From nobody Mon Sep 28 01:25:07 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=proton.me ARC-Seal: i=1; a=rsa-sha256; t=1786025641; cv=none; d=zohomail.com; s=zohoarc; b=KdVt72zQsSTkZYseQi//HvUD31bxwsN7xUoDQ4XSwRR+tcDNiY+hNcmxQCsK6bR72ML1igQ2CvhNRdDqDm8Bd78p1yKquOs3LsseDSq2yep/dYdCkVpd1g3EQHWRrLemAIS2sN7VPm6tkjKDfmZoqVNz8N73lPOs50KLiPyH64g= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1786025641; h=Content-Type:Content-Transfer-Encoding:Cc:Cc:Date:Date:From:From:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=NXSHtW8qDc7wlfrB+vA2ibpKtjZ1ya1mtVcYJ4jDhDo=; b=hul4MYr+icl3KZdMXUBn8LwnIcMByQmsGgMwUVXk7mPiWRut1kOXDJQIYPGQbWENnYXxxpiK9XG2kaxkUc5U5DepLweVkzm/A79KCrx0fOZWTfKI9u/Krsh1OIVuaSYgXByu1GJ5tqYu2oMXGcEdglOVhefTTcRBT6uoWnbGcuw= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1786025641508467.6622821036658; Thu, 6 Aug 2026 07:14:01 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wryqc-0003NO-VB; Thu, 06 Aug 2026 10:13:26 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wryqb-0003N1-B8 for qemu-devel@nongnu.org; Thu, 06 Aug 2026 10:13:25 -0400 Received: from mail-08.mail-europe.com ([57.129.93.249]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wryqY-0004Jo-GG for qemu-devel@nongnu.org; Thu, 06 Aug 2026 10:13:24 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=proton.me; s=protonmail; t=1786025589; x=1786284789; bh=NXSHtW8qDc7wlfrB+vA2ibpKtjZ1ya1mtVcYJ4jDhDo=; h=Date:To:From:Cc:Subject:Message-ID:Feedback-ID:From:To:Cc:Date: Subject:Reply-To:Feedback-ID:Message-ID:BIMI-Selector; b=E3xO4gIF7mG/YLcPHKsMFCb7tXx1pCFuLXpxaloHVPX06pHftbA5Mnnq+t9VZogL2 zKhk1tqf2XUE+91yDr0rIzkmzZx1bcTURiOqvppU1PS/J7npG1OZa+wEB6yRIiqn7i 1JtVAgEzKMfbaX53XypjJsbznNKRM79uFGVA1paxqs5qUKS77tfvZ7WHfxEPuhvxCG hfeSZkseqx67Ie16u3WlLIdNFCBnFxjZ3cFwAUfBq+Swmc7bof15koXl6GXxIG7ddB otW8tdbATCz3AIRJJ7p1aSNEQ9jIdoaTXyBfh3y/VNyj1Fjfawrkm+cU21Dary0d1N rvNERQC0EupGA== Date: Thu, 06 Aug 2026 14:13:04 +0000 To: "qemu-devel@nongnu.org" From: Feifan Qian Cc: "Michael S. Tsirkin" , Stefano Garzarella Subject: [PATCH v2] vhost-user: check memory slot availability for SHMEM_MAP Message-ID: Feedback-ID: 93226294:user:proton X-Pm-Message-ID: 8988a1035ba1feb76228ee663dfced85aeaf7a70 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=57.129.93.249; envelope-from=bea1e@proton.me; helo=mail-08.mail-europe.com X-Spam_score_int: -27 X-Spam_score: -2.8 X-Spam_bar: -- X-Spam_report: (-2.8 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @proton.me) X-ZM-MESSAGEID: 1786025643900158500 Content-Type: text/plain; charset="utf-8" SHMEM_MAP creates a separate RAM MemoryRegion for every mapping. It can therefore make a vhost-user memory table exceed the number of slots negotiated with the backend. Reject a mapping before changing the memory topology if KVM or a vhost backend has no unreserved slot left. Also validate each memory table against the negotiated vhost-user limit as a final defense for mappings that become visible in a later memory transaction. Fixes: b52e1896e764 ("vhost-user: Add VirtIO Shared Memory map request") Signed-off-by: Feifan Qian --- Tested with an ASan/UBSan x86_64 build and a vhost-user backend that filled the negotiated 512-slot memory table. The next SHMEM_MAP request was rejected and QEMU remained alive, with no sanitizer report. qtest-x86_64/qos-test also passed all 134 subtests. hw/virtio/vhost-user.c | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/hw/virtio/vhost-user.c b/hw/virtio/vhost-user.c index 2881cec72d..3673653f67 100644 --- a/hw/virtio/vhost-user.c +++ b/hw/virtio/vhost-user.c @@ -10,6 +10,7 @@ #include "qemu/osdep.h" #include "qapi/error.h" +#include "hw/mem/memory-device.h" #include "hw/virtio/virtio-dmabuf.h" #include "hw/virtio/virtio-qmp.h" #include "hw/virtio/vhost.h" @@ -1126,6 +1127,13 @@ static int vhost_user_set_mem_table(struct vhost_dev= *dev, dev, VHOST_USER_PROTOCOL_F_CONFIGURE_MEM_SLOTS); int ret; + if (mem->nregions > u->user->memory_slots) { + error_report("vhost-user memory table has %u regions, " + "but the backend supports only %d", + mem->nregions, u->user->memory_slots); + return -ENOSPC; + } + if (do_postcopy) { /* * Postcopy has enough differences that it's best done in it's own @@ -1940,6 +1948,7 @@ vhost_user_backend_handle_shmem_map(struct vhost_dev = *dev, VhostUserMMap *vu_mmap =3D &payload->mmap; VirtioSharedMemoryMapping *existing; Error *local_err =3D NULL; + unsigned int reserved_memslots; int ret =3D 0; if (fd < 0) { @@ -1980,6 +1989,15 @@ vhost_user_backend_handle_shmem_map(struct vhost_dev= *dev, } } + reserved_memslots =3D memory_devices_get_reserved_memslots(); + if ((kvm_enabled() && + kvm_get_free_memslots() <=3D reserved_memslots) || + vhost_get_free_memslots() <=3D reserved_memslots) { + error_report("No free memory slots for shared memory mapping"); + ret =3D -ENOSPC; + goto send_reply; + } + memory_region_transaction_begin(); /* Create VirtioSharedMemoryMapping object */ -- 2.43.0