From nobody Sun Jul 26 13:25:57 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1781289154; cv=none; d=zohomail.com; s=zohoarc; b=er2DVs7cDVp0peaotjmcHAhQ0CncUYAu+qzdsfDKlmUBSJ3grjK6yVl77XF0qjb4FROs6yTYP9jyJKXFQ/vgwYmkwISidKu7JdxVCC4BetOffN0AA6X3qr64FTGQD/wiNvJNRqI9maGBHOrYjbvIv03gO8n6U5Djz2JecRlvP8k= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781289154; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=LwNhhI3hE8IqgimhjcIWZMiFUZFgeoXrAM8FKvGMPZM=; b=CD+mXaW9c6BFdiHN7Wxc2JOF/pf1/YhD9JeNNY5PsSsBT03+HH3N+4byHytNdmr47S8mAPZ4hHv2LmcTx2n0p0rwE9lT93nsWTeoKdxVQeooKWeZocegkTB2cIQiPF0sJcudnHXStMkPYh9OpeonTg271mIlt8wja4XEyPgF1l4= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781289154464474.9728838825424; Fri, 12 Jun 2026 11:32:34 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wY6fU-0003Md-AP; Fri, 12 Jun 2026 14:31:48 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <7c4e53eb73c0580d7a321dbf3823ba5647652298@kylie.crudebyte.com>) id 1wY6fM-0003L4-63; Fri, 12 Jun 2026 14:31:40 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <7c4e53eb73c0580d7a321dbf3823ba5647652298@kylie.crudebyte.com>) id 1wY6fH-0000qj-43; Fri, 12 Jun 2026 14:31:36 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=LwNhhI3hE8IqgimhjcIWZMiFUZFgeoXrAM8FKvGMPZM=; b=ceXq2 Iu1T9ML0mHSY3V3SPuojr47Td0vR1gj/V+Fftr13yQ9ddGwxJ6T67Wv4b0opg1uKlp/r4knbp1ZJ4 qgLVvNM+AUGuovZbtMU7JqaZEujLEbn+bt/ESpZRiQm95dlDwYqeNjYUsXz3trf/yf575HInDoYh9 YK7ami/kh45/GkqqQPubn9/cZ1h6oQZ8HDVR365WL2wxcPppUHKYW4DRKJHZU8jqJHpvq++ZYYUqC Lqag1MFKzoFvX3sehdFiywPPJRRV8k2cfl1/gXlxQkmmbJZf51ZMN3eII7WBbrqalWhmQ/M6vquGW Qu0MwVNc9q0WdBLBfO0sdTUS0UDJOyDv5kWaav5pM2RUpvMIiwHmycjcLDyZzSGvBicXCGFZolV6t 7S3hAzeQKs0LV9tmaaxcCuUSS3jLvesArFEMXgiWK2kTFRcF3npgLLs6+EhsbcbhbnMhFx8jA0nnF 1nHG7eS5c/Wm3RYwiQ5X4n77zEaFfvpRDkyihvXsc4d9RKARCTYTfsBo5M4aBnwSLc8oE+QShzL29 TWgt7xrivoyLclrlHZsn3SPEX2Z5/CujQNTN6BWxSXB8xLmQN0FefBiVyZgE5DASyMNGAE4YtxOKw J6g8sMfjhIZ9xc4GhcnmInuQZql+uSLhwNr9mjaO/5HwUouX/6QG3+pEhoagWc=; Message-ID: <7c4e53eb73c0580d7a321dbf3823ba5647652298.1781287774.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Fri, 12 Jun 2026 20:22:52 +0200 Subject: [PATCH v2 1/8] hw/9pfs: add msize_limit transport callback To: qemu-devel@nongnu.org, qemu-stable@nongnu.org Cc: Greg Kurz , Feifan Qian , Stefano Stabellini , Anthony PERARD , "Edgar E. Iglesias" Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=7c4e53eb73c0580d7a321dbf3823ba5647652298@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1781289156707158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add a new callback 'msize_limit' to the V9fsTransport structure. This allows each transport implementation to provide its theoretical maximum 'msize' value, which will be used to cap the negotiated msize during Tversion handshake. Signed-off-by: Christian Schoenebeck --- hw/9pfs/9p.h | 1 + 1 file changed, 1 insertion(+) diff --git a/hw/9pfs/9p.h b/hw/9pfs/9p.h index 65cc45e344..14111e041a 100644 --- a/hw/9pfs/9p.h +++ b/hw/9pfs/9p.h @@ -481,6 +481,7 @@ struct V9fsTransport { void (*init_out_iov_from_pdu)(V9fsPDU *pdu, struct iovec **piov, unsigned int *pniov, size_t size); void (*push_and_notify)(V9fsPDU *pdu); + size_t (*msize_limit)(V9fsState *s); }; =20 #endif --=20 2.47.3 From nobody Sun Jul 26 13:25:57 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1781289180; cv=none; d=zohomail.com; s=zohoarc; b=VOLf5I5CfOkAfXYVWEcouDvXm55OKUUEHINn5aWcSLcUM4hlJDtfZ/ScyKKbCnF8SK8Y/096tgZZKVpa7M3YlcGaYW4MeCrTD5CjRd5bM0e3MZaq2CYi+XnqVoBU0q0IsvNRChPfwPEjJy0CsqzJfdE1shXIS6efUWMe8qao0XM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781289180; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=+XShxksSpz7jVIKWXrCLHZd5r7rA2GfVQktD6w9pGYI=; b=ff/u7prR69sEOp/KyfLVWRJqlDzk1QTSDYIUCMscXLu9y7rkEa3iCRtPWqUauJeWsg6siCKOrKQagZQ5bVLmu7UxS6dklNIv0Sf2iLljKYnjicQdH9RsZzPCNbpVxqBjpt4Y5WIBuAu09yWMJ3iGf4oB2RDy4WgEgk9T2VN23SE= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781289180147275.06480818102557; Fri, 12 Jun 2026 11:33:00 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wY6fT-0003M7-AV; Fri, 12 Jun 2026 14:31:47 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <4c34426bc906e19423e7e2389c419c2e972d9b9b@kylie.crudebyte.com>) id 1wY6fQ-0003LO-4i; Fri, 12 Jun 2026 14:31:45 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <4c34426bc906e19423e7e2389c419c2e972d9b9b@kylie.crudebyte.com>) id 1wY6fN-00014u-W0; Fri, 12 Jun 2026 14:31:43 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=+XShxksSpz7jVIKWXrCLHZd5r7rA2GfVQktD6w9pGYI=; b=mB0CO 0nmWuqvh7G+Lval3x2s8JW4NAlEE1SQXlwxBHU+PsfzCo+Fi5Nbm3H8lNv+YXZcg8OAyBIlHnKQfB ETVkeSPuAfV9/t4BFA8+UIxnAIPTyQvA5gUL8ytbiwaoaAdBd+Y0pYtWXjKY2BMlZE2J5m9aiKm9/ ohzgXcL9OZPMjHS1VGU9e+6WGuCiM+xEDbdy/GhJPuF/ypRna04q2aI92/gC3EnBDKWMW/taNVwIg a1/j6Ppv0xYnHIKDuqyxx2nsixZBucIMCk2bRMxm2Z2DKh+BVBZAugcXAic2Jct2elG1OsKDfZ3xd BfMzP1cNRcy7GoxUsx6I753bxwNRPOXL/xiMK9TsNwWx+OQ5h2ZtsN/dv7VTdVzH3YS/YtgHOYKGK vea64lGg+Id1yC/Cy00ImGLWCw2GcTvorBcL+8NdJZez5m3jN0Os+TJpfWcOYdnc2nRAUam7p2PRl HVLiuBaDYArBdX5nsjTU6meu3g9SkmL9Ao2rPsZvDOX7e9gId9BJyFXoGdtlX0tLJSbH/Bj9bUGC7 F620FCymSoUv/ScIx654YXH+YwMehTmgRXjNdbZno2yJWyktdjWbf6x9phmLWp8CnacvuTiT0aoeF yIiULXMekzdcsTYjz78Px4GYf0QRaT7CD1xQa+Js4lFfmOYNNTjXLUd3OrMzzA=; Message-ID: <4c34426bc906e19423e7e2389c419c2e972d9b9b.1781287774.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Fri, 12 Jun 2026 20:22:52 +0200 Subject: [PATCH v2 2/8] 9pfs/virtio: implement msize_limit callback To: qemu-devel@nongnu.org, qemu-stable@nongnu.org Cc: Greg Kurz , Feifan Qian , Stefano Stabellini Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=4c34426bc906e19423e7e2389c419c2e972d9b9b@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1781289182662158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add and implement the msize_limit callback for the virtio transport. This new callback function provides the theoretical maximum 'msize' value supported by this virtio transport. The limit is calculated as (VIRTQUEUE_MAX_SIZE - 2) * 4096 bytes, where 2 virtio descriptors are lost exactly for: - 1 descriptor for the original request (typically being small) - 1 descriptor as indirect table pointer (when used), which just contains a pointer to the separate sglist containing the response's actual payload data And 4096 bytes are assumed as standard page size used by Linux 9p client. This results in a maximum 'msize' of 4186112 bytes. Theoretically Linux client could support a much larger size, e.g. by using multiple consecutive pages per sg entry / descriptor. However that's currently not the case and unlikely to change any time soon. And due to recent security issues, let's handle this limit conservatively until really necessary to be raised. Signed-off-by: Christian Schoenebeck --- hw/9pfs/virtio-9p-device.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/hw/9pfs/virtio-9p-device.c b/hw/9pfs/virtio-9p-device.c index 9f70e2338c..8c5d86cb66 100644 --- a/hw/9pfs/virtio-9p-device.c +++ b/hw/9pfs/virtio-9p-device.c @@ -192,12 +192,19 @@ static void virtio_init_out_iov_from_pdu(V9fsPDU *pdu= , struct iovec **piov, *pniov =3D elem->out_num; } =20 +static size_t virtio_9p_msize_limit(V9fsState *s) +{ + const size_t guestPageSize =3D 4096; + return (VIRTQUEUE_MAX_SIZE - 2) * guestPageSize; +} + static const V9fsTransport virtio_9p_transport =3D { .pdu_vmarshal =3D virtio_pdu_vmarshal, .pdu_vunmarshal =3D virtio_pdu_vunmarshal, .init_in_iov_from_pdu =3D virtio_init_in_iov_from_pdu, .init_out_iov_from_pdu =3D virtio_init_out_iov_from_pdu, .push_and_notify =3D virtio_9p_push_and_notify, + .msize_limit =3D virtio_9p_msize_limit, }; =20 static void virtio_9p_device_realize(DeviceState *dev, Error **errp) --=20 2.47.3 From nobody Sun Jul 26 13:25:57 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1781290881; cv=none; d=zohomail.com; s=zohoarc; b=d0FcZllxZm5iacsdJlhOImK1qcBNj4dId3XEwMUEZ8E/iMwhqPNw9dwBLwgEMnwvL2SgFSpIJhaBqFUUQ4qf67S5L8t+EBQbwo9PYMmjYhKRsZ4GIZbBIA7tIm26DbvcM7oI6WV3tJRfKnvXPDfLi12zFeRqGeCl1/AyV9m2BCE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781290881; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=C2I/oAnjmmS/23juNsNQKAlgvmKnqj9OP4tqoHgG1e0=; b=h+aT/Q/T6fc20MkalIe3NB1KGvdZ8zkaZsfRrzoOVLgozEA/5ZiyNTTxN+CUoniJtsLjkYDJ7g/J3kQqD+3BgHaf6d36Gvo30pEZK9kbSwDn0fqP5JVTJ7vTUbLmSZ43vQqPWR8d9gqIY+afDNNMV4DGBnZN4hicWL05FUlrBBk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781290881221624.5737343954444; Fri, 12 Jun 2026 12:01:21 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wY777-00017Q-J1; Fri, 12 Jun 2026 15:00:21 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <9471786bc47b93e822f6c6233a83f2b9f61e6c82@kylie.crudebyte.com>) id 1wY775-00016i-JX; Fri, 12 Jun 2026 15:00:19 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <9471786bc47b93e822f6c6233a83f2b9f61e6c82@kylie.crudebyte.com>) id 1wY774-0000IN-0K; Fri, 12 Jun 2026 15:00:19 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=C2I/oAnjmmS/23juNsNQKAlgvmKnqj9OP4tqoHgG1e0=; b=JE/ms YFb8pgmOE/NVeGu7bVc5DUD9wNAosspTE8MxpCRnpISmVdCtsxTZpa6ET+HlfNaJwmlCBoBEoBmBc 5aIBRiPtqLJJn3WqUztWna/Bz5LsIIrCiiQ9czVl+NKb2jlY1O9itKzhSAuIY4mORu8zT4JrvbQA0 +sHwmUtmijKF/NFymXMQ2uBT4boKemiHM0CXo+2J+CCXqzMt0oLIVr7BBESXPuDDoqbUMMgCW3zyh 3EdkrE0EKAffjkeDhfgfbCrliDSYvga6ycZLMQrlRDwOFNA67I1j1tmHbel9E/HP3J4SDwwLgXZcY AgBdkFmd92qLs0Z/6NFOWx76biZBgOcRpBqoy2Y+edDrLZUwAV7f+feJ1fAKkiVO7V77ADJoVOsDo 9jvR/7lVDsG6fKjqzCDHSwhA5JyRzOG9XQOgOKS2kTVOhE6cKIOXjO48oj4ZaGqgzxqgMIqwzTK5V 5y+jNHB97CFVE3ej+xNdYofgeb6cnr31z4/mej0YORuiXYMdt4m1oz8ZUUlhyQIkk9EHgDyK3CP/2 jUvncGt4bnZ3u+Dfbhk6NDgJ26ec8/CRYNKEdJNvcNKARmuOV59o1iv9031KLXxvsySZybmAYGcdd 5X7wpQIxWsvOB7qkwUyQ1R37PkF07fQIG54kqi8/ohc2iWuS/hrZcIJ1iD6OuI=; Message-ID: <9471786bc47b93e822f6c6233a83f2b9f61e6c82.1781287774.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Fri, 12 Jun 2026 20:22:52 +0200 Subject: [PATCH v2 3/8] 9pfs/xen: implement msize_limit callback To: qemu-devel@nongnu.org, qemu-stable@nongnu.org Cc: Greg Kurz , Feifan Qian , Stefano Stabellini , Anthony PERARD , "Edgar E. Iglesias" Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=9471786bc47b93e822f6c6233a83f2b9f61e6c82@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1781290881641158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add and implement the msize_limit callback for the Xen transport. The limit is calculated using XEN_FLEX_RING_SIZE() based on the negotiated ring_order. For the theoretical maximum ring_order of 9, this results in a maximum 'msize' of 1048576 bytes (1 MiB). The minimum limit of all rings is picked, because multiple rings could theoretically have different ring_orders. Signed-off-by: Christian Schoenebeck Reviewed-by: Stefano Stabellini --- hw/9pfs/xen-9p-backend.c | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/hw/9pfs/xen-9p-backend.c b/hw/9pfs/xen-9p-backend.c index ca0fff5fa9..e31124bcf5 100644 --- a/hw/9pfs/xen-9p-backend.c +++ b/hw/9pfs/xen-9p-backend.c @@ -250,12 +250,31 @@ static void xen_9pfs_push_and_notify(V9fsPDU *pdu) qemu_bh_schedule(ring->bh); } =20 +static size_t xen_9p_msize_limit(V9fsState *s) +{ + Xen9pfsDev *xen_9pfs =3D container_of(s, Xen9pfsDev, state); + size_t limit; + int i; + + if (!xen_9pfs->num_rings) { + return 0; + } + + limit =3D XEN_FLEX_RING_SIZE(xen_9pfs->rings[0].ring_order); + for (i =3D 1; i < xen_9pfs->num_rings; i++) { + limit =3D MIN(limit, XEN_FLEX_RING_SIZE(xen_9pfs->rings[i].ring_or= der)); + } + + return limit; +} + static const V9fsTransport xen_9p_transport =3D { .pdu_vmarshal =3D xen_9pfs_pdu_vmarshal, .pdu_vunmarshal =3D xen_9pfs_pdu_vunmarshal, .init_in_iov_from_pdu =3D xen_9pfs_init_in_iov_from_pdu, .init_out_iov_from_pdu =3D xen_9pfs_init_out_iov_from_pdu, .push_and_notify =3D xen_9pfs_push_and_notify, + .msize_limit =3D xen_9p_msize_limit, }; =20 static int xen_9pfs_init(struct XenLegacyDevice *xendev) --=20 2.47.3 From nobody Sun Jul 26 13:25:57 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1781290868; cv=none; d=zohomail.com; s=zohoarc; b=IgzYTRhk9vSBUAY13YZoTIOd8lZQe3JLu4GZycdg7pZIaZCVdVFnHG5zlJIU1lX+BSOuWBuBIHlg8rid+c3kWMtu26blwPEajvkjZw+vVolvjxA0ZzaQZrqDgCjuqXx+0AbPXrMPjZItCp6TVNz4DpKC6+lFx71ZR2AaKfchLm4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781290868; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=EdZ3qDjoTlsu0Vpm6oK1beSP8+9sfvWnMcVTHk6OlsI=; b=UbGr4w0WPIovzerBGDFvPwtMW2rAXQZPof8OjtpVgMNukqJm442lSKIYDw2YF6ErtsQmEe0njENNaO5pzH3COX3jlnka8Iga8NQOPv3XkFmrf1ky6PvstOMfig44Um+vhqu+omi1X8Nslcy5g1U3bA02CCXhox8+rM3bJY3eEC8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781290868139583.9150855239043; Fri, 12 Jun 2026 12:01:08 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wY77G-0001Al-5B; Fri, 12 Jun 2026 15:00:30 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <2105e9a3578c6f751bb64af55c16dd953f393f20@kylie.crudebyte.com>) id 1wY77E-0001AT-RI; Fri, 12 Jun 2026 15:00:28 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <2105e9a3578c6f751bb64af55c16dd953f393f20@kylie.crudebyte.com>) id 1wY77D-0000LE-DD; Fri, 12 Jun 2026 15:00:28 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=EdZ3qDjoTlsu0Vpm6oK1beSP8+9sfvWnMcVTHk6OlsI=; b=WdsRK th2+EZcmBKwGsMSsdNz/cR7TbjWd5zMFKyTgdhp1s/Tkm2pWeTOBWHgCOrdQqhRuWAWk/v+Dxt/S5 b1/XrOYo/AN0KrvSsjO8OEzAJFYMZf0IqX5y0VpKIu4zLxd2FDzj2lv1YHVIoFZLnhpFyEmrt0jM9 1BNvPThKR+tTULt61IowZmWrhwNr1VlPhGla8kckppjRZp0b5iS8SmXdaSzfeBUld6Yu8cvF+hpoj RP2/t73OwvZkN+X0y/V74tocxMrUUlMIMHJVYuy3N9fxGxPTLJLp/tKXEwTsUcuJC9nBkovKFwIF7 Bb9fd3L2oKblZFhNWnVg6q3eH4044wKPcDLgHCZzNEO8o2Wzhp8I/L5vkNfQ8DVWxplDGyYN5dxly r79YV83vgWgkbN8ZHAWIfAZZBWd0KKT3QuEM8BTNwihggHyGA3pdg47yLmRFLKzYklLEqQITTfSzK uROlclKQX66UxrXXnx2yDSGe7jNItiicpppF0StGM+U1zQIyqNLDFTKuAc6sJPoeeCZCHU0xELfVS hPQXr/+rGGcB4jjn4pQhJw2RSm+K10u5SWvcAX5iErdl/ZpGF6Q6XamTa18579o979Tln+IXAPQJH lrj1SfMoXP6RZ7We0L+GdhNO2qXl6SL54rMUGCrKHANmizS75jGM+ocZ1+qxLI=; Message-ID: <2105e9a3578c6f751bb64af55c16dd953f393f20.1781287774.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Fri, 12 Jun 2026 20:22:52 +0200 Subject: [PATCH v2 4/8] hw/9pfs: cap negotiated msize to transport limit To: qemu-devel@nongnu.org, qemu-stable@nongnu.org Cc: Greg Kurz , Feifan Qian , Stefano Stabellini , Anthony PERARD , "Edgar E. Iglesias" Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=2105e9a3578c6f751bb64af55c16dd953f393f20@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1781290869768158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" The 'msize' parameter negotiated during Tversion handshake can be arbitrarily large as requested by the guest. So far 9p server accepted any msize value suggested by guest, i.e. server did not cap it at all, no matter how large, as in practice the upper limit of msize is a client capability. But as subsequent's security patch shows, capping msize on server side makes sense as additional safety-net. Let's cap msize to transport's theoretical limit for msize, mainly to prevent a bad client from triggering excessive host memory allocations throughout the session. We intentionally don't cap msize to transport's current, real response buffer size, as the response buffer size may vary between individual requests. Signed-off-by: Christian Schoenebeck --- hw/9pfs/9p.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index e2713b9eee..2bb42dfc2e 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -1456,6 +1456,16 @@ static void coroutine_fn v9fs_version(void *opaque) goto out; } =20 + /* cap msize to transport's theoretical limit */ + if (s->transport->msize_limit) { + size_t limit =3D s->transport->msize_limit(s); + if (s->msize > limit) { + s->msize =3D limit; + warn_report_once("9p: client msize capped to %zu (transport li= mit)", + limit); + } + } + /* 8192 is the default msize of Linux clients */ if (s->msize <=3D 8192 && !(s->ctx.export_flags & V9FS_NO_PERF_WARN)) { warn_report_once( --=20 2.47.3 From nobody Sun Jul 26 13:25:57 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1781290893; cv=none; d=zohomail.com; s=zohoarc; b=UXfRCEadE/mVT+WFiF6mU9p3lLemV9mF3etU6Y7GNhxsz8g6XcDhzkkhKrBDKoNlVoX6HU4cOjKlKLRTmBma3VKJpPrlzbOtXbOYSadgPLqZF1I/tANilOMfh6zjTjndUs4UFmPAyiAaeUhhGY5d8Uv42V8RbLqXoNQt/eqY92A= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781290893; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=nz0jGzs/Ah602Nv6FwI476PLtl2CK7ANoNulNygqAu8=; b=GzvG+QMWCkcp9CmAjlMwk8RBg4iuIleadTuH9nTU2rltEgE96O69KbRXD68tslBF1/6ONvFYdj81wJJIvsuU4iTdoPpUMTYASAHACBL/bsC0XsHgfILjsHmbXZsGuz8h7axMylCu7uYYPQeUcwMtnB9zFcxiHGtNV8y12keoRW8= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781290893667548.1018659387667; Fri, 12 Jun 2026 12:01:33 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wY77D-00019f-9P; Fri, 12 Jun 2026 15:00:27 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <703ed8ce4401c4550ef2cd99f30ab808665d6e85@kylie.crudebyte.com>) id 1wY77B-00019R-Tp; Fri, 12 Jun 2026 15:00:25 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <703ed8ce4401c4550ef2cd99f30ab808665d6e85@kylie.crudebyte.com>) id 1wY77A-0000Kp-Ge; Fri, 12 Jun 2026 15:00:25 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=nz0jGzs/Ah602Nv6FwI476PLtl2CK7ANoNulNygqAu8=; b=Y+cH1 4RWz6YpD7zUDMBFk5RF91u1wsXKwVl9CO4MLfyFxCaObuCW/y+M8/xZJ+yjOwq6Me8RL//Y7kfCcE WIfk8g0/sw4jfu1j+1WZq5VbOWUCjOEgAAteKR0oj0CS3sT8a7WpdhHkfC4qw8ruLs+nun3YJg0Vt WPfRCYRnJ8J+BGUrDkDo6qS+luAdte6ggFjq0mg4Kz99MrdsUw/DeKZzgGOa9MIl5JXEgoQqSrFaJ t2d0fi5usAkEQ/ZmnphCtI2f499AIcVjq2Dw05DgPczFUk31EKyC51vpiXQidn1neWpfJPag2x18J pGeU1IqleDkJvLYmouuqNlJUWhoAFY3sM7X22YTcnW9RdmwbyJVKRjHr/j1SZK/YN3O+3sRQ1VPp8 XUnxcJO3uTEwae4QlIobo/eKBx1N1Ft0NrbzXJAuOvJpy1JaaF08qDe66+y+KEzc5Xi+0PWDJhOwL uxCbTd+ZSWKVX7B+9yGySIT4QxVU9ScVsdxwyQ+geyN5z5miCO2FzStAmssEDc8+ECJsr0NO4ZRaq nei/q6+7SEboYy8CWJ6E3AWdqhFCqToymgf64s/zIaLbsL8O88aJ+vEC+Kmwfbppph2Fc3KdolTxH KyEOPGHRphVLCKrqokEsuJOmyTNKvOPsCnQJ/axtpUe+3HN/ft1hCBPLevq5Yo=; Message-ID: <703ed8ce4401c4550ef2cd99f30ab808665d6e85.1781287774.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Fri, 12 Jun 2026 20:22:52 +0200 Subject: [PATCH v2 5/8] hw/9pfs: add response_buffer_size transport callback To: qemu-devel@nongnu.org, qemu-stable@nongnu.org Cc: Greg Kurz , Feifan Qian , Stefano Stabellini , Anthony PERARD , "Edgar E. Iglesias" Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=703ed8ce4401c4550ef2cd99f30ab808665d6e85@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1781290895801158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add a new callback to the V9fsTransport interface that allows each transport to provide the real size of its current response buffer. This is needed for subsequent safety guards that will limit generated responses appropriately before trying to allocate, generate, and send a response to guest. This is especially required for request handlers that need to allocate dynamic and potentially large host memory for generating a response. These safety guards are mandatory to counter bad clients that try to trick server by supplying response buffers being smaller than the previously negotiated msize value. Signed-off-by: Christian Schoenebeck --- hw/9pfs/9p.h | 1 + 1 file changed, 1 insertion(+) diff --git a/hw/9pfs/9p.h b/hw/9pfs/9p.h index 14111e041a..1efe000f6f 100644 --- a/hw/9pfs/9p.h +++ b/hw/9pfs/9p.h @@ -482,6 +482,7 @@ struct V9fsTransport { unsigned int *pniov, size_t size); void (*push_and_notify)(V9fsPDU *pdu); size_t (*msize_limit)(V9fsState *s); + size_t (*response_buffer_size)(V9fsPDU *pdu); }; =20 #endif --=20 2.47.3 From nobody Sun Jul 26 13:25:57 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1781290842; cv=none; d=zohomail.com; s=zohoarc; b=E7rKmv2L5ev50aorZkjr+5QaVIMQ6RjkZ+xtDtd/FXQxwbfpPgkuMIVESy9B+gHQIvuAewb5gSEVZJVEKcWMiS39Bkuee81BIm3cBMVpwN4fohAJmi+sgh2eYgKLfx0eHr+OGW6yUB4qPU7LklcaujQW37BvNqykJIWiq28N6H4= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781290842; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=alpHi4/PFoi3yPOlBsVk76F8rFaLq0t1rgSAqoTTaO0=; b=klTfMDbUPbYBnqkaRKYKXz86yjatP6O21Urbl4n9aLMzd228o4cY4EhKEueZIjtG2qWS9ye2DTfRY9ry/2OOA5ip7zl4SDLvlqSuf9v9QN4nI3QRZcuT61xG/SuminGNNrnNW0/N7bHVxgjfQ2comhUX6gCfZ5ehOPo4W8Q5UbM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781290842147714.7547312461958; Fri, 12 Jun 2026 12:00:42 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wY770-00012H-3n; Fri, 12 Jun 2026 15:00:14 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <5bbed2768f7a0da8fa2be183e75928c5d1ef691d@kylie.crudebyte.com>) id 1wY76x-0000zO-No; Fri, 12 Jun 2026 15:00:11 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <5bbed2768f7a0da8fa2be183e75928c5d1ef691d@kylie.crudebyte.com>) id 1wY76w-0000GH-3L; Fri, 12 Jun 2026 15:00:11 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=alpHi4/PFoi3yPOlBsVk76F8rFaLq0t1rgSAqoTTaO0=; b=Gm2kf hqn3dvIZ0idm9wVpTrQwQwLr7ldCj0xjkf/MUaxXRFrNOlTjBWI4yteYg8zZD6yKoTa7Qy+Tcfer5 YyIWOuSIIi/9sqviu/adFfoGL+5aj8SNzFZwDBCXU/hnBs/Qt6/KDo2VaJoUMl456axgJNYuMo/mM yK3gHfuS/HZxx0v50m1NlVtxXKIC14NuPpKNP4TY/gxx+T7m4zTqqy6OOWmMmRzx/vkcUxCxrIhOP 3iKJuYSyDmt4acJmGRlh3SCCjp2H3rAsb6Yt48qud1p15n/M/wZaSgYe4N53c70Mf67YsdHUmwuEC TEwIBcE0LQDzMv89UyUB4QiLv0hVamUvDSEDgcvX7ISH7v34gwwdwdchxmm7b34ALuGkcrTmctmfb O0Of9vV+jtt233QBOnaPLl3OXb0tMJukxwKZMl43/BNEeSad7a+1ZQ64xp9WaEL03HkQ5C76zQcGd GeiQN1rgduiVvJL+ud1EYZs66jloGHgWqefDFMDEQyBbNKcSc9MQeI3Yj3/XUraQOrjvT46Ug/Ymt aqqLkiiORGp699wsScEL7jD5ndCnCAjBaZ692ToYaPOq27x4lm92g13wxgD0Kde2uO/wyL4afgYNj Ebyj1y2w2ld5rphV99q86ogcT/+DLG2BJXqf+5PpLhU60qFzzUH6D7ChAV3Cck=; Message-ID: <5bbed2768f7a0da8fa2be183e75928c5d1ef691d.1781287774.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Fri, 12 Jun 2026 20:22:52 +0200 Subject: [PATCH v2 6/8] 9pfs/virtio: implement response_buffer_size callback To: qemu-devel@nongnu.org, qemu-stable@nongnu.org Cc: Greg Kurz , Feifan Qian , Stefano Stabellini Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=5bbed2768f7a0da8fa2be183e75928c5d1ef691d@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1781290843188158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add and implement the response_buffer_size callback for the virtio transport. Returns the actual current virtio response buffer size for the supplied PDU, which will be used as safety guard for limiting the response size when generating a 9p response. Signed-off-by: Christian Schoenebeck --- hw/9pfs/virtio-9p-device.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/hw/9pfs/virtio-9p-device.c b/hw/9pfs/virtio-9p-device.c index 8c5d86cb66..50dc93091d 100644 --- a/hw/9pfs/virtio-9p-device.c +++ b/hw/9pfs/virtio-9p-device.c @@ -198,6 +198,15 @@ static size_t virtio_9p_msize_limit(V9fsState *s) return (VIRTQUEUE_MAX_SIZE - 2) * guestPageSize; } =20 +static size_t virtio_9p_response_buffer_size(V9fsPDU *pdu) +{ + V9fsState *s =3D pdu->s; + V9fsVirtioState *v =3D container_of(s, V9fsVirtioState, state); + VirtQueueElement *elem =3D v->elems[pdu->idx]; + + return iov_size(elem->in_sg, elem->in_num); +} + static const V9fsTransport virtio_9p_transport =3D { .pdu_vmarshal =3D virtio_pdu_vmarshal, .pdu_vunmarshal =3D virtio_pdu_vunmarshal, @@ -205,6 +214,7 @@ static const V9fsTransport virtio_9p_transport =3D { .init_out_iov_from_pdu =3D virtio_init_out_iov_from_pdu, .push_and_notify =3D virtio_9p_push_and_notify, .msize_limit =3D virtio_9p_msize_limit, + .response_buffer_size =3D virtio_9p_response_buffer_size, }; =20 static void virtio_9p_device_realize(DeviceState *dev, Error **errp) --=20 2.47.3 From nobody Sun Jul 26 13:25:57 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1781290840; cv=none; d=zohomail.com; s=zohoarc; b=I+a6enrupftDmjzgGQPhzoJUhdlP5c9HKtLgpc4EBsSNdYofGC5bu6sxymaWBnHZmP/a5zOtEOwHHuz2K7JFk2N+xNakJA9ijFJ5ypsIXdkDpt2+y9ebjCS3V/jHn8ssEro+BKc4KWSpXdlyfEDENOjRlNEfqCYO8ji/qCD1yCg= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781290840; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=YloPe28xGJlncaABfmiARrLOQS4xgd2vL+jt3ecEHEQ=; b=mQCCdV64GHF1+v1MZ7QI0hv7u68JTRwlrnqywD5/RkB/BOZMWs9pjpdqP2YX1Ie153paE5qI40siAgODkUWfHnWl5SpdU2iLLhzMi/47fPCVXtzbYqmX5FXmFFn1pvuWhaKNHr+VmtOjmjwkZy2ERcVByQqlrYPFbE17N77MUDM= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781290840696567.9230664568391; Fri, 12 Jun 2026 12:00:40 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wY76t-0000wS-8O; Fri, 12 Jun 2026 15:00:07 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <3b139769eb1d3f9d91ee5281228e6467f9a08b99@kylie.crudebyte.com>) id 1wY76s-0000wC-Io; Fri, 12 Jun 2026 15:00:06 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from <3b139769eb1d3f9d91ee5281228e6467f9a08b99@kylie.crudebyte.com>) id 1wY76q-0008V7-WD; Fri, 12 Jun 2026 15:00:06 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=YloPe28xGJlncaABfmiARrLOQS4xgd2vL+jt3ecEHEQ=; b=vxJGU 7FrGbt1RmrRor5NfrF9q4xt2mH5Qk/JnNVTJ2HLAsa1a27y0xwQrmEYjoSi9cWuzxo/p5EAdh6QWQ rLYdzAL7I2qQLHHmogjvLwaiSba+HyfG2wzWvvm2GuImqLmstE4uPwXDfxP+rpTukHWUgq5u8O80o gZi8WHfR03wSaTQgLQ/uGFPqAQltdVIrsjKAOoFDKgyzvUbBcWRem00PyWZTc6ysfyLWfnVayclRv Syfw+ClRmrZR2H0HoFkcgJ9nSjerJafaziDO5wRo43NG5fM+TCZAbgyaAtoZx6K4um9uCoONG0RkT 7Qh5cBgCykOsg4l0pPzmBNVjZmPsGKKuJYjVx3xE3qQ92rPDDS2BwRJfIHb9w+K8BreB9kr06VQ4t JZXwGgKyguxlBQez2eVsVK8u4sPg2V0fkUaLhK0s0bihYtD1b6mKlZBz3EN5ggybg2YfY8fb8nyxP nw4dXo7r/IPYbRw3Cg/x8LuGLu8lNMwZqHWI6DMr/R0/SVvLkoF1DtzyWaeRjFa+CIswrRiSylPih T8O0k0LErZzRPieNyNuUgqoYfmUdJzcshN8FxlFk/pMxJQi4esLhI81zrEJoeJzbidNxk86KYotsY N0o0rOY9E06apJ2meYt4sHnkt+V498Vk+I4Ca2+GQ2elzs0MWVoq5ZoM7oR1tc=; Message-ID: <3b139769eb1d3f9d91ee5281228e6467f9a08b99.1781287774.git.qemu_oss@crudebyte.com> In-Reply-To: References: From: Christian Schoenebeck Date: Fri, 12 Jun 2026 20:22:52 +0200 Subject: [PATCH v2 7/8] 9pfs/xen: implement response_buffer_size callback To: qemu-devel@nongnu.org, qemu-stable@nongnu.org Cc: Greg Kurz , Feifan Qian , Stefano Stabellini , Anthony PERARD , "Edgar E. Iglesias" Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=3b139769eb1d3f9d91ee5281228e6467f9a08b99@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1781290841770158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Add and implement the response_buffer_size callback for the Xen transport. Returns the size of the response buffer from the rings in_sg, as limit for 9p server while generating a response for supplied PDU. We use a local iovec array variable in_sg[2] instead of ring->sg, as ring->sg is only allocated by init_in_iov_from_pdu() and init_out_iov_from_pdu() during request / response processing. response_buffer_size() however may be called before those allocators, which would dereference ring->sg as NULL pointer. The local array avoids this. Signed-off-by: Christian Schoenebeck Reviewed-by: Stefano Stabellini --- hw/9pfs/xen-9p-backend.c | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/hw/9pfs/xen-9p-backend.c b/hw/9pfs/xen-9p-backend.c index e31124bcf5..24c90d97ec 100644 --- a/hw/9pfs/xen-9p-backend.c +++ b/hw/9pfs/xen-9p-backend.c @@ -268,6 +268,17 @@ static size_t xen_9p_msize_limit(V9fsState *s) return limit; } =20 +static size_t xen_9pfs_response_buffer_size(V9fsPDU *pdu) +{ + Xen9pfsDev *priv =3D container_of(pdu->s, Xen9pfsDev, state); + Xen9pfsRing *ring =3D &priv->rings[pdu->tag % priv->num_rings]; + struct iovec in_sg[2]; + int num; + + xen_9pfs_in_sg(ring, in_sg, &num, pdu->idx, 0); + return iov_size(in_sg, num); +} + static const V9fsTransport xen_9p_transport =3D { .pdu_vmarshal =3D xen_9pfs_pdu_vmarshal, .pdu_vunmarshal =3D xen_9pfs_pdu_vunmarshal, @@ -275,6 +286,7 @@ static const V9fsTransport xen_9p_transport =3D { .init_out_iov_from_pdu =3D xen_9pfs_init_out_iov_from_pdu, .push_and_notify =3D xen_9pfs_push_and_notify, .msize_limit =3D xen_9p_msize_limit, + .response_buffer_size =3D xen_9pfs_response_buffer_size, }; =20 static int xen_9pfs_init(struct XenLegacyDevice *xendev) --=20 2.47.3 From nobody Sun Jul 26 13:25:57 2026 Delivered-To: importer@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass(p=quarantine dis=none) header.from=crudebyte.com ARC-Seal: i=1; a=rsa-sha256; t=1781290904; cv=none; d=zohomail.com; s=zohoarc; b=aj4LWoGOvLPuaXkF4bkxUSI4BMs/GvkQOJqdl8zOXih2lRLtseJ1nZ6wVOTH5rV+khtC7HZnAHNLgYrcqolPl2UOqrAm/FOR2FMZTtVHQUfxp48w1bO2OfPBjX3XWYTUl5m04rgeTXWoS6YhexzabRtv+DnQsNF3CwIFH1kfaC0= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1781290904; h=Cc:Cc:Date:Date:From:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:Message-ID:References:Sender:Subject:Subject:To:To:Message-Id:Reply-To; bh=9Ly3p2SFfCcPy7GWSz0ag36rm1I3UTgEr6JUOkLsvo0=; b=SuYBMsExhBgfdaL8x2FJUazwaJ+j5Q2iA71/XG3nZ6Gbj+ago+D/UFlJCRuIMk+1Uesg8GkXZV1z+URFMYK3wmSftMPUZ0wBZCB/OR4LsLEhgwsZ8csyumJqoNEiA/JoJZv17j0p44CZfz23rUQ1JFZwTBqnHY/JKYVAkH+sTts= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org; dmarc=pass header.from= (p=quarantine dis=none) Return-Path: Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1781290903843953.6742894737821; Fri, 12 Jun 2026 12:01:43 -0700 (PDT) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1wY77A-00018v-FR; Fri, 12 Jun 2026 15:00:24 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wY779-00018F-2i; Fri, 12 Jun 2026 15:00:23 -0400 Received: from kylie.crudebyte.com ([5.189.157.229]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1wY777-0000KS-Gb; Fri, 12 Jun 2026 15:00:22 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=crudebyte.com; s=kylie; h=Cc:To:Subject:Date:From:References:In-Reply-To: Message-ID:Content-Type:Content-Transfer-Encoding:MIME-Version:Content-ID: Content-Description; bh=9Ly3p2SFfCcPy7GWSz0ag36rm1I3UTgEr6JUOkLsvo0=; b=ie23g c5my1j2/cPK6iMLYZECRLwPkenNb6BsQZ7HYYH3GDf28pa6DB+M88MPuXNP5xYJhq08MuhskJPUlI y1atL5wQ/N0TL9RgiTbyFREU9OwT75YX38YB/bVnEio9nRpYZm0R8qZPWbpKfYP2PDmkswszOp5X9 Om7AeY+lJuxQEYfumQwJMaZSAWOWhuLi3xISWgDQ0Tz3I4f1Vs0aF3hdl+4OLFbOYv3z41f2AvET5 7mLQ2bIIxJB51RSPtVLMNNR8uraD0J3VGyw8xJmSRrGu1IFsyXCayRWUbBbbfWvFpmr8syOrHdYXa ly5a8Z3/BweOhUqk0BWSN6kcieebVuW+ldji67Zd2EHY2X5AVjxLDeBIcdBTiuXFJytlFpyYI5K/x Xrc6dUTXUm/cp7VWXX/h+qCqbFWhdJWm/w8u9TcRwCaYgNObbGdhRduON4Q8Zdsz3vMnDzq+usPOn JNXNtSTlOu9SwEPm3zOxPBrouK+fx6iXTM01jmIqlF5DEh44DzyRPQqvKtFz1xhvRCQPPdJyr6emd 1tqwXulhzoiDhGIKS3IiVuN/I9OOjljL/XIKl/dfav2RSEFX28zGdsXGyBRZMqd3OqOhLtr9Apq2E RuVCKu/chlUpaHHV6KxrpGZJRHSeFOr4nJltiDPcpV8BMidtsHyzP/UmA16eS4=; Message-ID: In-Reply-To: References: From: Christian Schoenebeck Date: Fri, 12 Jun 2026 20:22:52 +0200 Subject: [PATCH v2 8/8] hw/9pfs: cap Treaddir allocation (CVE-2026-9238) To: qemu-devel@nongnu.org, qemu-stable@nongnu.org Cc: Greg Kurz , Feifan Qian , Stefano Stabellini , Anthony PERARD , "Edgar E. Iglesias" Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists1p.gnu.org; Received-SPF: pass client-ip=5.189.157.229; envelope-from=f81a387a2de4f2172fd5830c5654f49d78102254@kylie.crudebyte.com; helo=kylie.crudebyte.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @crudebyte.com) X-ZM-MESSAGEID: 1781290905702158500 Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Constrain max_count in v9fs_readdir() to transport's current, real response buffer size before calling v9fs_do_readdir() to prevent excessive host memory allocation for specific, crafted, huge directories (large amount of entries) by bad clients. Client may send a Treaddir request with a large 'count' parameter, and while the negotiated 'msize' provides some limit, it accounts for guest being somewhat faithful on the negotiated 'msize' value throughout the session. A bad guest client could have negotiated a large 'msize' but provide a small reply buffer for Treaddir request, causing QEMU to allocate host memory proportional to 'msize' before discovering the reply cannot fit. Possible consequence was a potential DoS by a priviliged guest, causing a disconnection of guest communication due to transport device being marked as "broken", however QEMU process would have continued to run with potentially giant host memory allocation, which might have negative impact on other services running on host. Fixes: CVE-2026-9238 Fixes: 2149675b195f ("9pfs: add new function v9fs_co_readdir_many()") Reported-by: Feifan Qian Signed-off-by: Christian Schoenebeck Reviewed-by: Stefano Stabellini --- hw/9pfs/9p.c | 24 ++++++++++++++++++++++-- 1 file changed, 22 insertions(+), 2 deletions(-) diff --git a/hw/9pfs/9p.c b/hw/9pfs/9p.c index 2bb42dfc2e..c3e78779b7 100644 --- a/hw/9pfs/9p.c +++ b/hw/9pfs/9p.c @@ -2652,6 +2652,7 @@ static void coroutine_fn v9fs_readdir(void *opaque) uint32_t max_count; V9fsPDU *pdu =3D opaque; V9fsState *s =3D pdu->s; + size_t max_resp_sz; =20 retval =3D pdu_unmarshal(pdu, offset, "dqd", &fid, &initial_offset, &max_count); @@ -2660,9 +2661,28 @@ static void coroutine_fn v9fs_readdir(void *opaque) } trace_v9fs_readdir(pdu->tag, pdu->id, fid, initial_offset, max_count); =20 + max_resp_sz =3D s->msize; + + /* + * Constrain max_count to transport's current, actual response buffer = size. + * A bad client might provide a response buffer < msize. + */ + if (s->transport->response_buffer_size) { + size_t buf_size =3D s->transport->response_buffer_size(pdu); + if (max_resp_sz > buf_size) { + max_resp_sz =3D buf_size; + } + } + /* Enough space for a R_readdir header: size[4] Rreaddir tag[2] count[= 4] */ - if (max_count > s->msize - 11) { - max_count =3D s->msize - 11; + if (max_resp_sz > 11) { + max_resp_sz -=3D 11; + } else { + max_resp_sz =3D 0; + } + + if (max_count > max_resp_sz) { + max_count =3D max_resp_sz; warn_report_once( "9p: bad client: T_readdir with count > msize - 11" ); --=20 2.47.3