtio-scsi.c b/hw/scsi/virtio-scsi.c index 10eee3a4cff8..8814b246048f 100644 --- a/hw/scsi/virtio-scsi.c +++ b/hw/scsi/virtio-scsi.c @@ -272,7 +272,12 @@ static void *virtio_scsi_load_request(QEMUFile *f, SCS= IRequest *sreq, uint32_t n; =20 qemu_get_be32s(f, &n); - assert(n < vs->conf.num_queues); + if (n >=3D vs->conf.num_queues) { + error_setg(errp, "Invalid queues number %u > %u", n, + vs->conf.num_queues); + return NULL; + } + req =3D qemu_get_virtqueue_element(vdev, f, sizeof(VirtIOSCSIReq) + vs->cdb_size); if (!req) { @@ -283,14 +288,20 @@ static void *virtio_scsi_load_request(QEMUFile *f, SC= SIRequest *sreq, =20 if (virtio_scsi_parse_req(req, sizeof(VirtIOSCSICmdReq) + vs->cdb_size, sizeof(VirtIOSCSICmdResp) + vs->sense_size) = < 0) { - error_report("invalid SCSI request migration data"); - exit(1); + error_setg(errp, "invalid SCSI request migration data"); + virtio_scsi_free_req(req); + return NULL; } =20 scsi_req_ref(sreq); req->sreq =3D sreq; - if (req->sreq->cmd.mode !=3D SCSI_XFER_NONE) { - assert(req->sreq->cmd.mode =3D=3D req->mode); + if (req->sreq->cmd.mode !=3D SCSI_XFER_NONE && + req->sreq->cmd.mode !=3D req->mode) { + error_setg(errp, "Invalid SCSI request mode %u", + req->sreq->cmd.mode); + scsi_req_unref(sreq); + virtio_scsi_free_req(req); + return NULL; } return req; } --=20 2.54.0 From nobody Mon Sep 28 02:06:11 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1785367224; cv=none; d=zohomail.com; s=zohoarc; b=l4QcyEmRZlFNjhk64GjeNPgUp57wiNqJCOb/2pY2fX0sOxBHwZtiXIJkrdEdw9cAP7zt744ANXrwJi2u9toJ7oZunTbC+4FhUVNcww2gSMdGVD6+0PmDiHExuH7Ky3Fv1s/USRSXMWREbpve1QMpEvxHDrkiVK+uoS8pg0Lv+U0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1785367224; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=cFLIOP7KXUhsLxNU8aKzx2Ksu61X7QeSpeVNl9P28zE=; b=mlAr3vACo2l1J5CPmD0wbsdSHK1oaxy6VKm4LC2kDIEP6HBD6JBEGVy4QzBH+DqON5l6GtytY93NjVUFmLI8DLpbo8aKaNZDWGtzt4CibYHzGC2eoqPvdUqojkWTb7kvEgwDRsJYSgiB1T8Guwh2649JCuyWZED3Sg2wO6JyEpA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1785367224130837.5201928494957; Wed, 29 Jul 2026 16:20:24 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wpDYv-0003YZ-VZ; Wed, 29 Jul 2026 19:19:46 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpDYt-0003SC-Fl for qemu-devel@nongnu.org; Wed, 29 Jul 2026 19:19:43 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wpDYq-0008HA-QP for qemu-devel@nongnu.org; Wed, 29 Jul 2026 19:19:43 -0400 Received: from mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (ec2-54-186-198-63.us-west-2.compute.amazonaws.com [54.186.198.63]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-672-BginPbpdPgeQWO12pPCFoA-1; Wed, 29 Jul 2026 19:19:36 -0400 Received: from mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.4]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 47CA2195608F; Wed, 29 Jul 2026 23:19:35 +0000 (UTC) Received: from lenovo-t14s.redhat.corp (headnet04.pony-001.prod.iad2.dc.redhat.com [10.2.32.116]) by mx-prod-int-01.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 55CEC300019F; Wed, 29 Jul 2026 23:19:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1785367180; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=cFLIOP7KXUhsLxNU8aKzx2Ksu61X7QeSpeVNl9P28zE=; b=dH9RKMg73CwtW6m/kEuiV71Tb7sjFK3bXp1IGW8rdhSP4j/r2d0KrW+YPtK0Gh2uxDAMrl BCkMDxUnCyzrhGROFGi/tb6aptGRQl7nPMJCW4FhEj5LKAZZdEGkohCzcgJhvB8NrETWv8 OOil7aroBacBCu+kQTGIgeeXv4FeynY= X-MC-Unique: BginPbpdPgeQWO12pPCFoA-1 X-Mimecast-MFC-AGG-ID: BginPbpdPgeQWO12pPCFoA_1785367175 From: Laurent Vivier To: qemu-devel@nongnu.org Cc: Amit Shah , qemu-ppc@nongnu.org, Harsh Prateek Bora , Hanna Reitz , Nicholas Piggin , "Michael S. Tsirkin" , Kevin Wolf , Paolo Bonzini , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Fam Zheng , qemu-block@nongnu.org, Stefan Hajnoczi , Laurent Vivier Subject: [PATCH v3 7/7] hw/scsi/spapr_vscsi: do not crash QEMU on migration errors Date: Thu, 30 Jul 2026 01:19:04 +0200 Message-ID: <20260729231904.775331-8-lvivier@redhat.com> In-Reply-To: <20260729231904.775331-1-lvivier@redhat.com> References: <20260729231904.775331-1-lvivier@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 3.4.1 on 10.30.177.4 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=lvivier@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -2 X-Spam_score: -0.3 X-Spam_bar: / X-Spam_report: (-0.3 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-1.58, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_SBL_CSS=3.335, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1785367225096158500 Content-Type: text/plain; charset="utf-8" Currently vscsi asserts on invalid SCSI requests. Fail migration gracefully instead. Signed-off-by: Laurent Vivier Reviewed-by: Michael S. Tsirkin Reviewed-by: Stefan Hajnoczi --- Notes: v2: New patch to manage vscsi hw/scsi/spapr_vscsi.c | 18 +++++++++++++++--- 1 file changed, 15 insertions(+), 3 deletions(-) diff --git a/hw/scsi/spapr_vscsi.c b/hw/scsi/spapr_vscsi.c index 7768ec0bdd49..b6a0411e9c44 100644 --- a/hw/scsi/spapr_vscsi.c +++ b/hw/scsi/spapr_vscsi.c @@ -650,9 +650,17 @@ static void *vscsi_load_request(QEMUFile *f, SCSIReque= st *sreq, Error **errp) int rc; Error *local_err =3D NULL; =20 - assert(sreq->tag < VSCSI_REQ_LIMIT); + if (sreq->tag >=3D VSCSI_REQ_LIMIT) { + error_setg(errp, "VSCSI: request tag#%u out of range (max %d)", + sreq->tag, VSCSI_REQ_LIMIT); + return NULL; + } + req =3D &s->reqs[sreq->tag]; - assert(!req->active); + if (req->active) { + error_setg(errp, "VSCSI: request tag#%u already active", sreq->tag= ); + return NULL; + } =20 memset(req, 0, sizeof(*req)); rc =3D vmstate_load_state(f, &vmstate_spapr_vscsi_req, req, 1, &local_= err); @@ -662,7 +670,11 @@ static void *vscsi_load_request(QEMUFile *f, SCSIReque= st *sreq, Error **errp) sreq->tag); return NULL; } - assert(req->active); + if (!req->active) { + error_setg(errp, "VSCSI: request tag#%u not active after load", + sreq->tag); + return NULL; + } =20 req->sreq =3D scsi_req_ref(sreq); =20 --=20 2.54.0