From: "Michael S. Tsirkin" <mst@redhat.com>
To: "Philippe Mathieu-Daudé" <philmd@linaro.org>
Cc: qemu-devel@nongnu.org, "Gerd Hoffmann" <kraxel@redhat.com>,
"Amit Shah" <amit@kernel.org>,
"Alexander Bulekov" <alxndr@bu.edu>,
"Gonglei (Arei)" <arei.gonglei@huawei.com>,
"Marc-André Lureau" <marcandre.lureau@redhat.com>,
"Laurent Vivier" <lvivier@redhat.com>,
"Mauro Matteo Cascella" <mcascell@redhat.com>,
"Paolo Bonzini" <pbonzini@redhat.com>,
qemu-stable@nongnu.org
Subject: Re: [PATCH-for-9.0 3/4] hw/char/virtio-serial-bus: Protect from DMA re-entrancy bugs
Date: Mon, 8 Apr 2024 06:08:35 -0400 [thread overview]
Message-ID: <20240408060802-mutt-send-email-mst@kernel.org> (raw)
In-Reply-To: <942c06fd-fac0-49da-9421-92dc3a357cb3@linaro.org>
On Mon, Apr 08, 2024 at 09:14:39AM +0200, Philippe Mathieu-Daudé wrote:
> On 4/4/24 21:13, Philippe Mathieu-Daudé wrote:
> > Replace qemu_bh_new_guarded() by virtio_bh_new_guarded()
> > so the bus and device use the same guard. Otherwise the
> > DMA-reentrancy protection can be bypassed.
> >
> > Cc: qemu-stable@nongnu.org
> > Suggested-by: Alexander Bulekov <alxndr@bu.edu>
> > Signed-off-by: Philippe Mathieu-Daudé <philmd@linaro.org>
> > ---
> > hw/char/virtio-serial-bus.c | 3 +--
> > 1 file changed, 1 insertion(+), 2 deletions(-)
> >
> > diff --git a/hw/char/virtio-serial-bus.c b/hw/char/virtio-serial-bus.c
> > index 016aba6374..cd0e3a11f7 100644
> > --- a/hw/char/virtio-serial-bus.c
> > +++ b/hw/char/virtio-serial-bus.c
> > @@ -985,8 +985,7 @@ static void virtser_port_device_realize(DeviceState *dev, Error **errp)
> > return;
> > }
> > - port->bh = qemu_bh_new_guarded(flush_queued_data_bh, port,
> > - &dev->mem_reentrancy_guard);
> > + port->bh = virtio_bh_new_guarded(vdev, flush_queued_data_bh, port);
>
> Missing:
> -- >8 --
> - port->bh = virtio_bh_new_guarded(vdev, flush_queued_data_bh, port);
> + port->bh = virtio_bh_new_guarded(VIRTIO_DEVICE(dev),
> + flush_queued_data_bh, port);
> ---
I don't get it. vdev is already the correct type. Why do you need
VIRTIO_DEVICE here?
> > port->elem = NULL;
> > }
next prev parent reply other threads:[~2024-04-08 10:09 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-04-04 19:13 [PATCH-for-9.0 0/4] hw/virtio: Protect from more DMA re-entrancy bugs Philippe Mathieu-Daudé
2024-04-04 19:13 ` [PATCH-for-9.0 1/4] hw/virtio: Introduce virtio_bh_new_guarded() helper Philippe Mathieu-Daudé
2024-04-04 19:13 ` [PATCH-for-9.0 2/4] hw/display/virtio-gpu: Protect from DMA re-entrancy bugs Philippe Mathieu-Daudé
2024-04-04 19:13 ` [PATCH-for-9.0 3/4] hw/char/virtio-serial-bus: " Philippe Mathieu-Daudé
2024-04-08 7:14 ` Philippe Mathieu-Daudé
2024-04-08 10:08 ` Michael S. Tsirkin [this message]
2024-04-08 11:04 ` Philippe Mathieu-Daudé
2024-04-08 15:20 ` Michael S. Tsirkin
2024-04-08 18:22 ` Philippe Mathieu-Daudé
2024-04-04 19:13 ` [PATCH-for-9.0 4/4] hw/virtio/virtio-crypto: " Philippe Mathieu-Daudé
2024-04-05 7:02 ` [PATCH-for-9.0 0/4] hw/virtio: Protect from more " Gerd Hoffmann
2024-04-08 7:37 ` Mauro Matteo Cascella
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240408060802-mutt-send-email-mst@kernel.org \
--to=mst@redhat.com \
--cc=alxndr@bu.edu \
--cc=amit@kernel.org \
--cc=arei.gonglei@huawei.com \
--cc=kraxel@redhat.com \
--cc=lvivier@redhat.com \
--cc=marcandre.lureau@redhat.com \
--cc=mcascell@redhat.com \
--cc=pbonzini@redhat.com \
--cc=philmd@linaro.org \
--cc=qemu-devel@nongnu.org \
--cc=qemu-stable@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.