From nobody Wed Aug 26 07:24:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1786547778; cv=none; d=zohomail.com; s=zohoarc; b=mFUmdICEnXYnoXXwj08zwQQnnUXG7aaepoMBmtkGJ8bHVg3QhMYRX55Hqc9EbJKhNxNN2pcE23/1PvFTibRNYreLvz06iN+j6hLgkR+iE2JqtN5Sq0+FZ/kJJ08jq/+RJIW6Z13PDAvORCdvoqXkXZjEYj7oA+WkHnqTcpV6Kd4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786547778; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=TX0U+ugy7x+wm20G4gdM+YFRzx0HE5ijHl7s3lRaCoQ=; b=KDwdI4bmUJviDdoqt7zx5z07lDrQfiv3pO+0c8gQlJXVHfvxc3+QCwdtnPCzzYv0sTvl+NIrw/cJRnM64tNrqVg5T2w/M6YoHhCyXcCvd6LSPTFa4qIL+VDCySQ/qMMNy7nCNv9vrWEJyyEErMXsFihGfPCkF06my0OsB41v/dc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786547778392913.8792847019483; Wed, 12 Aug 2026 08:16:18 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wuAfz-0006G7-Tf; Wed, 12 Aug 2026 11:15:31 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAfm-0005vd-Fg for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:15:21 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAfk-00072Q-Ol for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:15:18 -0400 Received: from mail-qt1-f199.google.com (mail-qt1-f199.google.com [209.85.160.199]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-247-GikNWgtvPeiV1LfX4Fvc0w-1; Wed, 12 Aug 2026 11:15:14 -0400 Received: by mail-qt1-f199.google.com with SMTP id d75a77b69052e-52b4f6ac06aso18863601cf.1 for ; Wed, 12 Aug 2026 08:15:14 -0700 (PDT) Received: from x1.com ([174.91.117.74]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-52d61d948d6sm19552841cf.15.2026.08.12.08.15.04 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 08:15:04 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786547715; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=TX0U+ugy7x+wm20G4gdM+YFRzx0HE5ijHl7s3lRaCoQ=; b=i2BOSmqV/JSO2W6/PFoS3zkZLoB6abI4ZrTaJUkWUiu1CfiOCknFDndhcMOFNJQ7tKS60+ t17Zf30UwBzOIQtqLJT5hd83j2g0spElKgObs7wto86rGPASZ0mHLsiumPdpmxbIRoVepk k2PrmPf1HGrxqQ/nVLUskl9HfRyNGCI= X-MC-Unique: GikNWgtvPeiV1LfX4Fvc0w-1 X-Mimecast-MFC-AGG-ID: GikNWgtvPeiV1LfX4Fvc0w_1786547714 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1786547714; x=1787152514; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=TX0U+ugy7x+wm20G4gdM+YFRzx0HE5ijHl7s3lRaCoQ=; b=DZIOBqTORtTism9cRq8A3nAoXiK1s9L3U3cVeBwaGW082LjRECZ2aGKiOaR2oNVZX2 CpqVhx6PKLL2Wr2o0pyu8o8rxNjuxYBSo3SOuVHfmihtSd4xrbs+qaZD3P2tcVw8Gt6y VM4k6ARvHkopYXD1KuY/Wrb/iaZF9WWrcBOaj7lNP1GqczTX0l2qdvgHT4cdnkFqxDbI LAyulOTpzIF2uAHPJRShHVvw0IWr2YCW4W8KTNn/f2EoGl0yuv+3yl4aWhuKpVCnN0mf 2UeHg8lMzu/qvhlSXL5Brsb++Upf6tcLtjD5iHFpRer9/+nEqp5P9URtDpCF28AwDrXk y7Sg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786547714; x=1787152514; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=TX0U+ugy7x+wm20G4gdM+YFRzx0HE5ijHl7s3lRaCoQ=; b=ph2XOnwM7Btdu3u9QOqa/novLxtNCwjqTrVE2/COZljZbVD6x4qa3kd6bI45PRTKy/ JwfECiVneQ+DteP1sNdXW34vECZmeecYaNecihV1LE2bXZp5rQ4fuYcXmx+vaLNuBCg8 DgXDSDikQkbZSjGm1DNFAQXPjZx8VU4o2CKq6bcV1aPaSRbodpUcS/EsArTJwmR+q8jn LqqYHL8VpJvJGUaxFC2KhABYYgZ44vuKAlvsAhgPaEuCipyNVN78917Temrgk6NbCIhi xmh9hG5Xgh+/d7zrfgT+djNklDhOfCDyXiVQNIsxCssOru8MEJv+DVaNvkhMtUmLSlSc WJ8Q== X-Gm-Message-State: AOJu0Ywr0J+vbBka4Mt6v0rwoWQyFNDA9FVQl5JZ9T5LSQelh/6gMh8b JzVL60zq5oTkk3nD+l7gIzZ29eVt0XqLsJ/4jYQMNWzP8Wr5tWerV31EaQAfwg64AVOrLCaUux5 dtKAwF0m/hStdm+VevAIJDfmeKGaH+t29m9fluiiQnbNcYOHby0eyiJExiKl/VlCf22FSYfHK6/ gjCcIueJuYUh37xvlMhM+pTssTJhqc0SUJrxwvDw== X-Gm-Gg: AR+sD13i8rdQ1kIPtCjUBmHGyo4AUFs4pqI2yV/3AFLDiVfQBClpXFdevtyLsbk8063 r3gImhV0EcuShx97q0WdWHA67XPz1OP+AOfa56ZG2cQhj0vFXjMchHcIWKHD0DKUsSB0p6uyPck sJ5fLxhyRs3rz6ZBcicSSxoToyEbssTIeM4z3hX0dIaLvUGXDY7qy6JWTSGeHQRxmVFtnU/UWNV x6RmVH7VTcJ0nHcqK+NacR0WPLlDKayS/eACQAZpl77oWWdpPkxpWP6Bp83E+ezD4ShVyhbxkRS DmY7rgISYS+DEosrdZeeVk9vMgt/LZGUTqDsJYZZGl4MSCCLETguBO02p+8wTk4Yzg== X-Received: by 2002:a05:622a:38f:b0:527:7d0f:709c with SMTP id d75a77b69052e-52d648836b3mr49885961cf.42.1786547713675; Wed, 12 Aug 2026 08:15:13 -0700 (PDT) X-Received: by 2002:a05:622a:38f:b0:527:7d0f:709c with SMTP id d75a77b69052e-52d648836b3mr49884621cf.42.1786547712951; Wed, 12 Aug 2026 08:15:12 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: Peter Xu , Fabiano Rosas , Paolo Bonzini , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PULL 01/10] docs: Add security considerations for migration Date: Wed, 12 Aug 2026 11:14:34 -0400 Message-ID: <20260812151444.2611689-2-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260812151444.2611689-1-peterx@redhat.com> References: <20260812151444.2611689-1-peterx@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -21 X-Spam_score: -2.2 X-Spam_bar: -- X-Spam_report: (-2.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.104, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1786547779388158500 From: Fabiano Rosas Add the security considerations that are unique to migration and that do not already fall into one of the other categories. Some aspects are better framed as security architecture considerations, so extend that section to mention TLS and clarify that disk images and guest network also need to be isolated from other processes, not just other guests. Reviewed-by: Peter Xu Reviewed-by: Daniel P. Berrang=C3=A9 Signed-off-by: Fabiano Rosas Link: https://lore.kernel.org/r/20260721131457.3062767-1-farosas@suse.de Signed-off-by: Peter Xu --- docs/system/security.rst | 22 ++++++++++++++++++---- 1 file changed, 18 insertions(+), 4 deletions(-) diff --git a/docs/system/security.rst b/docs/system/security.rst index 52bbf0cc7a..af626a4230 100644 --- a/docs/system/security.rst +++ b/docs/system/security.rst @@ -133,6 +133,16 @@ an issue as a normal bug. that affect the level 0 QEMU process. While these bugs should be fixed, they will not be triaged as security flaws at this time. =20 +* **migration/snapshots**. Migration failures and snapshot load + failures are considered part of normal operation as long as the + source virtual machine and savevm file, respectively, are still + functional. Aborting the QEMU process at the migration/snapshot + destination is similarly not considered a security issue. The + migration stream is assumed to be secure as long as the design + principles described in the Architecture section are held, in + which case plain manipulation of the stream is not considered as + an attack vector. + * **low severity impact**. As a catch all rule, issues which are judged to have a "low" severity impact on the system will usually not justify handling as security bugs, nor assignment @@ -159,10 +169,11 @@ could allow malicious guests to gain code execution i= n QEMU. At this point the guest has escaped the virtual machine and is able to act in the context of= the QEMU process on the host. =20 -Guests often interact with other guests and share resources with them. A -malicious guest must not gain control of other guests or access their data. -Disk image files and network traffic must be protected from other guests u= nless -explicitly shared between them by the user. +Guests often interact with other guests and share resources with them. +A malicious guest must not gain control of other guests or access +their data. Disk image files and network traffic must be protected +from other guests, users and processes unless explicitly shared with +them by the user. =20 Principle of Least Privilege '''''''''''''''''''''''''''' @@ -223,6 +234,9 @@ Some Linux distros already ship with UNIX groups for th= ese devices by default. system calls that are not needed by QEMU, thereby reducing the host kern= el attack surface. =20 +- Transport Layer Security (TLS) protocol can be used to ensure authentici= ty and + encryption of the live migration connection where the network is untrust= ed. + Sensitive configurations ------------------------ =20 --=20 2.54.0 From nobody Wed Aug 26 07:24:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1786547744; cv=none; d=zohomail.com; s=zohoarc; b=Z+v57sorOMf2NsPBHhQvy+xPTAPsPCbMq47nBE1+dh9M2aRY9tFqEICiqismFsuIxk12O40r2u2CZ9UPXSl9jgKwJ0h2NriKhoY93AQvPzBfEm02AcpU+AsVwbhgk5H8KzYrIkYfMcJi84EzS+rfxdB0apRapXS5gfFkbyxM4Nk= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786547744; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=C3umiU2VQlfFldgzpAdABpy12j6rspPaYQokfsxVpno=; b=P6oe6mztbPNYw4T8D43HOEQN5R5oU5Wfi6c7k1+FK2g8lF9I4EEm14coZ2vjWcWn6/sCZ+B+38mO4xwgdVeESym+mYpGDt5gfFKmTRrQKbj5P0GMWIe4r8LWaekKhy1FTdZZuRlYQN9e5iLDSmftZuLivfDc5qckcq/sTtha8ik= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178654774484719.42418729510905; Wed, 12 Aug 2026 08:15:44 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wuAg1-0006Ql-Ca; Wed, 12 Aug 2026 11:15:33 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAft-00066R-Lp for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:15:29 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAfq-00073u-EC for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:15:24 -0400 Received: from mail-qt1-f200.google.com (mail-qt1-f200.google.com [209.85.160.200]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-613-S4pp5Kv6MoaBdm8sLdGSqg-1; Wed, 12 Aug 2026 11:15:19 -0400 Received: by mail-qt1-f200.google.com with SMTP id d75a77b69052e-51c21c01cf3so18790701cf.2 for ; Wed, 12 Aug 2026 08:15:19 -0700 (PDT) Received: from x1.com ([174.91.117.74]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-52d61d948d6sm19552841cf.15.2026.08.12.08.15.13 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 08:15:13 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786547721; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=C3umiU2VQlfFldgzpAdABpy12j6rspPaYQokfsxVpno=; b=WeIQSvEVVM2XHeK4dCbYtH5wCRdxcsBgGIWquKQgg81Xd34/xMVqI8/KYauNt3GouyKvbH JV4iH3PEfpUITY4cbPTB9Zz/f/8hMXXeZOH9F8uqsRwG/abGCKXQJKEcpHJfgvqF594xCU NPAFkb74Bryc4tBz2cgOHwTLxrmFRgY= X-MC-Unique: S4pp5Kv6MoaBdm8sLdGSqg-1 X-Mimecast-MFC-AGG-ID: S4pp5Kv6MoaBdm8sLdGSqg_1786547719 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1786547719; x=1787152519; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=C3umiU2VQlfFldgzpAdABpy12j6rspPaYQokfsxVpno=; b=asVJyzIPKPTwpRl6UdTyaYpmYOKQROVPjfwTkYz/G1vMx8Q3/texdakQhQyQgJ4zZD 9bCwReAlDEZZUrs3zZwudtHV/h8ZKVHCWkkX9vHbdPxVDZKgPnRfJJkCGbut74CrPjz6 o1XOaQ4u21uEsJtoQpjsbLZHbptYhK85CmPpO0OGjxP6lk36A1JAXo0Mg6xBfC0XMWyr BucbMMUVEJOgePmquJ65LT7WGZrBt7BNMlBa/oJaOoDwwSp8NadkHRrtVnO7/exLQAYD gmdOPuyXpdiq0UuYH0XDpCyb/bH8FYe0KGBNMJH48e3pJqEXEYGGakss43+nDrZaWzr5 wOsQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786547719; x=1787152519; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=C3umiU2VQlfFldgzpAdABpy12j6rspPaYQokfsxVpno=; b=HUZeK9k39Y4dmrohwNyltb+ltyuuBP6WZTrrbMCRl5Cxl6k95ZInYy0xdS10YAsMh9 gaGl4fO6zt0DmDukkbGlcC8BAaM8SFtQrewld9rRNgzEWZwvB9h0wd6hD8w+iPBZ4i+4 ASmxwmkw5bLtRD2dJkY0yIj2fknKDreyHzq9auAflIZGnGYwP3uBy+tYs+gBAWY9wesl 2WlIaBTGYJbE9nOa+3FmnmGofA22L1iGQyDk2aSZfY9T8D2IOpgpll09Wj4+a/KFzKXN W8+9o6amWVXRbOZ876cKYmzI9BLzc8BB+ophu7OAYRhBk+Z2auR+jr2chMgmt/wwErhd 3C6g== X-Gm-Message-State: AOJu0YxzuP3+a+m7dkj1g5ONjdzyIyUbp960KIQKqCvY2xu/9Yl7VKMd MinCzj1Fx4mt9OoTE2bE3nqODPov7RuHt56I0GdiKo4XYAl+CPlFEsZo4olsIhqL63Z/+8IxsAI 8aVbgtbc9yi355hcLD8gBjLFS8HBxeoyWMHa6n2TXER72BkdTdJeI5RxfjWDqJc/7wFWudyQRwz tgO/2UNNBIdu9kTVogEw3NjKyoJLoyyS41ycFSVA== X-Gm-Gg: AR+sD11e7gOLxUhEXzwppRG4XyZkp5TNMw6vXYWGe8Xc8MP56qPz0IOaqZEFqY87/Fu InxOmAwfGu4pyoFNWgx27EUM/Ele8WTrqyprj1jkgQHC3NKntpH8m/9+LN+3iJ4oeNr8MH8P0ZN 68S9OeE8yva89f1KQcDS7wZfILmC89OT6fsmVe4M5Cf6VHkeYX6Dz0VgtyJqrdSCoIIPDsUK1c0 JJuJQ4W4I3Zwr0nExiwnlL1hdb9vhWKAr0CnIbwiZip2E/2XyVl4qCANbAZinMfpVAVFxf0LS89 pJOcDXQHTIxmsMtADMbEAwtw9UiO3MnpzTHkkmGlTuyKpU1m1V6pjD4YArwGD1rGrQ== X-Received: by 2002:a05:622a:148f:b0:51a:8b64:69e0 with SMTP id d75a77b69052e-52d646fd1d5mr46855401cf.11.1786547718644; Wed, 12 Aug 2026 08:15:18 -0700 (PDT) X-Received: by 2002:a05:622a:148f:b0:51a:8b64:69e0 with SMTP id d75a77b69052e-52d646fd1d5mr46854291cf.11.1786547717949; Wed, 12 Aug 2026 08:15:17 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: Peter Xu , Fabiano Rosas , Paolo Bonzini , Dongli Zhang , "Dr. David Alan Gilbert" , "Maciej S. Szmigiero" Subject: [PULL 02/10] migration/cpr: Add HMP support for cpr-transfer Date: Wed, 12 Aug 2026 11:14:35 -0400 Message-ID: <20260812151444.2611689-3-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260812151444.2611689-1-peterx@redhat.com> References: <20260812151444.2611689-1-peterx@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -21 X-Spam_score: -2.2 X-Spam_bar: -- X-Spam_report: (-2.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.104, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1786547747572158500 Content-Type: text/plain; charset="utf-8" From: Dongli Zhang Currently the cpr-transfer source QEMU instance cannot be driven entirely via HMP. The source must use QMP in order to specify both the main migration channel and the CPR channel. Extend the HMP migrate command with an optional CPR channel URI. When the migration mode is cpr-transfer, HMP uses this URI to build a CPR MigrationChannel in addition to the main migration channel. The new option is rejected unless the migration mode is cpr-transfer, so existing HMP migrate usage is unchanged. For example, source QEMU HMP commands can be something like below. The "-c unix:/tmp/cpr.sock" is for CPR URI. (qemu) migrate_set_parameter mode cpr-transfer (qemu) migrate -c unix:/tmp/cpr.sock tcp:0:50002 Signed-off-by: Dongli Zhang Reviewed-by: Dr. David Alan Gilbert Acked-by: Maciej S. Szmigiero Link: https://lore.kernel.org/r/20260728085903.173265-1-dongli.zhang@oracle= .com Signed-off-by: Peter Xu --- migration/migration-hmp-cmds.c | 18 ++++++++++++++++++ hmp-commands.hx | 12 ++++++++---- 2 files changed, 26 insertions(+), 4 deletions(-) diff --git a/migration/migration-hmp-cmds.c b/migration/migration-hmp-cmds.c index b04fc4489f..b5eb27467c 100644 --- a/migration/migration-hmp-cmds.c +++ b/migration/migration-hmp-cmds.c @@ -837,9 +837,11 @@ void hmp_migrate(Monitor *mon, const QDict *qdict) bool detach =3D qdict_get_try_bool(qdict, "detach", false); bool resume =3D qdict_get_try_bool(qdict, "resume", false); const char *uri =3D qdict_get_str(qdict, "uri"); + const char *uri_cpr =3D qdict_get_try_str(qdict, "uri-cpr"); Error *err =3D NULL; g_autoptr(MigrationChannelList) caps =3D NULL; g_autoptr(MigrationChannel) channel =3D NULL; + g_autoptr(MigrationChannel) channel_cpr =3D NULL; =20 if (!migrate_uri_parse(uri, &channel, &err)) { hmp_handle_error(mon, err); @@ -847,6 +849,22 @@ void hmp_migrate(Monitor *mon, const QDict *qdict) } QAPI_LIST_PREPEND(caps, g_steal_pointer(&channel)); =20 + if (uri_cpr) { + if (migrate_mode() !=3D MIG_MODE_CPR_TRANSFER) { + error_setg(&err, "-c can only be used in cpr-transfer mode"); + hmp_handle_error(mon, err); + return; + } + + if (!migrate_uri_parse(uri_cpr, &channel_cpr, &err)) { + hmp_handle_error(mon, err); + return; + } + + channel_cpr->channel_type =3D MIGRATION_CHANNEL_TYPE_CPR; + QAPI_LIST_PREPEND(caps, g_steal_pointer(&channel_cpr)); + } + qmp_migrate(NULL, true, caps, true, resume, &err); if (hmp_handle_error(mon, err)) { return; diff --git a/hmp-commands.hx b/hmp-commands.hx index 7ae2468a3d..7f43cf537f 100644 --- a/hmp-commands.hx +++ b/hmp-commands.hx @@ -928,16 +928,17 @@ ERST =20 { .name =3D "migrate", - .args_type =3D "detach:-d,resume:-r,uri:s", - .params =3D "[-d] [-r] uri", + .args_type =3D "detach:-d,resume:-r,uri-cpr:-cs,uri:s", + .params =3D "[-d] [-r] [-c uri-cpr] uri", .help =3D "migrate to URI (using -d to not wait for completi= on)" - "\n\t\t\t -r to resume a paused postcopy migration", + "\n\t\t\t -r to resume a paused postcopy migration" + "\n\t\t\t -c to specify a CPR URI for cpr-transfer mode", .cmd =3D hmp_migrate, }, =20 =20 SRST -``migrate [-d] [-r]`` *uri* +``migrate [-d] [-r] [-c uri-cpr]`` *uri* Migrate the VM to *uri*. =20 ``-d`` @@ -945,6 +946,9 @@ SRST query an ongoing migration process, use "info migrate". ``-r`` Resume a paused postcopy migration. + ``-c`` *uri-cpr* + Specify the CPR URI for cpr-transfer mode. It must be a UNIX domain + socket. ERST =20 { --=20 2.54.0 From nobody Wed Aug 26 07:24:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1786547819; cv=none; d=zohomail.com; s=zohoarc; b=bEcQfirwgaBqDXmEw4CTu9Z3kSuoUItRCIu8qo6JI8BD74WMrEST+PtUGeEFHioLTGW0z7lNUOn/9dPYCjcn8MOOMe8q7CKKOyfBOA5eIW8MC6OB1HYzXYeGuqhmAMGt8IFf6i2C9dfnpEcjBGx1ELvaWvlPSZVvETZUEhyHxH4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786547819; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=JcxukroejjvEu8ghEHMU38aY+6/s5Jxqaaa6rod+xLU=; b=SkCq6TLTH9iEV7m1qUTeTHVaiCOCEaYf53miMzpL0YdVuxGewBGWv9G+Phti6mKPCglEaj1d/ONKel1Idwfgpyij5J2oPRhPNi3vrvMhVa3ZHj+12HdKJcF5g+lYFQYkKpn6VGijM2MbstEB8Krc9OSfhegZMlMw35gQNL4ziH0= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786547819027788.230485959685; Wed, 12 Aug 2026 08:16:59 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wuAgj-0008Mw-SI; Wed, 12 Aug 2026 11:16:18 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAgG-00083z-Tv for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:15:55 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAgF-0007Bi-48 for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:15:48 -0400 Received: from mail-qt1-f197.google.com (mail-qt1-f197.google.com [209.85.160.197]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-22-vtVGVIIuPOa1Ya0FsfMbDQ-1; Wed, 12 Aug 2026 11:15:26 -0400 Received: by mail-qt1-f197.google.com with SMTP id d75a77b69052e-51bf321d786so17315071cf.1 for ; Wed, 12 Aug 2026 08:15:25 -0700 (PDT) Received: from x1.com ([174.91.117.74]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-52d61d948d6sm19552841cf.15.2026.08.12.08.15.18 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 08:15:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786547746; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=JcxukroejjvEu8ghEHMU38aY+6/s5Jxqaaa6rod+xLU=; b=SJQfw6vq/yRIPqjXzs51Z32Dr6+sjq7HK+n3mIVwcsDjlBy1LZYKc3k1lzrh9os7LK1ABf 5TVqHHmwuUEKNo5Nt2BouCV3Tf2r+4ntEJ3MlPuBjKnJiR0ZTfgkhK762NBIfMC2pIoKLY VOycTRalHN/4PTXPUoJd5N5Wx2qo7Pw= X-MC-Unique: vtVGVIIuPOa1Ya0FsfMbDQ-1 X-Mimecast-MFC-AGG-ID: vtVGVIIuPOa1Ya0FsfMbDQ_1786547725 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1786547725; x=1787152525; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=JcxukroejjvEu8ghEHMU38aY+6/s5Jxqaaa6rod+xLU=; b=U6/hwy9eoUz++wqGpyPEMbIgNaeV0NYaP1Du9aHK9bXPXPKmT3wJicbrLhSdJDS7C8 V0j4OiTX6r2/FnRqEiICSF3q6OKcTJkKHdobNrrZjvZ0Od9lwBxSBcs2B0uzPN4NvqJn MmCtghRJwd8b7ObgGOJsUzGxqsgqobPNg+H0Km8PtLPLRYyePJZMYEFHdtXwzfmb0VrY z6yQGlzNSK6XRi/toAJfamshbbAn4/LJ2nbMezsjZN69Ckq67AtDP0OP2la9QC14mjQY aIgUe6SF9QCaqryRx5pFNG5x2cbcKwOZLVYiPfuc9KISmpct3yiTIHfC7+WSdo1l9PIu iSEw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786547725; x=1787152525; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=JcxukroejjvEu8ghEHMU38aY+6/s5Jxqaaa6rod+xLU=; b=US/6wgHt4QMpJwL/ROlpILdIlLioVFeq/0TN+YFPSLwb4Xib7KdpJf5EuygZ6k9p3k b1+cCwTHwOdUppSSdQXfF11hSXp1CpQhNSZtV9dQcBaOZZ//RoLH9ehTneeadRwZ6mhT TDRk8Tz53dzPctj2KmiXG7fbHHty1gk01iw8Rn25pih84RyBjkDEGA1bI2nqZYTo1DI1 jreHBk0cJjSJLJQSm7DAhn8slQMr46BFHwiOXaBoxkm+ztIiIZSHXU8vWpb6h+4H+U6g r1UEIoLNHwdn2rJWk91AcjcZXae3/jpx/+ykw2r4P8073bRSU/HZQFF2hoaYNBz6Hc5K c7ZQ== X-Gm-Message-State: AOJu0YynoGknEW6rZRyBYlqHsGV1BNl58O9C6Y9+0gEuHSFOl70DDFHb 5K+rptOPj7Lj/tzfV+f9g2uTiipwL/BhvI/KilpXdEeJOuym997mGCBID7e/OPJEpjSncZg9Mu0 RcHBNAVE2jddjDLs3qmTm1fMQOVUx3onZcP2fB2i5yCAaRg2i4p68g3laPZp7lkUdph7qC8Fxlf pDBHz9xtePZrAY368N3kntDEEAX0h78i95Cu0IFQ== X-Gm-Gg: AR+sD11xZSDdC3OEdiICRNgKiTP+YJaujMgGx6IJLRsZ5+dXhZlB+h2r+9g5zCRDzaK JhM1h1Cb5ynZzXHZ7BcnxHVEaSiZkiraTK4cmR6QLkcZC2cHAY7Lj9h8RX+KLD/uWwIFYbt+NBh wMdWFEj4QDWFjMUKfnXnNDG9JtF99gDF3ztbzAzsC0gMopwx/U+4WUUKQPMIVKMGAR4sue3A8Sh aJeGBFbN1woQQ6VTCF0tJ+HddryWX0PC648C2jLW0crfjbszRm40Tqc9SDHj2w7PJXE2yYVwbdf IvZX+GXDXwxWHpG/UTGztuItd1qITA62zywELLTHNxVEckQfItl9fjjxrCXC7UDyYg== X-Received: by 2002:a05:622a:4d91:b0:51c:1d18:2fe9 with SMTP id d75a77b69052e-52d6469cf4amr49008631cf.5.1786547725288; Wed, 12 Aug 2026 08:15:25 -0700 (PDT) X-Received: by 2002:a05:622a:4d91:b0:51c:1d18:2fe9 with SMTP id d75a77b69052e-52d6469cf4amr49007491cf.5.1786547724552; Wed, 12 Aug 2026 08:15:24 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: Peter Xu , Fabiano Rosas , Paolo Bonzini , Gavin Shan , Peter Maydell Subject: [PULL 03/10] system/memory: Use memmove() for directly accessible regions Date: Wed, 12 Aug 2026 11:14:36 -0400 Message-ID: <20260812151444.2611689-4-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260812151444.2611689-1-peterx@redhat.com> References: <20260812151444.2611689-1-peterx@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -21 X-Spam_score: -2.2 X-Spam_bar: -- X-Spam_report: (-2.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.104, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1786547819778158500 Content-Type: text/plain; charset="utf-8" From: Gavin Shan Similar to what's done in commit 4a73aee88140 ("softmmu: Use memmove in flatview_write_continue"), there are more sites where the overlapping source and destination buffer are allowed for the directly accessible regions. Use memmove() in those sites, listed as below. hw/remote/vfio-user-obj.c::vfu_object_mr_rw include/system/memory.h::address_space_read system/physmem.c::flatview_read_continue_step Signed-off-by: Gavin Shan Reviewed-by: Peter Maydell Reviewed-by: Peter Xu Link: https://lore.kernel.org/r/20260728031731.286666-2-gshan@redhat.com Signed-off-by: Peter Xu --- include/system/memory.h | 2 +- hw/remote/vfio-user-obj.c | 4 ++-- system/physmem.c | 2 +- 3 files changed, 4 insertions(+), 4 deletions(-) diff --git a/include/system/memory.h b/include/system/memory.h index 2192fc9bdc..336d4e84a6 100644 --- a/include/system/memory.h +++ b/include/system/memory.h @@ -2741,7 +2741,7 @@ MemTxResult address_space_read(const AddressSpace *as= , hwaddr addr, mr =3D flatview_translate(fv, addr, &addr1, &l, false, attrs); if (len =3D=3D l && memory_access_is_direct(mr, false, attrs))= { ptr =3D qemu_map_ram_ptr(mr->ram_block, addr1); - memcpy(buf, ptr, len); + memmove(buf, ptr, len); } else { result =3D flatview_read_continue(fv, addr, attrs, buf, le= n, addr1, l, mr); diff --git a/hw/remote/vfio-user-obj.c b/hw/remote/vfio-user-obj.c index 87fa7b6572..ea50270628 100644 --- a/hw/remote/vfio-user-obj.c +++ b/hw/remote/vfio-user-obj.c @@ -375,9 +375,9 @@ static int vfu_object_mr_rw(MemoryRegion *mr, uint8_t *= buf, hwaddr offset, ram_ptr =3D memory_region_get_ram_ptr(mr); =20 if (is_write) { - memcpy((ram_ptr + offset), buf, size); + memmove((ram_ptr + offset), buf, size); } else { - memcpy(buf, (ram_ptr + offset), size); + memmove(buf, (ram_ptr + offset), size); } =20 return 0; diff --git a/system/physmem.c b/system/physmem.c index c21ea92915..2c42e365cb 100644 --- a/system/physmem.c +++ b/system/physmem.c @@ -3363,7 +3363,7 @@ static MemTxResult flatview_read_continue_step(MemTxA= ttrs attrs, uint8_t *buf, uint8_t *ram_ptr =3D qemu_ram_ptr_length(mr->ram_block, mr_addr, l, false, false); =20 - memcpy(buf, ram_ptr, *l); + memmove(buf, ram_ptr, *l); =20 return MEMTX_OK; } --=20 2.54.0 From nobody Wed Aug 26 07:24:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1786547851; cv=none; d=zohomail.com; s=zohoarc; b=iqRZMlrAzeHRayO2bx6juDIEV7fUUlY3ZghgDGHlrmKNg3HQrwQqOShMQy6aDECVzPRV+nEPYA7b2OyrZgjuHyysNgFxsvAO/9SV5FV1WmWQ/ytycIhvabvjMU3WvmuWDH+baMy/NTI9h5bd0oBnXAjMOPElnNN5iQMtNQiVDlE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786547851; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=O5FFCa47ef/OZEWEx9f76qW3xxrL0nngPfnEebtktI0=; b=iLabalXyO9SwfaxlctdNPAaQa9XLhTHaXDbbau/O6buOVbaBuNrThFFfa/Ora01lwYsNjczCcjcAoJkgZwocniCePfuV/0eZg9NbCQq+mccUECTVwuJDMdcjba5szrugnC5V3q81lbVEsYJU876eC40AcnB1s3ikkKik4c4zcy8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786547851792132.9513073411938; Wed, 12 Aug 2026 08:17:31 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wuAg6-0007BS-PK; Wed, 12 Aug 2026 11:15:38 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAg4-0006sZ-0s for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:15:36 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAg1-000779-4y for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:15:35 -0400 Received: from mail-qt1-f200.google.com (mail-qt1-f200.google.com [209.85.160.200]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-286-lCFtXSIHPEWKnqinpeV2og-1; Wed, 12 Aug 2026 11:15:31 -0400 Received: by mail-qt1-f200.google.com with SMTP id d75a77b69052e-526da7e3c9dso10743111cf.1 for ; Wed, 12 Aug 2026 08:15:30 -0700 (PDT) Received: from x1.com ([174.91.117.74]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-52d61d948d6sm19552841cf.15.2026.08.12.08.15.24 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 08:15:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786547732; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=O5FFCa47ef/OZEWEx9f76qW3xxrL0nngPfnEebtktI0=; b=RdLGMPYdquzJJnwXwuPYrtTTCVoA+nyaxLwmVyJDs9wNyLxyiFx+xB8gAmb0ynnn4HHp/V GfslkPPbB/22BW2rLmuRBD0x/vtZQISDILvELnlkBH0cSH4xW2fEnYtrkDlGfp+r6N1EV+ NTu1kkIgWqIPs2fmALk/G0JNj9cL4zI= X-MC-Unique: lCFtXSIHPEWKnqinpeV2og-1 X-Mimecast-MFC-AGG-ID: lCFtXSIHPEWKnqinpeV2og_1786547730 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1786547730; x=1787152530; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=O5FFCa47ef/OZEWEx9f76qW3xxrL0nngPfnEebtktI0=; b=egh1tld8mEfqvNrcFj3epTF7Ao9jZKDWTP28zkyw0MFXccoTt0FpZHXiJ287JQgNMD nuya9/4HI5hokW27fpIh97CRtpLIPET05+DX7Q9S6yZee6n5N/e00SAMw8Kzc/gUO+Ds HrzwWDZUb571C83WCYl9Oup9+7HbWAbt2YI1nkgwAfNX7f1Ia60P6sDb1Z4yHbB20a2s t8RM5I1yokXDQrEWCun4tLp8QY0MXGyijBylMgDbAs+AWmPM0Hh2L+kN4VeEr17jFWnp oOBnlKHXQXulerHUe/fbNJ0o7WADi65bC/GPCbolRxkt3uoeiFLfWt+2UEkGuB/SgEOy gcVA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786547730; x=1787152530; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=O5FFCa47ef/OZEWEx9f76qW3xxrL0nngPfnEebtktI0=; b=OUP11W588jdBNhB8NsNtPrdNQPAAYBOLfpjNjUL/s8DrQYsfCPHelUgD0hI/Lj1STl iatqZS8r0cO7Q+oi3HO3E3oCBVo3j/u62m7dAZM3EtDtckEgIZTf0vk7c2l1PxRQV0X+ OJNJXHAmmQHUDFZ+ZqqJSheNbg7B5T/haJBkVQyNniQtZFQdOA1huTLuen+qbtxHL0gf 3dN2TsCSxnQ6RNTfwTANwLrUKREtrutaRIfEE4Y12Cuw0K3pK+nukaK9/eBtjTM2Jdww J+0zN1U+8g3B1ruVNkA+W6kqv7aP8YwjrFLdgp9wPU3TyEQka88GgPF4nQ119BO2cfsF iMGA== X-Gm-Message-State: AOJu0YwL+Bgw8LF7wOQ/bqC0eb9XTvgvhpkkeO99ziBpPOYDgI7saP9m l+cw6YMc5T/I3dvz1AW+yypEKEi/wh7dZG+Pkq5JrH7DMCR0wOtFNwoGUC5lA2T+kVimm6qf4OM rafx36Qwxtm8Af0M5lbcf6N5QVjojxDhIGGBy1ni+POylM5LVRacpGD67DrRilA2RrwLUM8G3sX jvWX8AOwVDQ8ziWQlr/kOVSN8tifLQ9JoX8jwNfQ== X-Gm-Gg: AR+sD11ZZvzR0BEfjmPQ99Kheff1FcmqpvV2M/zHfp9pgrC/tMDR4GM4qcTliZ5MFzd lkR/+z4TTamqC1bEGnnaDIQ0rJE+9D/83ib8x90friaS7jFpmIMlzYuQKqZh7j8Rf7rVFALIN48 gLJamwrSZOB5ponJlM853BoND2EofUVYrlniu0/4qwq8ZPA9NOqWQ/eqXU7tpx0rfMrHiccaF1L UG5LdPUlUfHGTeLN6Qk5vI0Lq6p3u5dE/Pu9XSU02S6jAjDOFj6//zR+6y+z4rrml2Kwmajyn64 SEQornthvfmDUwPbEDxug8s6bxk3Y7HrDXiyAZqUf+qUCcRDkkqD25mcBzpgZqKFcQ== X-Received: by 2002:a05:622a:598a:b0:51b:f40b:2fb3 with SMTP id d75a77b69052e-52d646bad9dmr53597611cf.9.1786547730086; Wed, 12 Aug 2026 08:15:30 -0700 (PDT) X-Received: by 2002:a05:622a:598a:b0:51b:f40b:2fb3 with SMTP id d75a77b69052e-52d646bad9dmr53596271cf.9.1786547729286; Wed, 12 Aug 2026 08:15:29 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: Peter Xu , Fabiano Rosas , Paolo Bonzini , Gavin Shan , Julia Graham , Liu Gang , Ding Hui , "Michael S. Tsirkin" , Richard Henderson , Peter Maydell Subject: [PULL 04/10] system/memory: Use qemu_ram_move() for directly accessible regions Date: Wed, 12 Aug 2026 11:14:37 -0400 Message-ID: <20260812151444.2611689-5-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260812151444.2611689-1-peterx@redhat.com> References: <20260812151444.2611689-1-peterx@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -21 X-Spam_score: -2.2 X-Spam_bar: -- X-Spam_report: (-2.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.104, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1786547854366158500 Content-Type: text/plain; charset="utf-8" From: Gavin Shan All ram device regions were turned to be indirectly accessible by commit 4a2e242bbb ("memory: Don't use memcpy for ram_device regions"). This leads to guest hang on attempt to build 'cuda-samples' as reported by Julia. The guest is started by the following command lines, with GH100 GPU card passed from the host. host$ lspci | grep GH100 0009:01:00.0 3D controller: NVIDIA Corporation GH100 [GH200 120GB / 480G= B] (rev a1) host$ /home/sandbox/gavin/qemu.main/build/qemu-system-aarch64 = \ -machine virt,gic-version=3Dhost,ras=3Don,highmem-mmio-size=3D4T = \ -accel kvm -cpu host -smp cpus=3D48 -m size=3D8G = \ -drive file=3D/home/gavin/sandbox/images/disk.qcow2,if=3Dnone,id= =3Dd0 \ -device virtio-blk-pci,id=3Dvb0,bus=3Dpcie.0,drive=3Dd0,num-queues= =3D4 \ -device vfio-pci-nohotplug,host=3D0009:01:00.0,bus=3Dpcie.1.0 : guest$ cd cuda-samples/build guest$ make -j 20 clean guest$ make -j 20 : [ 54%] Linking CUDA executable graphMemoryNodes [ 54%] Built target graphMemoryNodes guest$ qemu-system-aarch64: virtio: bogus descriptor or out of resources [ 555.814025] virtio_blk virtio0: [vda] new size: 268435456 512-byte lo= gical blocks (137 GB/128 GiB) When the GPU's driver (NVidia open driver) is loaded on guest bootup, the memory blocks residing in the PCI BAR#4 of the GH100 GPU card can be presented to the guest through memory hot-add. The page cache can then be allocated from the hot added memory blocks when cuda-samples is being built. Afterwards, the page cache is sent to QEMU's virtio-blk device as part of the DMA request, the bounce buffer has to be used to accomodate the request as the corresponding memory region (MemoryRegion) is an indirectly accessible ram device region in qemu. However, the max bounce bufer size is only 4096 bytes by default and that is exhausted quickly, leading to a reset on the virtio-blk device and frozen guest eventually. QEMU =3D=3D=3D=3D virtio_blk_handle_output virtio_blk_handle_vq virtio_blk_get_request virtqueue_pop virtqueue_split_pop virtqueue_map_desc address_space_map memory_access_is_direct # Return false memory_region_supports_direct_access (qemu) info mtree memory-region: pci_bridge_pci 0000000000000000-ffffffffffffffff (prio 0, container): pci_bridge_pci 0000042000000000-0000043fffffffff (prio 1, i/o): 0009:01:00.0 base BA= R 4 0000042000000000-0000043fffffffff (prio 0, i/o): 0009:01:00.0 BAR 4 0000042000000000-000004379fffffff (prio 0, ramd): 0009:01:00.0 BA= R 4 mmaps[0] This adds qemu_ram_move() where the aligned and small-sized accesses are handled by qatomics, and fall back to memmove() otherwise. The memove() for the directly accessible regions is replaced by qemu_ram_move() so that the issue covered by commit 4a2e242bbb (MMIO access instructions were optimized to SSE instructions) is fixed. This makes 'ram_device_mem_ops' redundant, paving the way to revert that commit to make the ram device region directly accessible again in the next patch. Besides, this also fixes the issue of the unexpected frozen reception on e1000 NIC in the scenario of DPDK due to the wrong Rx queue full indication caused by the following memcpy(), which is turned to 3 consective 'strb' instructions to the same location by glibc-2.24+ for aarch64. With this applied, the syntax of one-byte store is strictly ensured by a one-byte qatomic set. QEMU =3D=3D=3D=3D e1000_receive_iov pci_dma_write pci_dma_rw dma_memory_rw dma_memory_rw_relaxed address_space_rw address_space_write flatview_write flatview_write_continue flatview_write_continue_step memcpy # 3 consective 'strb' instructions Reported-by: Julia Graham Reported-by: Liu Gang Reported-by: Ding Hui Suggested-by: Michael S. Tsirkin Suggested-by: Peter Xu Suggested-by: Richard Henderson Suggested-by: Peter Maydell Signed-off-by: Gavin Shan Reviewed-by: Peter Maydell Link: https://lore.kernel.org/r/20260728031731.286666-3-gshan@redhat.com [peterx: remove src=3D=3Ddst check, fix doc, enhance comments, per PeterM, = add R-b] Signed-off-by: Peter Xu --- include/system/memory.h | 35 +++++++++++++++++++++++++++- hw/remote/vfio-user-obj.c | 4 ++-- system/physmem.c | 48 +++++++++++++++++++++++++++++++++++++-- 3 files changed, 82 insertions(+), 5 deletions(-) diff --git a/include/system/memory.h b/include/system/memory.h index 336d4e84a6..4de5bf2577 100644 --- a/include/system/memory.h +++ b/include/system/memory.h @@ -2668,6 +2668,39 @@ void address_space_register_map_client(AddressSpace = *as, QEMUBH *bh); void address_space_unregister_map_client(AddressSpace *as, QEMUBH *bh); =20 /* Internal functions, part of the implementation of address_space_read. = */ + +/** + * qemu_ram_move: move data from or to ramblock + * + * @dst: destination where the data is moved to + * @src: source where the data is moved from + * @n: length of data to be moved + * + * Move @n bytes from @src to @dst, the memory areas may overlap. This + * provides the same semantics as memmove(), plus an additional stronger + * guarantee: if @n is 1, 2 or 4 or 8 bytes, and @src and @dst are both + * naturally aligned for that access size, then both the load and the store + * will be done as a single atomic access (with the semantics of + * qatomic_read() and qatomic_set()). + * + * This is the underlying function that we use to implement accesses by + * a guest vCPU or a device DMA operation to a ram block. The atomic + * guarantee is needed for two major cases: (A) When the ram block is + * backed by a PCI BAR passed through from a host device (and so it might + * be hardware registers that must be accessed exactly once at the right + * width); (B) When an emulated device updates a data structure shared in + * guest memory with guest software (e.g. a network device's set of tx and + * rx descriptor blocks), if a write to memory is accidentally performed + * multiple times then it can break the guest code when it busy polls the + * guest memory. + * + * We don't attempt to perform the exact access when it would be unaligned + * because this can't be done on all host architectures. Although this is + * strictly speaking not doing what would happen on real hardware, we don't + * think there are going to be situations where that matters in practice. + */ +void qemu_ram_move(void *dst, const void *src, size_t n); + MemTxResult address_space_read_full(const AddressSpace *as, hwaddr addr, MemTxAttrs attrs, void *buf, hwaddr le= n); MemTxResult flatview_read_continue(FlatView *fv, hwaddr addr, @@ -2741,7 +2774,7 @@ MemTxResult address_space_read(const AddressSpace *as= , hwaddr addr, mr =3D flatview_translate(fv, addr, &addr1, &l, false, attrs); if (len =3D=3D l && memory_access_is_direct(mr, false, attrs))= { ptr =3D qemu_map_ram_ptr(mr->ram_block, addr1); - memmove(buf, ptr, len); + qemu_ram_move(buf, ptr, len); } else { result =3D flatview_read_continue(fv, addr, attrs, buf, le= n, addr1, l, mr); diff --git a/hw/remote/vfio-user-obj.c b/hw/remote/vfio-user-obj.c index ea50270628..a0498d218f 100644 --- a/hw/remote/vfio-user-obj.c +++ b/hw/remote/vfio-user-obj.c @@ -375,9 +375,9 @@ static int vfu_object_mr_rw(MemoryRegion *mr, uint8_t *= buf, hwaddr offset, ram_ptr =3D memory_region_get_ram_ptr(mr); =20 if (is_write) { - memmove((ram_ptr + offset), buf, size); + qemu_ram_move((ram_ptr + offset), buf, size); } else { - memmove(buf, (ram_ptr + offset), size); + qemu_ram_move(buf, (ram_ptr + offset), size); } =20 return 0; diff --git a/system/physmem.c b/system/physmem.c index 2c42e365cb..2f37cbeb07 100644 --- a/system/physmem.c +++ b/system/physmem.c @@ -3158,6 +3158,50 @@ void memory_region_flush_rom_device(MemoryRegion *mr= , hwaddr addr, hwaddr size) invalidate_and_set_dirty(mr, addr, size); } =20 +void qemu_ram_move(void *dst, const void *src, size_t n) +{ + uintptr_t test, len; + + if (n =3D=3D 0) { + return; + } + + /* + * Calculate "the lowest set bit" over @src, @dst and @n, result put + * into @len (which guarantees a power-of-two). With that and the + * later check (len!=3Dn), it makes sure that we will only do the atom= ic + * ops when: + * + * (1) @n is a power-of-two + * (2) @src and @dst addresses are both aligned to @n + */ + test =3D (uintptr_t)src | (uintptr_t)dst | n; + len =3D test & -test; + + /* Overlapping buffers, unaligned or oversized access */ + if (n > 8 || len !=3D n) { + memmove(dst, src, n); + return; + } + + switch (len) { + case 1: + qatomic_set((uint8_t *)dst, qatomic_read((uint8_t *)src)); + break; + case 2: + qatomic_set((uint16_t *)dst, qatomic_read((uint16_t *)src)); + break; + case 4: + qatomic_set((uint32_t *)dst, qatomic_read((uint32_t *)src)); + break; + case 8: + qatomic_set((uint64_t *)dst, qatomic_read((uint64_t *)src)); + break; + default: + g_assert_not_reached(); + } +} + int memory_access_size(MemoryRegion *mr, unsigned l, hwaddr addr) { unsigned access_size_max =3D mr->ops->valid.max_access_size; @@ -3270,7 +3314,7 @@ static MemTxResult flatview_write_continue_step(MemTx= Attrs attrs, uint8_t *ram_ptr =3D qemu_ram_ptr_length(mr->ram_block, mr_addr, l, false, true); =20 - memmove(ram_ptr, buf, *l); + qemu_ram_move(ram_ptr, buf, *l); invalidate_and_set_dirty(mr, mr_addr, *l); =20 return MEMTX_OK; @@ -3363,7 +3407,7 @@ static MemTxResult flatview_read_continue_step(MemTxA= ttrs attrs, uint8_t *buf, uint8_t *ram_ptr =3D qemu_ram_ptr_length(mr->ram_block, mr_addr, l, false, false); =20 - memmove(buf, ram_ptr, *l); + qemu_ram_move(buf, ram_ptr, *l); =20 return MEMTX_OK; } --=20 2.54.0 From nobody Wed Aug 26 07:24:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1786547861; cv=none; d=zohomail.com; s=zohoarc; b=Yp598LuPr+AXYKrpU0tZie6urYoxMR1w4V+jEDXRT8Ftg4lhwKzhdeq4CdkDoFp3jr8MXcd11t96EKnQMfTZaJg563ajU9UTE8p12rdmK14gAzj2SRIt5kU1NVr5Cso9HjgBJO9V+yk1iyqwuQEs86g+ykSzlaHxstaSAyLdm30= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786547861; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=VoqA1ZaTEbS0pqgotOLPlk7qgStthSVvyDWDGPx2uz8=; b=FIEHUs00T0LYDHCdNTU6xcMj8XRyZ/aSxAhnJIsJNdBcS92lnecpwkNoN1i9oFcLZdkPbLEy9OgNLkpHnygq5NceHCHyubQKGbcY+v8NfzAZaTJv4s4huawhaycHx2lk8JLePamzWNVoOw2C67jUo3Hy4a7bPlStDe53ne33wPI= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786547861786688.6020348956743; Wed, 12 Aug 2026 08:17:41 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wuAgB-0007Zk-Nz; Wed, 12 Aug 2026 11:15:43 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAg9-0007Vl-CY for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:15:41 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAg7-00079k-Cg for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:15:41 -0400 Received: from mail-qt1-f198.google.com (mail-qt1-f198.google.com [209.85.160.198]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-175-DvAWVUPUNfSFfNnCyE2yQg-1; Wed, 12 Aug 2026 11:15:36 -0400 Received: by mail-qt1-f198.google.com with SMTP id d75a77b69052e-51c12e43b98so13034551cf.1 for ; Wed, 12 Aug 2026 08:15:36 -0700 (PDT) Received: from x1.com ([174.91.117.74]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-52d61d948d6sm19552841cf.15.2026.08.12.08.15.29 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 08:15:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786547738; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=VoqA1ZaTEbS0pqgotOLPlk7qgStthSVvyDWDGPx2uz8=; b=WF4dDNvaqyzNKi9/p/3pg1qmZbJKnwfxECKfsblY/TMVXCqDW5JDaeCB68dwLxRhRB0ZDT JfxndkP96MazW2VDABzmEFBsKDPzkJ55yURLPIHO5fq7fTqFmIQx+d33BjN2lfVR3I/YRF C2oif+fKfrWoz+1tg3vq2B/Lg6xqWjw= X-MC-Unique: DvAWVUPUNfSFfNnCyE2yQg-1 X-Mimecast-MFC-AGG-ID: DvAWVUPUNfSFfNnCyE2yQg_1786547736 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1786547736; x=1787152536; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VoqA1ZaTEbS0pqgotOLPlk7qgStthSVvyDWDGPx2uz8=; b=tD3MNHnKeP5qxrjOhAMuHijUMd82/kCUJpkWgjy7vlcYk0bv03lJKaugL6q9O0D5xo v2OhR1xw43ENuhWdbo+TZwmLvg/WhCiQJuhp9ItZMQn7VPU8s79J/lQFqNackeJ06OvA KquMNz2sglzBlTeX7QaEp7/1bbPXqU6xMJcsrIA/fLUZdE7c5FAsAXcn6Z/JTiPujx31 Pc9DUMfazxN7uM+4JfjWlyCh2zIvgL85pZM/nd37AFNhy5mxeyPcSV9sdTwcfBjzMJNl Z+whWKhjojLhk85LdF/RvGY1VoJqz97p6gnvg1Wwi/FmAm5d5V8SA2MSmLJyMTyY11Qw +bkg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786547736; x=1787152536; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=VoqA1ZaTEbS0pqgotOLPlk7qgStthSVvyDWDGPx2uz8=; b=SgLqXn9h/4PNsKs8OWzQHIit6kE3FfQdlU3JuwMC7yub6RncRYmFiXnUV+HkRLeHOC MSNqdLYSM/sXQlig5+kkkSHiciWEuryBelAYMZsOe5ZC+rX6YPflbOakA5bYh8j4sgY/ 8LyDa2WyWx0FO81qnUJBO9i6uW6UJPfbKuqG3iOFrSneSbsIQ8UekE7MiF7RL5/OlPEv T1V+0oio4+X3+TZuWbF7zOgChHvEexNwsy05SZ3bsHbKWoXBTnk/Omn+vXpKL0OcIhUk c+7ISjigF/AiTjvs87WveX6BXj5mw0qFIoKrOAdcP1l4AJjkk/upFhrI5EtQBLTzzlUy 0hEA== X-Gm-Message-State: AOJu0Yyv8H0xz604lJInPFcmoAIwy/yPSsoNDFbS61E35ZGsc3vKUKFb 7RTQOIY9gFETYsliRPCA4HGxHFErnztN1umD/WZIxxxZHHJfrzI+Lgaax1NJXLe23pYWj9AvWo6 5Tow19ZbxukpNM4yIRP9xA76qsA6iIdMO4ye7EM7oV6B4jKKRoJsDhLtbU+k/vWw9nEhm1rtu6P DFz9PeA4qGQG3FwGd3VH8XcuobilLjOoKMx4ttcg== X-Gm-Gg: AR+sD12iOjiQW0Odd2LKlXiJKv0MqVFSPSDpfl1hi2geBHyoPmQ2TWBqd4ARu+Z4w+r j1lyxLpBXdiJx8GtU1A+os0aLtcZ4B1CR3mkwqZuxmy2xkxu7ycUxKLAMTOremY5WEiK6Sxvm6W 2EdR38S2oiDo4EfKMMnUhO3WV2ODqOEbdD2t5DeHZiyy0mD/6rkrYYwPqEGj9PcU2JHmmJ6RtcW da0+hAXNnDkvWxhtNhK3IU47z5auwIxXre4N5z3X1vtA8xTQor+7kENp1LpyNeqZQU3BJk095Hb TzaDZC1FsMI5BnjNc2zO7Kc2jvrXOVSVIVT+cTDU4PyssOi74ebPF/rx5Sq0BUABaw== X-Received: by 2002:ac8:5a84:0:b0:51c:1e69:bcc9 with SMTP id d75a77b69052e-52d6471a403mr52750481cf.12.1786547735606; Wed, 12 Aug 2026 08:15:35 -0700 (PDT) X-Received: by 2002:ac8:5a84:0:b0:51c:1e69:bcc9 with SMTP id d75a77b69052e-52d6471a403mr52749101cf.12.1786547734804; Wed, 12 Aug 2026 08:15:34 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: Peter Xu , Fabiano Rosas , Paolo Bonzini , Gavin Shan , Julia Graham , "Michael S. Tsirkin" , Richard Henderson , Peter Maydell Subject: [PULL 05/10] system/memory: Make ram device region directly accessible Date: Wed, 12 Aug 2026 11:14:38 -0400 Message-ID: <20260812151444.2611689-6-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260812151444.2611689-1-peterx@redhat.com> References: <20260812151444.2611689-1-peterx@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -21 X-Spam_score: -2.2 X-Spam_bar: -- X-Spam_report: (-2.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.104, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1786547862093158500 Content-Type: text/plain; charset="utf-8" From: Gavin Shan This basically reverts 4a2e242bbb30 ("memory: Don't use memcpy for ram_device regions") to make ram device region directly accessible again. With this, the bounce buffer is bypassed in address_space_map() when a ram device region is involved, potentially avoid to overrun the (small) bounce buffer. Reported-by: Julia Graham Suggested-by: Michael S. Tsirkin Suggested-by: Peter Xu Suggested-by: Richard Henderson Suggested-by: Peter Maydell Signed-off-by: Gavin Shan Reviewed-by: Peter Maydell Link: https://lore.kernel.org/r/20260728031731.286666-4-gshan@redhat.com Signed-off-by: Peter Xu --- include/system/memory.h | 11 ++--------- system/memory.c | 41 +---------------------------------------- system/trace-events | 2 -- 3 files changed, 3 insertions(+), 51 deletions(-) diff --git a/include/system/memory.h b/include/system/memory.h index 4de5bf2577..1dc761058f 100644 --- a/include/system/memory.h +++ b/include/system/memory.h @@ -2718,15 +2718,8 @@ static inline bool memory_region_supports_direct_acc= ess(const MemoryRegion *mr) if (memory_region_is_romd(mr)) { return true; } - if (!memory_region_is_ram(mr)) { - return false; - } - /* - * RAM DEVICE regions can be accessed directly using memcpy, but it mi= ght - * be MMIO and access using mempy can be wrong (e.g., using instructio= ns not - * intended for MMIO access). So we treat this as IO. - */ - return !memory_region_is_ram_device(mr); + + return memory_region_is_ram(mr); } =20 static inline bool memory_access_is_direct(const MemoryRegion *mr, diff --git a/system/memory.c b/system/memory.c index 5fc36708ec..da710bbade 100644 --- a/system/memory.c +++ b/system/memory.c @@ -1364,43 +1364,6 @@ const MemoryRegionOps unassigned_mem_ops =3D { .endianness =3D DEVICE_NATIVE_ENDIAN, }; =20 -static uint64_t memory_region_ram_device_read(void *opaque, - hwaddr addr, unsigned size) -{ - MemoryRegion *mr =3D opaque; - uint64_t data =3D ldn_he_p(mr->ram_block->host + addr, size); - - trace_memory_region_ram_device_read(get_cpu_index(), mr, addr, data, s= ize); - - return data; -} - -static void memory_region_ram_device_write(void *opaque, hwaddr addr, - uint64_t data, unsigned size) -{ - MemoryRegion *mr =3D opaque; - - trace_memory_region_ram_device_write(get_cpu_index(), mr, addr, data, = size); - - stn_he_p(mr->ram_block->host + addr, size, data); -} - -static const MemoryRegionOps ram_device_mem_ops =3D { - .read =3D memory_region_ram_device_read, - .write =3D memory_region_ram_device_write, - .endianness =3D HOST_BIG_ENDIAN ? DEVICE_BIG_ENDIAN : DEVICE_LITTLE_EN= DIAN, - .valid =3D { - .min_access_size =3D 1, - .max_access_size =3D 8, - .unaligned =3D true, - }, - .impl =3D { - .min_access_size =3D 1, - .max_access_size =3D 8, - .unaligned =3D true, - }, -}; - bool memory_region_access_valid(MemoryRegion *mr, hwaddr addr, unsigned size, @@ -1692,10 +1655,8 @@ void memory_region_init_ram_device_ptr(MemoryRegion = *mr, Object *owner, const char *name, uint64_t size, void *ptr) { - memory_region_init_io(mr, owner, &ram_device_mem_ops, mr, name, size); - mr->ram =3D true; + memory_region_init_ram_ptr(mr, owner, name, size, ptr); mr->ram_device =3D true; - memory_region_set_ram_ptr(mr, size, ptr); } =20 void memory_region_init_alias(MemoryRegion *mr, Object *owner, diff --git a/system/trace-events b/system/trace-events index 51b4a4679a..d483b31419 100644 --- a/system/trace-events +++ b/system/trace-events @@ -20,8 +20,6 @@ memory_region_ops_read(int cpu_index, void *mr, uint64_t = addr, uint64_t value, u memory_region_ops_write(int cpu_index, void *mr, uint64_t addr, uint64_t v= alue, unsigned size, const char *name) "cpu %d mr %p addr 0x%"PRIx64" value= 0x%"PRIx64" size %u name '%s'" memory_region_subpage_read(int cpu_index, void *mr, uint64_t offset, uint6= 4_t value, unsigned size) "cpu %d mr %p offset 0x%"PRIx64" value 0x%"PRIx64= " size %u" memory_region_subpage_write(int cpu_index, void *mr, uint64_t offset, uint= 64_t value, unsigned size) "cpu %d mr %p offset 0x%"PRIx64" value 0x%"PRIx6= 4" size %u" -memory_region_ram_device_read(int cpu_index, void *mr, uint64_t addr, uint= 64_t value, unsigned size) "cpu %d mr %p addr 0x%"PRIx64" value 0x%"PRIx64"= size %u" -memory_region_ram_device_write(int cpu_index, void *mr, uint64_t addr, uin= t64_t value, unsigned size) "cpu %d mr %p addr 0x%"PRIx64" value 0x%"PRIx64= " size %u" memory_region_sync_dirty(const char *mr, const char *listener, int global)= "mr '%s' listener '%s' synced (global=3D%d)" flatview_new(void *view, void *root) "%p (root %p)" flatview_destroy(void *view, void *root) "%p (root %p)" --=20 2.54.0 From nobody Wed Aug 26 07:24:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1786547861; cv=none; d=zohomail.com; s=zohoarc; b=ce5H/Jbh24jemOTn6oflJcp0ksKIg4Lv3AYz3+jExA126rJVXLYkm0ULmtRR2XcGuSUZHgxphO0+9i61XE0AbuLBe80Q+WakwSvfcJ1eReoWODD1suRlfq3tly/Ba2o6Xj3psOw6hinCU7DiwFFVg59Yc4IkAetZGTQsHaslLfE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786547861; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=0iT8zWdwP/JoJO55pCA3wPGlSWkzRKH/4c+aZeB9UMc=; b=FQp/CjHYDOUUX+FByL5E/+78lKmDbOwSFiyqJ4KbRCYPqVQtsMmYN8yD9+JECyI4Q6Zwkf8qPMdHIC18AeLG3J6grff4tk2PpSaS1aCdiIYCdLzXuam9pOgwglCy8Z1gyiZehWKGMg36Sn0F9pf4GaobATUJ5uZ4PfPKL11vYdA= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178654786186661.8813484050321; Wed, 12 Aug 2026 08:17:41 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wuAgh-0008DW-EM; Wed, 12 Aug 2026 11:16:15 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAgG-00082i-G0 for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:15:48 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAgD-0007BF-P0 for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:15:48 -0400 Received: from mail-qt1-f200.google.com (mail-qt1-f200.google.com [209.85.160.200]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-100-4qchVrk6NSWi7ThBL5m4IQ-1; Wed, 12 Aug 2026 11:15:38 -0400 Received: by mail-qt1-f200.google.com with SMTP id d75a77b69052e-51c1b4d961dso10224001cf.1 for ; Wed, 12 Aug 2026 08:15:38 -0700 (PDT) Received: from x1.com ([174.91.117.74]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-52d61d948d6sm19552841cf.15.2026.08.12.08.15.35 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 08:15:35 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786547745; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=0iT8zWdwP/JoJO55pCA3wPGlSWkzRKH/4c+aZeB9UMc=; b=MQz1k3UtgXQ/38kU3Z7RLtKuT9oCduekoxOCd5eFLpeeZvHdNpxNwJyvMYSWvotEvdkTDX hjuXgRir9vgDLTwamKhNO7jYrvFBl+s0HOIeVEle/jras7OrdD/ryhcqoDAh8fXRrgCKI6 Y5VP1KWzV9rbROixaUfJi+YamXffO0Q= X-MC-Unique: 4qchVrk6NSWi7ThBL5m4IQ-1 X-Mimecast-MFC-AGG-ID: 4qchVrk6NSWi7ThBL5m4IQ_1786547738 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1786547738; x=1787152538; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=0iT8zWdwP/JoJO55pCA3wPGlSWkzRKH/4c+aZeB9UMc=; b=oJ9NoN8V0DyoPpSNanukoD6ZVSVqiFR1k9tWTMEDrwJ5zX5OY07plA9xnyda5wHqSB 5r2JD1/u/tWUS2zkq8glntWcjlm5AQuBGKOsW9BvBlcTK+qPHZXG3B+S8FJ1cJdSviG0 UHaS9g+Ek57LJFqUM6npnF3U4vqPnRblamMz1FrcslL6Q8JHU4y6o+GMvEwLAWW7Nxtl rjcg18QmXwaaYEfw0meRE5G5W4UAARqAMqL7mgOh3082lM5xoU/RQVgi/d9fNIpk2DHe HZOCSWE+GqP31/EEb/Oue5WM3CS6ft8hK7VABngKJ02QUDghpXE78BfDzMH1b3lRLZv3 rMQQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786547738; x=1787152538; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=0iT8zWdwP/JoJO55pCA3wPGlSWkzRKH/4c+aZeB9UMc=; b=r42fpogVZQgS7TtW8D7GN/0qV4gE1V4G8p5YTTwenRu5dH9vNTOS4hu6mu8swhW0P9 8vEvUCz3XDpkAXlmkCu5mMTQymi4eupHSt0Q+FX7tEbcr7IkUu6DwrlQeao7JvHy3u1A 3gnS9kwgKCxpmqYZpBYE6owvrtP2HSI5rAKyOmbDwnv1yMxv7IQWg58MgOjoORRCiYzR uBZ26BY9RJSfQDpR5g/qUYxj0WS2M/ZM/u0Oyxua5GGVnZa3rfB8a/8G6NvQCjP1gn43 Dn4SYudYsBuZmSqVpc8KNMBO83aeECG+y5xxb5jrz0UfDuGEAeB1EkeIeyre9PaQ4fe3 vvjQ== X-Gm-Message-State: AOJu0Yza0IKuTBaLBCxQfTX0bYKfLuJ6QPatIIeYPXCSp1lBf/9mXHSb VsBxPOTgbuN1T8YV/TqNgno0HWfsOmeePN5weHRoM4GeKhN2nF4bHFgxAg3o0g3lP4ub0pGdy3P qdslcYBNJ5Kqf9CoG1RiUH/SkhfgPja/gTTv5xH2M4e75okIam2t9QEBA67XJ5AwIOQ/r1kPHhj ZlKW6boWVQbLb6f6O2gy/pfxXW9yTJQKMV3dhN1A== X-Gm-Gg: AR+sD128sZy6Ho4Bgv2hMnP86AfjSqxXRX21USob/mIe5q5xjIPzWfiXRklBYKXPXlV OyMV2tJdgzhonek9VfnDFU2lQFiCPX+dPIexOL2HSs2QpH7tAbhYII5lKy30GyQlKyQ/Li/KJud Tq2MCOB+WcW4Of3FQtPayjUT1RKVXfvSIoEjfeZQBvjxZEVdHgPjPLonzyu02llcw5a02/qKFNM GJdUpAtdaw2zupPbS2wZs98IRJdFe2T4KhhycB8BHAqHGnpHgpXvxc900NFJHO3BKqGddT4e6ET YEpwnBQIX7H2PUlwWUq98E01+zcxFOyeGMjdrRKeRnAQPBIVBuiNlLa5lx1lsMLYRw== X-Received: by 2002:a05:622a:544b:b0:51b:feee:b08f with SMTP id d75a77b69052e-52d657dd626mr41570361cf.1.1786547737902; Wed, 12 Aug 2026 08:15:37 -0700 (PDT) X-Received: by 2002:a05:622a:544b:b0:51b:feee:b08f with SMTP id d75a77b69052e-52d657dd626mr41569571cf.1.1786547737325; Wed, 12 Aug 2026 08:15:37 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: Peter Xu , Fabiano Rosas , Paolo Bonzini , Sam Heney Subject: [PULL 06/10] tests/qtest/migration: Only build tls_no_hostname test with TASN1 Date: Wed, 12 Aug 2026 11:14:39 -0400 Message-ID: <20260812151444.2611689-7-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260812151444.2611689-1-peterx@redhat.com> References: <20260812151444.2611689-1-peterx@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -21 X-Spam_score: -2.2 X-Spam_bar: -- X-Spam_report: (-2.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.104, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1786547864091158500 Content-Type: text/plain; charset="utf-8" From: Sam Heney The test_precopy_tcp_tls_no_hostname test and its start hook use TestMigrateTLSX509 and migrate_hook_start_tls_x509_common(), which are only defined when CONFIG_TASN1 is set. This means building with gnutls enabled but libtasn1 unavailable fails: ../tests/qtest/migration/tls-tests.c: In function 'migrate_hook_start_tls= _x509_no_host': ../tests/qtest/migration/tls-tests.c:510:5: error: unknown type name 'Tes= tMigrateTLSX509' Guard the test with CONFIG_TASN1 like the other x509 tests. Fixes: df9c38b19af8 ("tests/qtest/migration: Add a NULL parameters test for= TLS") Signed-off-by: Sam Heney Link: https://lore.kernel.org/r/5f24de0e-49af-45a7-927f-f79b203bb335@app.fa= stmail.com Signed-off-by: Peter Xu --- tests/qtest/migration/tls-tests.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/tests/qtest/migration/tls-tests.c b/tests/qtest/migration/tls-= tests.c index 827cc7bcf8..9bdb1165af 100644 --- a/tests/qtest/migration/tls-tests.c +++ b/tests/qtest/migration/tls-tests.c @@ -492,6 +492,7 @@ static void test_precopy_tcp_no_tls(char *name, Migrate= Common *args) test_precopy_common(args); } =20 +#ifdef CONFIG_TASN1 static void * migrate_hook_start_tls_x509_no_host(QTestState *from, QTestState *to) { @@ -519,7 +520,6 @@ static void test_precopy_tcp_tls_no_hostname(char *name= , MigrateCommon *args) test_precopy_common(args); } =20 -#ifdef CONFIG_TASN1 static void test_precopy_tcp_tls_x509_default_host(char *name, MigrateCommon *args) { @@ -719,8 +719,10 @@ void migration_test_add_tls(MigrationTestEnv *env) =20 migration_test_add("/migration/precopy/tcp/no-tls", test_precopy_tcp_no_tls); +#ifdef CONFIG_TASN1 migration_test_add("/migration/precopy/tcp/tls/no-hostname", test_precopy_tcp_tls_no_hostname); +#endif /* CONFIG_TASN1 */ =20 migration_test_add("/migration/precopy/unix/tls/psk", test_precopy_unix_tls_psk); --=20 2.54.0 From nobody Wed Aug 26 07:24:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1786547820; cv=none; d=zohomail.com; s=zohoarc; b=LEaBh+W0y1YrA6z8L64sA7ZeMivVw2tNb9HoOd/gEw2BElXhfUOZ6vJqc/0EG/yREV0uHhgn3G9oDrSiKwCOuUwvC6EjtqlZ3GH5/NTstSDkOEsTM7xUEP0PrEipjUylVZ1YwGb+l63dQqFVz6R+tKV9vRldVqmTxQCemMwyNL4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786547820; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=0JQ86lSdiu/uKGXruj2u8e/IyYjOzEuT9uWy0Nac8HE=; b=dnHkIISz0yvs2+rkf/fgOw52CBOXHIJi5mbGUhegiIxO6rE9ussV0YarTHTOVDNd0UBsbokBQnIMz30oSp0oZFDceUmZ+ZNuCcZ85fBIGBOh1by8IkPUy1/XXIamGpmGrcxrPbtijCUcSJAJOV8M5wPqBr4Kq3nrQq770tsbyLg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786547820175840.1062408176048; Wed, 12 Aug 2026 08:17:00 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wuAgc-00087a-Uf; Wed, 12 Aug 2026 11:16:12 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAgF-0007wv-Bk for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:15:47 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAgD-0007B5-F4 for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:15:47 -0400 Received: from mail-qt1-f199.google.com (mail-qt1-f199.google.com [209.85.160.199]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-249-9t3_PTG2P2-MZ9Yfu4iDdQ-1; Wed, 12 Aug 2026 11:15:43 -0400 Received: by mail-qt1-f199.google.com with SMTP id d75a77b69052e-526da7e3c9dso10745141cf.1 for ; Wed, 12 Aug 2026 08:15:43 -0700 (PDT) Received: from x1.com ([174.91.117.74]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-52d61d948d6sm19552841cf.15.2026.08.12.08.15.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 08:15:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786547744; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=0JQ86lSdiu/uKGXruj2u8e/IyYjOzEuT9uWy0Nac8HE=; b=eXl5SyPOV+uBSa/zLO9lai05fzLDycsssAHLffWGb5lrrlTWRbTStjHF3n1VRgBukcDSbR Gyki7BPFW7dThBiQxiHQe0FclvG29ePsAq+dtJZt5EQAejUVlGEMISqpOexCUhHstNFMt5 fDW4OWbWx3XEsHcxyD8adaKk/nf1TdY= X-MC-Unique: 9t3_PTG2P2-MZ9Yfu4iDdQ-1 X-Mimecast-MFC-AGG-ID: 9t3_PTG2P2-MZ9Yfu4iDdQ_1786547743 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1786547743; x=1787152543; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=0JQ86lSdiu/uKGXruj2u8e/IyYjOzEuT9uWy0Nac8HE=; b=UWtmeBsU3YhVAfwZpbziAY0nlvXBp0IXZRMXv63Bc4N2JIP8rhkxTK3+5Q24Z/ISsg xQgwx6cOQAgD/eCMjaUk0w78bXsAiM8iEy/fxMlUGk25A25Vip56RhNZ0Bj83N1zjUXD Hm39y3UZkRiuJN1rUXJ9w/Dx7VM1FLaLYfiwYICU60qmvDsJKjzc9iL0W/oCEzZ4ymLa 0RVOPormyPwWv5qLojCL5H4zPvn0GTOSkxQzxIWgrdoH2XLg3KW2xgGZHawkROGfFRgx dSwaOZVuSaaHH+Kcs8YxAZyiv1Rp1PSWHkwnjFSlRcMva/4OQrvmP6r/yMhJV3nZEUjP W85A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786547743; x=1787152543; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=0JQ86lSdiu/uKGXruj2u8e/IyYjOzEuT9uWy0Nac8HE=; b=p4k/Hdxbq1OL5zNW1h0qJyFJNo9GqslH6G6Vt8RhrSX6Crm3nW+4ZqBWxU2Ye526dS wAEHuLrIrmB7cVuErgp5lFIR+bd5dmFwCzOKjGbxSJmGe+DLp3+IK2o66/OLWPCHya43 IJbK2EI2TgecJ9lu0BPanHT2G33XNKUm132qOtTNeWNS4Z1pgAIMLU1LqMqxj6JgGVjn vle0yIfP6xLJebqYL16zz+r0upTiPxqevRSIz+/V1wKP5RHjGxe/KTZwEPiAeVo4YJpR CPTICjDG6b8SBPj75iDehSl4ky56Fpi5zI+6g3kcPPaJD9D6E+LaIkYUxSg/IQ/sHq3V CfbQ== X-Gm-Message-State: AOJu0Yz+GV1yp7gnxJbTymtqqmWvk1VfQ/CuDSnHWNt+SSgAQeIC2kLp 4SPc0fFxnQXa2sXrxRYmYpZe8tvSPrKp6kgz3mShRryHid1wcyBHa5E5ltmiGmorHjc9pLzJh3u cN/sl21XdimyHsA8VYEfNq7cpL7qLaszK+/q9Ja2d6IFQMye0RuImUAkxLD6BFwAhnx+5Xg3/8D oQAeclqIzvWphKmuWWiD77reis8NHJoMmd4WCgCQ== X-Gm-Gg: AR+sD104nLSFMZ4Kb4wmZaEv5IV0ilNis7bHkBDRYap7yp3ENUSVK4h7Qj1STYC9GZK 2GmD47kjH9lLUd4csj0mp/gk3pfIJ0bZ2A1GE9RUdreO7iUU6F3t+QjBbH8Q83N4X0iF78JKi6G BkfBtrt/eL9CblnchKYSgDZg/s1mt1vPb2RtCpHS+amsB9AAo6g6sL1cZAhLSOAX3H/1Kc6AL6t QGbRNS3Ygri78ZtdQKF/KmtXsbKxocrBWsKAP0orKHxIca8F+p4L14Y/Ixo/s7ysDs5MdPV6CRW aI5mJDcKD7u00qFli2BPDZsb3YlpmXfZOLAuJd9urrN22ALsdKikpwSPZAFOP4DIMA== X-Received: by 2002:ac8:6f1b:0:b0:52d:3d46:bfd6 with SMTP id d75a77b69052e-52d64712203mr45475041cf.12.1786547742773; Wed, 12 Aug 2026 08:15:42 -0700 (PDT) X-Received: by 2002:ac8:6f1b:0:b0:52d:3d46:bfd6 with SMTP id d75a77b69052e-52d64712203mr45474001cf.12.1786547742006; Wed, 12 Aug 2026 08:15:42 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: Peter Xu , Fabiano Rosas , Paolo Bonzini , xlabai , Jules Denardou , Tristan Madani , qemu-stable Subject: [PULL 07/10] migration/multifd: Validate next_packet_size in zlib/zstd recv Date: Wed, 12 Aug 2026 11:14:40 -0400 Message-ID: <20260812151444.2611689-8-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260812151444.2611689-1-peterx@redhat.com> References: <20260812151444.2611689-1-peterx@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -21 X-Spam_score: -2.2 X-Spam_bar: -- X-Spam_report: (-2.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.104, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=unavailable autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1786547821951158500 Content-Type: text/plain; charset="utf-8" The zlib and zstd multifd compression backends read next_packet_size from the incoming migration stream and use it directly as the read length into a fixed-size buffer (MULTIFD_PACKET_SIZE * 2 =3D 1MB). A malicious migration source can set next_packet_size bigger than allocated, causing a heap buffer overflow write on the destination. Add a check against zbuff_len before reading, matching what the qatzip backend already does. Also replace the assert(in_size =3D=3D 0) for empty packets with proper error reporting, since the value is wire-controlled, meanwhile assert() stops working with -DNDEBUG builds. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3737 Reported-by: xlabai Reported-by: Jules Denardou Reported-by: Tristan Madani Reported-by: david korczynski (@david1766) Reported-by: huntr bubble (@bubblehuntr) Cc: qemu-stable Reviewed-by: Fabiano Rosas Link: https://lore.kernel.org/r/20260728210417.1925078-3-peterx@redhat.com Signed-off-by: Peter Xu --- migration/multifd-zlib.c | 11 ++++++++++- migration/multifd-zstd.c | 11 ++++++++++- 2 files changed, 20 insertions(+), 2 deletions(-) diff --git a/migration/multifd-zlib.c b/migration/multifd-zlib.c index 8820b2a787..400146566e 100644 --- a/migration/multifd-zlib.c +++ b/migration/multifd-zlib.c @@ -216,10 +216,19 @@ static int multifd_zlib_recv(MultiFDRecvParams *p, Er= ror **errp) return -1; } =20 + if (in_size > z->zbuff_len) { + error_setg(errp, "multifd %u: next_packet_size %"PRIu32 + " exceeds allocated %"PRIu32, p->id, in_size, z->zbuff_= len); + return -1; + } + multifd_recv_zero_page_process(p); =20 if (!p->normal_num) { - assert(in_size =3D=3D 0); + if (in_size !=3D 0) { + error_setg(errp, "multifd %u: expected empty packet", p->id); + return -1; + } return 0; } =20 diff --git a/migration/multifd-zstd.c b/migration/multifd-zstd.c index 3c2dcf76b0..69ef1a5f38 100644 --- a/migration/multifd-zstd.c +++ b/migration/multifd-zstd.c @@ -210,10 +210,19 @@ static int multifd_zstd_recv(MultiFDRecvParams *p, Er= ror **errp) return -1; } =20 + if (in_size > z->zbuff_len) { + error_setg(errp, "multifd %u: next_packet_size %"PRIu32 + " exceeds allocated %"PRIu32, p->id, in_size, z->zbuff_= len); + return -1; + } + multifd_recv_zero_page_process(p); =20 if (!p->normal_num) { - assert(in_size =3D=3D 0); + if (in_size !=3D 0) { + error_setg(errp, "multifd %u: expected empty packet", p->id); + return -1; + } return 0; } =20 --=20 2.54.0 From nobody Wed Aug 26 07:24:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1786547885; cv=none; d=zohomail.com; s=zohoarc; b=dUVEsmIMjD5wjUjxsseBBM7yXbb8Z4oVUrZ0qRXb7mS6ayky+sTeejfCU+LkMPuZdRCzEM0qSZXrfFIGoI5YdLjMfoPCsj/YbDuO0+oKRNOx1EP08uXzNkTGML6afdIU9LIEIlMhyfbpdE/sJEVeTfmcgOBCFmMelCpDmZBGyKs= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786547885; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=+OceRc3ZgDjagPSQ/pqT62JhQxrkVIS83abLwhmkN1c=; b=Kpf9lp0YX2luLyC5PH7xRZTLKMF0CbootFTrPRMSKY5/rOoOOioCIpuvrDEIDp8Xkx0C5ZPSbOvIK+YgdwzUQdxqw0rAKnJhl2afVUjIH750GkL24spBpxs8Ni/BRi0LgwPq9Gunq+qv46YN8ycS4trQX3iHikUVquU18O4e7Sg= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786547885519398.1752465732286; Wed, 12 Aug 2026 08:18:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wuAgk-0008Ul-VW; Wed, 12 Aug 2026 11:16:19 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAgN-00086B-18 for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:16:01 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.133.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAgK-0007DN-W9 for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:15:54 -0400 Received: from mail-qt1-f200.google.com (mail-qt1-f200.google.com [209.85.160.200]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-88-ua-GYnnaNKmYfpjxj5QeKg-1; Wed, 12 Aug 2026 11:15:49 -0400 Received: by mail-qt1-f200.google.com with SMTP id d75a77b69052e-51c1b4d961dso10224871cf.1 for ; Wed, 12 Aug 2026 08:15:49 -0700 (PDT) Received: from x1.com ([174.91.117.74]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-52d61d948d6sm19552841cf.15.2026.08.12.08.15.42 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 08:15:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786547752; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=+OceRc3ZgDjagPSQ/pqT62JhQxrkVIS83abLwhmkN1c=; b=UKXgqXK3Xp+NTlpCJEQFZafqMdKeLbCC9gkRq4JCg+qr/KOtRz5Ke/wvLDippbr45HUNlB vcebf7GBkzwuX+1/a7U4JpnQtHPoHd7vvV668z5mFQpXpFHc7QxcWw7/yw7myx5Dv4k/Ak rv+PRVjMRFKbDDZ+8OY7OlzzSn76wsg= X-MC-Unique: ua-GYnnaNKmYfpjxj5QeKg-1 X-Mimecast-MFC-AGG-ID: ua-GYnnaNKmYfpjxj5QeKg_1786547749 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1786547749; x=1787152549; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=+OceRc3ZgDjagPSQ/pqT62JhQxrkVIS83abLwhmkN1c=; b=ckwXRrMHLxqWohqrRzr8yvpnvHR1Afy+uUsd7XYPFntaOmNEtaMDiIxcW8RGyZqrOX 7eCqE+yx88s5BXHgxpCGB/IDdUTA7LfA8Cpa2wRWD+cfYa4HlVNV53V7XqjbA3ZugcPt qTfOVA1jIpUV4bqJJlT3PxguHITlrT5Z0AwKM7djsEa+R9cdj3tvqEyNqeMWoFiwTSVt TiKOzwVJJo3mSRM39/lZHYy8LjgJhO2vxerYhZzkhVeuhruj8LqVOZOx3aZqRi3d2eDU PUJ6ccs5WaIJimZiwAuNUOswQfugvTXLdt86TxKLAmUXA0RZJmG5i0qDOXiN9S3+j7An n8vg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786547749; x=1787152549; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=+OceRc3ZgDjagPSQ/pqT62JhQxrkVIS83abLwhmkN1c=; b=b50gXO4K0cgn4XYYKuKyKj0kQIQj2uR8Jmvuh3LmZkv111BSRRV02imhOHrsYUy17c lwEB+5h6EbNWfQol4BC17kTopb6528BZ+EZhbQ4umgPzQxkXdemLin/ok3oSB9NrPJiv j5Fy3NVQ8rqrO7bMBYK6YSJWWKqGa7fWwGxK9groBicmyizL3MpHlizsDjGUJSOKIqeq L18VuZhiRh1bYyX4SRnj+v6h0OqMQe+nd74iy0jWtqpn47RY0LVSOq7887UIBvbRdfjd MGeiWYxUtNr5F7RPhz5pbaCFQw5XfpEEQ+I3AZ7sd17sZLOXV6pzgPXD/mVjjQyfCJww qISg== X-Gm-Message-State: AOJu0YzBHF0e1xmjEAF1FmbNEOOYZlL/slGxIMQkjYz1TVuPJ1MnVrUs EuemAETY4u99pbJRp0+wBcdwA5NBo2VzRNyClgOJckdjpaLCD6+Up8pvgj30tkojqGzP+aP0LPv pqGcL1+SVuBM7i0USiho3Oo2e9LMSqi2jrRkKtgV2uxD3dALPKBzNzxB3HbG4iJgdmOGw6xExih LI6cVaVLqMjra5lln1MBUDjAnv3Uc+OUB6hlyyIg== X-Gm-Gg: AR+sD11PrWTWaqdGSaQz5yV5qMsvT/4hbKuLlPoobFmPF9PkTBMIvJeUXEjZTiIwgXC 7E8VMgZsGS/LfLR+cLdRiXmjJRk2TtJaL0I4rfCdzIlTctPHrow1DnXi37JqG7T3GdPYJlB5krQ P13R4e5rsgBf9xam3o/8wY9OY4iVoEZBWiImZCXOd2S0ERuBFoQYfdVzZfIhm68+0VXNT0PetKa 2Oe6CQoU+RpupP473Rrrkkq1tkeXQGYWj3Cr/go+tJnIUTT9+ALXFJY/8HIFAsQfog73Sx+ntvp mYjD+DDcPNsXbWA1dhbod2Gcnk/Znc4dFwR9oLytJdCYru1qFZE6lMc7TxdmlLj3Wg== X-Received: by 2002:a05:622a:248b:b0:521:103d:9f98 with SMTP id d75a77b69052e-52d659f7970mr41745531cf.19.1786547748639; Wed, 12 Aug 2026 08:15:48 -0700 (PDT) X-Received: by 2002:a05:622a:248b:b0:521:103d:9f98 with SMTP id d75a77b69052e-52d659f7970mr41744501cf.19.1786547747923; Wed, 12 Aug 2026 08:15:47 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: Peter Xu , Fabiano Rosas , Paolo Bonzini , qemu-stable , Yuan Liu , Yichen Wang Subject: [PULL 08/10] migration/multifd: Replace assert() with error_setg() in recv paths Date: Wed, 12 Aug 2026 11:14:41 -0400 Message-ID: <20260812151444.2611689-9-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260812151444.2611689-1-peterx@redhat.com> References: <20260812151444.2611689-1-peterx@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.133.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -21 X-Spam_score: -2.2 X-Spam_bar: -- X-Spam_report: (-2.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.104, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1786547886294158500 Content-Type: text/plain; charset="utf-8" QPL and UADK multifd backends use assert() to validate wire-controlled fields like per-page compressed lengths and packet size consistency. These asserts will stop working with -DNDEBUG builds, so may stop working. Replace all assert() calls in the receive path with proper error_setg() so validation failures are reported gracefully rather than crashing or silently ignored. While at it, touch up an assert() in qatzip recv path too. Cc: qemu-stable Cc: Yuan Liu Cc: Yichen Wang Reviewed-by: Fabiano Rosas Link: https://lore.kernel.org/r/20260728210417.1925078-4-peterx@redhat.com Signed-off-by: Peter Xu --- migration/multifd-qatzip.c | 5 ++++- migration/multifd-qpl.c | 24 ++++++++++++++++++++---- migration/multifd-uadk.c | 24 ++++++++++++++++++++---- 3 files changed, 44 insertions(+), 9 deletions(-) diff --git a/migration/multifd-qatzip.c b/migration/multifd-qatzip.c index 7419e5dc0d..0262e81eac 100644 --- a/migration/multifd-qatzip.c +++ b/migration/multifd-qatzip.c @@ -348,7 +348,10 @@ static int qatzip_recv(MultiFDRecvParams *p, Error **e= rrp) =20 multifd_recv_zero_page_process(p); if (!p->normal_num) { - assert(in_size =3D=3D 0); + if (in_size !=3D 0) { + error_setg(errp, "multifd %u: expected empty packet", p->id); + return -1; + } return 0; } =20 diff --git a/migration/multifd-qpl.c b/migration/multifd-qpl.c index 52902eb00c..3826e7f340 100644 --- a/migration/multifd-qpl.c +++ b/migration/multifd-qpl.c @@ -664,26 +664,42 @@ static int multifd_qpl_recv(MultiFDRecvParams *p, Err= or **errp) } multifd_recv_zero_page_process(p); if (!p->normal_num) { - assert(in_size =3D=3D 0); + if (in_size !=3D 0) { + error_setg(errp, "multifd %u: expected empty packet", p->id); + return -1; + } return 0; } =20 /* read compressed page lengths */ len =3D p->normal_num * sizeof(uint32_t); - assert(len < in_size); + if (len >=3D in_size) { + error_setg(errp, "multifd %u: header len %"PRIu32 + " >=3D packet size %"PRIu32, p->id, len, in_size); + return -1; + } ret =3D qio_channel_read_all(p->c, (void *) qpl->zlen, len, errp); if (ret !=3D 0) { return ret; } for (int i =3D 0; i < p->normal_num; i++) { qpl->zlen[i] =3D be32_to_cpu(qpl->zlen[i]); - assert(qpl->zlen[i] <=3D multifd_ram_page_size()); + if (qpl->zlen[i] > multifd_ram_page_size()) { + error_setg(errp, "multifd %u: page %d compressed len %" + PRIu32" too large", p->id, i, qpl->zlen[i]); + return -1; + } zbuf_len +=3D qpl->zlen[i]; ramblock_recv_bitmap_set_offset(p->block, p->normal[i]); } =20 /* read compressed pages */ - assert(in_size =3D=3D len + zbuf_len); + if (in_size !=3D len + zbuf_len) { + error_setg(errp, "multifd %u: packet size %"PRIu32 + " !=3D header %"PRIu32" + data %"PRIu32, + p->id, in_size, len, zbuf_len); + return -1; + } ret =3D qio_channel_read_all(p->c, (void *) qpl->zbuf, zbuf_len, errp); if (ret !=3D 0) { return ret; diff --git a/migration/multifd-uadk.c b/migration/multifd-uadk.c index fd7cd9b5e8..d373615ba8 100644 --- a/migration/multifd-uadk.c +++ b/migration/multifd-uadk.c @@ -245,12 +245,19 @@ static int multifd_uadk_recv(MultiFDRecvParams *p, Er= ror **errp) =20 multifd_recv_zero_page_process(p); if (!p->normal_num) { - assert(in_size =3D=3D 0); + if (in_size !=3D 0) { + error_setg(errp, "multifd %u: expected empty packet", p->id); + return -1; + } return 0; } =20 /* read compressed data lengths */ - assert(hdr_len < in_size); + if (hdr_len >=3D in_size) { + error_setg(errp, "multifd %u: header len %"PRIu32 + " >=3D packet size %"PRIu32, p->id, hdr_len, in_size); + return -1; + } ret =3D qio_channel_read_all(p->c, (void *) uadk_data->buf_hdr, hdr_len, errp); if (ret !=3D 0) { @@ -259,12 +266,21 @@ static int multifd_uadk_recv(MultiFDRecvParams *p, Er= ror **errp) =20 for (int i =3D 0; i < p->normal_num; i++) { uadk_data->buf_hdr[i] =3D be32_to_cpu(uadk_data->buf_hdr[i]); + if (uadk_data->buf_hdr[i] > page_size) { + error_setg(errp, "multifd %u: page %d compressed len %"PRIu32 + " too large", p->id, i, uadk_data->buf_hdr[i]); + return -1; + } data_len +=3D uadk_data->buf_hdr[i]; - assert(uadk_data->buf_hdr[i] <=3D page_size); } =20 /* read compressed data */ - assert(in_size =3D=3D hdr_len + data_len); + if (in_size !=3D hdr_len + data_len) { + error_setg(errp, "multifd %u: packet size %"PRIu32 + " !=3D header %"PRIu32" + data %"PRIu32, + p->id, in_size, hdr_len, data_len); + return -1; + } ret =3D qio_channel_read_all(p->c, (void *)buf, data_len, errp); if (ret !=3D 0) { return ret; --=20 2.54.0 From nobody Wed Aug 26 07:24:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1786547884; cv=none; d=zohomail.com; s=zohoarc; b=FuMI40UpGR4a4GaVHUjN4g7v0niCXcXgpmPtT1yTESvbIsQGCxJ6jKMXQXwIGisvmOLASZNF1pC0e5ncC6zMLsEq/ttWnumTElAA1/8C8IPMLdRBjpAQ3lnwatJcLjptp2Qz/5RoDB+VxVZcRnBixq8w5wfxzFPeLYHAeMYn1XM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786547884; h=Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=UuW++BxckSebbVYSJky3TOCAC5NfFrDSCOlGqtDgr60=; b=Rchgqz5kxrkPxpAms+GLFhN9uYAqQj+iqSSeRo8gP4vwySagMNc0Z4RxcJMkqsS3pc42aignnKebPC69aCDR8b23zWsLXyWpWSkDlXedwQ4kaciQpW6AGHoJB5i6uZS4GEHC33porUDDRJBjqew/YrkRes+J/fVaDzxjNJJrSXc= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 178654788416120.42946609133662; Wed, 12 Aug 2026 08:18:04 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wuAgk-0008Ts-Rd; Wed, 12 Aug 2026 11:16:18 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAgO-00086D-44 for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:16:07 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAgM-0007Dc-Nc for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:15:55 -0400 Received: from mail-qt1-f199.google.com (mail-qt1-f199.google.com [209.85.160.199]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-37-5eVdpf9YPqCRkfR6LRoNaw-1; Wed, 12 Aug 2026 11:15:51 -0400 Received: by mail-qt1-f199.google.com with SMTP id d75a77b69052e-52d28f8737eso20521831cf.2 for ; Wed, 12 Aug 2026 08:15:51 -0700 (PDT) Received: from x1.com ([174.91.117.74]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-52d61d948d6sm19552841cf.15.2026.08.12.08.15.48 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 08:15:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786547754; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=UuW++BxckSebbVYSJky3TOCAC5NfFrDSCOlGqtDgr60=; b=E3DvfXouY0OLwLrUStsuTb7C24VuSy8D69Xib8p5rwgwJwYK129dYXOGMP8rv9aFACxWGQ 7f0UKDfXoEK0n1HnZ/q/42QmofwfxliEWj327wmrigrTgFRdhcbaF1KXTrsn468O/Npbc8 ziPiJwLniTZdq/7zJ6v7hRuYp3gU4ks= X-MC-Unique: 5eVdpf9YPqCRkfR6LRoNaw-1 X-Mimecast-MFC-AGG-ID: 5eVdpf9YPqCRkfR6LRoNaw_1786547751 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1786547751; x=1787152551; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=UuW++BxckSebbVYSJky3TOCAC5NfFrDSCOlGqtDgr60=; b=IlPTwvaBWuNpK++N6d4uHB1swJswWrDjw1T18R6ZBkfhV1xT/wzzDBIIqNCLvbXx1u Ozc35sD12S5s72mciYw30LR7JULxmtamPBrLZ+btyIp7b1Kk9CYnUaNRxXQNQXOgGYJf 7wVNb1nfdjfqRNXDzFh4V+EpWdQ+kcrS8VfxED6OfbTa2BRwvZmL8Ry0HU0+/Yczbjvn IqxIExSHKzhFOEVV+/rtwI7KsuzaU7AsdPw7Fp4rBypvHtV3upg5movNgS+4XP/Rkkt1 L/KDEZSS/mBz/gm3hou/IN93irsFoppYlyVZBvHXw10xgYJyZ1l1d+ISfyeZPJxFDYri wawQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786547751; x=1787152551; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=UuW++BxckSebbVYSJky3TOCAC5NfFrDSCOlGqtDgr60=; b=Gu7CQ9H7KMKVQ6LmC0rh3tiOEAJ3U0SxZiOCfy12qkb4YoMGmF31MzqobG5EBp09w4 /SgQicmWndOdsP5J9mKZNJrqU37n5Uhf3RXInCXC47pLaPVT/LHoRG14VDlHV7fxSvh9 cRdMu+yHBqrusRRt4tzjnGSnxk4kzNrVq7mNHiTJdcio+bb/wjf8k+js7kYKTn3yFBWw grx0luIItSOAkP3xTLlhmf/3SOYTPsdBwXOS2z6M9VoviaBxsMifsa8UO3/MD93RfBbG qS62XQ23T5DsSTcZr1i/UM5uPlLGIMj1eZKZhWyFx7/QeMgyGPk0iM8ACeOvaH45afuw W5XQ== X-Gm-Message-State: AOJu0Yy5fnyC6G+LHZrLT1TliwRxCz8Q0U2bFtoeEFTykZ9lgSSniCl0 EnMhMtf60dfa/j/gfhnlVaDc9syeviz/imMzpfjIwyG5eqHkQg23u/eBmdeURBWkBrRoBlKRTj7 +1qKpx6QNNkMTanVoRDGaK7DwMDVL2n54TfPZhlIV3IhbuVP5Cl6r9rW7X+tp0CLkuvDGAzLFp0 FpgnibvjNcCurf+aHZ5qgvvDimYVLMyHa1DyQuXA== X-Gm-Gg: AR+sD12CxzXlF/EsiQsJAIYbCFJQkNbxHsvYQn/+e+pYxIxH2YHBB1FaU48LwtO+4Pp FXz9+amI/lHQ5DqpIuPJUmo67XuzrGdYPG4q9F1YZAvHauw1tRvGzN/ylwAjD3uKuyd6YoTtoCA DTM0JIAKChY6BHq2+EVxnTT38dDTwV/CoYsThwH/RJQ/l1tkc9zlGJ5Pp5SgGDftsmRUT32l6er VNAbjCMhwIpCv2vsePx76VYhikJ143yioF5X+AylWwqlF3hBqet87Zp4r9CXd/N9+sHCgwFNPUY AACUcC3KS4gfyRH8OlEa1fmDzhOsvGaxrJdAq5LrC2GFBWuRVpox0xWRq8sS3Zoppw== X-Received: by 2002:a05:622a:c08:b0:517:5add:e449 with SMTP id d75a77b69052e-52d647ec62cmr57551201cf.22.1786547750761; Wed, 12 Aug 2026 08:15:50 -0700 (PDT) X-Received: by 2002:a05:622a:c08:b0:517:5add:e449 with SMTP id d75a77b69052e-52d647ec62cmr57550181cf.22.1786547750234; Wed, 12 Aug 2026 08:15:50 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: Peter Xu , Fabiano Rosas , Paolo Bonzini , Tristan Madani Subject: [PULL 09/10] migration/ram: Check for RAMBlock size mismatch when parsing Date: Wed, 12 Aug 2026 11:14:42 -0400 Message-ID: <20260812151444.2611689-10-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260812151444.2611689-1-peterx@redhat.com> References: <20260812151444.2611689-1-peterx@redhat.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -21 X-Spam_score: -2.2 X-Spam_bar: -- X-Spam_report: (-2.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.104, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1786547886370158500 Content-Type: text/plain; charset="utf-8" Add an underflow check for the subtract of total RAMBlock size to make sure it won't underflow. It should not happen in production systems but only if the migration stream was hijacked, which is not a real concern since migration channel is trusted. Still protect against it. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4013 Reported-by: Tristan Madani Reviewed-by: Fabiano Rosas Link: https://lore.kernel.org/r/20260728210417.1925078-6-peterx@redhat.com Signed-off-by: Peter Xu --- migration/ram.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/migration/ram.c b/migration/ram.c index 8918b2f03b..85feff578c 100644 --- a/migration/ram.c +++ b/migration/ram.c @@ -4268,7 +4268,7 @@ static int parse_ramblocks(QEMUFile *f, ram_addr_t to= tal_ram_bytes) int ret =3D 0; =20 /* Synchronize RAM block list */ - while (!ret && total_ram_bytes) { + while (total_ram_bytes) { RAMBlock *block; char id[256]; ram_addr_t length; @@ -4285,8 +4285,15 @@ static int parse_ramblocks(QEMUFile *f, ram_addr_t t= otal_ram_bytes) error_report("Unknown ramblock \"%s\", cannot accept " "migration", id); ret =3D -EINVAL; + break; + } + + if (usub64_overflow(total_ram_bytes, length, &total_ram_bytes)) { + error_report("%s: RAMBlock '%s' size underflow total RAM size", + __func__, block->idstr); + ret =3D -EFAULT; + break; } - total_ram_bytes -=3D length; } =20 return ret; --=20 2.54.0 From nobody Wed Aug 26 07:24:39 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1786547885; cv=none; d=zohomail.com; s=zohoarc; b=NQ54jKWWAr68IgcNn5kStx1zqM7WwaPI20dPF7FFGjS/7EHLci/C3uF155pTICD3Tp8zzhd+ogIK6eRHHEfbJv1rPAKKJ02bDwEa+fLcfHDfsgnrwSmw99Ur/Dw90E90HmuOqvmBko8O9vzOPdjS66ysmh66oP5liTD+S1CGbDc= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786547885; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=wdsfDJq0N8HUdLIKKMBehusFJkGfXcTT0b2//0AMEHw=; b=EBFzpe6XNwNfC204qF3CxY336txNz8Ja1tqzs2YipmuZvCRC9nnC1AX+QVPNWE7nbgPHNYUbg6VAI3TLWXI+ymsc84HUo6Q/bnRvAviwCkgf0VqYoi+rhTwtafum2yPo6fNCUD1FQwG7bwKjf3PS/RR0H2de6ESg2vGLeZ6cFSE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786547885571168.82280301760318; Wed, 12 Aug 2026 08:18:05 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wuAgx-00008F-HO; Wed, 12 Aug 2026 11:16:34 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAgV-00087f-SX for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:16:08 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wuAgU-0007EX-8X for qemu-devel@nongnu.org; Wed, 12 Aug 2026 11:16:03 -0400 Received: from mail-qt1-f198.google.com (mail-qt1-f198.google.com [209.85.160.198]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-251-nX_UV4JAPwygHhN1Pp8Z4A-1; Wed, 12 Aug 2026 11:15:59 -0400 Received: by mail-qt1-f198.google.com with SMTP id d75a77b69052e-526da7e3c9dso10747271cf.1 for ; Wed, 12 Aug 2026 08:15:59 -0700 (PDT) Received: from x1.com ([174.91.117.74]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-52d61d948d6sm19552841cf.15.2026.08.12.08.15.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 08:15:50 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1786547760; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=wdsfDJq0N8HUdLIKKMBehusFJkGfXcTT0b2//0AMEHw=; b=eH1xMEsGsblYPNsddahp+b8MktXHH6HwLS4HZ7f4AU/R6t8BmJfk5yYf1yIbzHC31dzIFd uf24DZfCR3IjCiQG4BhVfUy/v+n51l3yG5xkUCdVAmb9GyvFopY6Z12wtU2IA1SHi1dgk/ 8u+EKiOwDDMM9OzL1jZMnb91hepWwPE= X-MC-Unique: nX_UV4JAPwygHhN1Pp8Z4A-1 X-Mimecast-MFC-AGG-ID: nX_UV4JAPwygHhN1Pp8Z4A_1786547758 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1786547758; x=1787152558; darn=nongnu.org; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:from:to:cc:subject :date:message-id:reply-to:content-type; bh=wdsfDJq0N8HUdLIKKMBehusFJkGfXcTT0b2//0AMEHw=; b=dO15qFEETl1BRhNsCzA1d6RlMvM7GultG0mElWe4q9ZUyOFpQrSFv1pNxm+T8jhQE6 GyTk2AYgnt/V0KGKu0Ax68T464RS8eYs37l3ZoZwSS70e66PcCQuPsCi6yxNr4UAfrUg yWKo9t7O6ZQJVm/UYHsUlFzKPAVYRaL9mfcps2Z8zzCX4UJySKosmA0tIOpTXMyPZiqu eviFMB37H6o3a+MI1qr/tYAXxrlqZN+wNTjbPb3T67AGw8g6VDvEPEaigfIry6lcZDw5 THVLj18mXHCZG0FQhRG8GBaBUGde75/VUx3jXNk1vsKGzrKS3nsmmsGbJONt9Wr3kbIz AAmw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786547758; x=1787152558; h=content-transfer-encoding:content-type:mime-version:references :in-reply-to:message-id:date:subject:cc:to:from:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=wdsfDJq0N8HUdLIKKMBehusFJkGfXcTT0b2//0AMEHw=; b=OVy/JW6gNFVgDSzq22gyC++jr56Yjf4PjPbSELpYjagaMcajQk1sHIZANcB3xrn72z yEo59rIyB2BeXa4FruOzwuhlrxfVuSoNP8uoK+yzsK2Z76wHqbNIZvp0PrOnl2lklBwA COo/hgMug7M4HXERyJvBzoAIzbl5e2pCwJfLm4duy0kdtc+F3VZ8QwUaoY8GEP1q3vnn Qru1AI51xPZ++7vISpVeoXBzGkfvpLlxGZm5AEsltCA856ZxXIudMIXZvjr3/GaiSlHZ rjvrVadKuJ1ITIcMybc+pwzyXaZxx0s58TypSuL0UgR16gxtsTBPxu/gKTEvdIRTlfxh nH6w== X-Gm-Message-State: AOJu0YzMhOjnSJIILekl1Q2KqFCv1GcqD6hZ/5sabIRZyLyV5u9QNbL2 OHLvMov6R8JUnibUrHBetIrVyaEUG0LdJiCA0b/Qx/oN8gSsySiurb8e8zU58ADfsk9K/a5yH+a lc0BmfMUJmvlyv4LIttr5uItJDPQVUM5CoLCNSVSVPO7/ue864oU2eiyHepIiOC5+FpZYp/IOun bGPbohYdjpeYNUMKgWQ2P/uNCetUtnSAaZDPK8Nw== X-Gm-Gg: AR+sD12m4FO3YO4iTopeymH1MdMtf6iLrhFM0H84/IJ/bUNQYdG5G9Tf8R+vhxoPZQC TtkPv7oHx7kCgvxY/AmH33dNrVSWpuY1A5eGk32cwIRgx1WO4YXoAf4V2M2uptlf+9klSO2y2K7 a6vdq2b58R3lTau10y4HE4IFToTt1xTfq0x7AEnoVjeBZBerhFhWt0C3B/I83a9WgkzhcyXKIyS e2cl/PC4rfHDEL20UuYCkbIjfIzhgVxBhLpELaljdJeEbHqo4Xfx+SzZUXbNrVakjpDQV6bf+Kq CHmhGqxhHCtuIBerZ5NiOkbeJ3EJD+4CTC3OwoRZ2zBXmyG299xS3+gcCGDYfwvxcg== X-Received: by 2002:a05:622a:581a:b0:528:22:8c61 with SMTP id d75a77b69052e-52d648b2a9emr49738331cf.38.1786547756938; Wed, 12 Aug 2026 08:15:56 -0700 (PDT) X-Received: by 2002:a05:622a:581a:b0:528:22:8c61 with SMTP id d75a77b69052e-52d648b2a9emr49736781cf.38.1786547756149; Wed, 12 Aug 2026 08:15:56 -0700 (PDT) From: Peter Xu To: qemu-devel@nongnu.org Cc: Peter Xu , Fabiano Rosas , Paolo Bonzini , Feifan Qian , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PULL 10/10] migration: Fix rare hang of migration_channel_read_peek() Date: Wed, 12 Aug 2026 11:14:43 -0400 Message-ID: <20260812151444.2611689-11-peterx@redhat.com> X-Mailer: git-send-email 2.54.0 In-Reply-To: <20260812151444.2611689-1-peterx@redhat.com> References: <20260812151444.2611689-1-peterx@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=170.10.129.124; envelope-from=peterx@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -21 X-Spam_score: -2.2 X-Spam_bar: -- X-Spam_report: (-2.2 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.104, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @redhat.com) X-ZM-MESSAGEID: 1786547886238158500 In an unlikely case, when a migration stream is attached to the destination QEMU and only send <4 bytes to the channel as magic, it's possible that migration_channel_read_peek() may spin forever. Fix it by adding a manual sleep for partial read. Since the path isn't attached to a coroutine, it means when partial read happens, there's yet not much we can do but hang the main thread, it will happen even for len=3D=3D0 case. It means monitors can hang due to this, either partial read or no data arrived (but connection established). Leave this for later, the hope is this is extremely rare in production. Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3889 Reported-by: Feifan Qian Cc: Daniel P. Berrang=C3=A9 Reviewed-by: Daniel P. Berrang=C3=A9 Link: https://lore.kernel.org/r/20260812124327.2572363-1-peterx@redhat.com Signed-off-by: Peter Xu --- migration/channel.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/migration/channel.c b/migration/channel.c index 1e2935f926..266ae8f776 100644 --- a/migration/channel.c +++ b/migration/channel.c @@ -296,9 +296,16 @@ int migration_channel_read_peek(QIOChannel *ioc, =20 if (len =3D=3D buflen) { break; + } else if (len =3D=3D QIO_CHANNEL_ERR_BLOCK) { + qio_channel_wait_cond(ioc, G_IO_IN); + } else { + /* + * When partially ready, we can't use qio_channel_wait_cond() + * because it will return immediately. Apply a manual wait. + */ + assert(!qemu_in_coroutine()); + g_usleep(1000); } - - qio_channel_wait_cond(ioc, G_IO_IN); } =20 return 0; --=20 2.54.0