* [PATCH v3 0/2] More virtio-snd fortifications/coverity fixes
@ 2026-04-20 5:07 Manos Pitsidianakis
2026-04-20 5:07 ` [PATCH v3 1/2] virtio-snd: check rx buffer descriptor size Manos Pitsidianakis
` (2 more replies)
0 siblings, 3 replies; 7+ messages in thread
From: Manos Pitsidianakis @ 2026-04-20 5:07 UTC (permalink / raw)
To: qemu-devel
Cc: Gerd Hoffmann, Michael S. Tsirkin, Philippe Mathieu-Daudé,
Alex Bennée, Richard Henderson, qemu-stable,
Manos Pitsidianakis
Added checks for stuff coverity pointed out (CID 1547527).
Signed-off-by: Manos Pitsidianakis <manos.pitsidianakis@linaro.org>
---
Changes in v3:
- Added Coverity CID in patch message (thanks Alex)
- Link to v2: https://lore.kernel.org/qemu-devel/20260417-virtio-fixups-v2-0-4a0d8636a628@linaro.org
Changes in v2:
- Use g_size_checked_add (thanks rth)
- Link to v1: https://lore.kernel.org/qemu-devel/20260416-virtio-fixups-v1-0-ec14e2de0852@linaro.org
---
Manos Pitsidianakis (2):
virtio-snd: check rx buffer descriptor size
virtio-snd: check for overflow before g_malloc0
hw/audio/virtio-snd.c | 24 +++++++++++++++++-------
1 file changed, 17 insertions(+), 7 deletions(-)
---
base-commit: da6c4fe60fee30dd77267764d55b38af9cb89d4b
change-id: 20260415-virtio-fixups-3bc3a1a1cd27
--
γαῖα πυρί μιχθήτω
^ permalink raw reply [flat|nested] 7+ messages in thread* [PATCH v3 1/2] virtio-snd: check rx buffer descriptor size 2026-04-20 5:07 [PATCH v3 0/2] More virtio-snd fortifications/coverity fixes Manos Pitsidianakis @ 2026-04-20 5:07 ` Manos Pitsidianakis 2026-04-20 5:07 ` [PATCH v3 2/2] virtio-snd: check for overflow before g_malloc0 Manos Pitsidianakis 2026-07-08 9:09 ` [PATCH v3 0/2] More virtio-snd fortifications/coverity fixes Michael Tokarev 2 siblings, 0 replies; 7+ messages in thread From: Manos Pitsidianakis @ 2026-04-20 5:07 UTC (permalink / raw) To: qemu-devel Cc: Gerd Hoffmann, Michael S. Tsirkin, Philippe Mathieu-Daudé, Alex Bennée, Richard Henderson, qemu-stable, Manos Pitsidianakis It must be at least sizeof(virtio_snd_pcm_status). I haven't verified if it's possible to get an underflow, but coverity points it out in CID 1547527 so add a check. Reviewed-by: Alex Bennée <alex.bennee@linaro.org> Signed-off-by: Manos Pitsidianakis <manos.pitsidianakis@linaro.org> --- hw/audio/virtio-snd.c | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/hw/audio/virtio-snd.c b/hw/audio/virtio-snd.c index fb5cff386606d03e5cfce88f79e404e510bbcde7..93fbcfb43f7fdcfd5c164b496015da743822f5eb 100644 --- a/hw/audio/virtio-snd.c +++ b/hw/audio/virtio-snd.c @@ -970,12 +970,14 @@ static void virtio_snd_handle_rx_xfer(VirtIODevice *vdev, VirtQueue *vq) } stream = vsnd->pcm.streams[stream_id]; - if (stream == NULL || stream->info.direction != VIRTIO_SND_D_INPUT) { + size = iov_size(elem->in_sg, elem->in_num); + if (stream == NULL + || stream->info.direction != VIRTIO_SND_D_INPUT + || size < sizeof(virtio_snd_pcm_status)) { goto rx_err; } + size -= sizeof(virtio_snd_pcm_status); WITH_QEMU_LOCK_GUARD(&stream->queue_mutex) { - size = iov_size(elem->in_sg, elem->in_num) - - sizeof(virtio_snd_pcm_status); buffer = g_malloc0(sizeof(VirtIOSoundPCMBuffer) + size); buffer->elem = elem; buffer->vq = vq; -- 2.47.3 ^ permalink raw reply related [flat|nested] 7+ messages in thread
* [PATCH v3 2/2] virtio-snd: check for overflow before g_malloc0 2026-04-20 5:07 [PATCH v3 0/2] More virtio-snd fortifications/coverity fixes Manos Pitsidianakis 2026-04-20 5:07 ` [PATCH v3 1/2] virtio-snd: check rx buffer descriptor size Manos Pitsidianakis @ 2026-04-20 5:07 ` Manos Pitsidianakis 2026-07-08 9:09 ` [PATCH v3 0/2] More virtio-snd fortifications/coverity fixes Michael Tokarev 2 siblings, 0 replies; 7+ messages in thread From: Manos Pitsidianakis @ 2026-04-20 5:07 UTC (permalink / raw) To: qemu-devel Cc: Gerd Hoffmann, Michael S. Tsirkin, Philippe Mathieu-Daudé, Alex Bennée, Richard Henderson, qemu-stable, Manos Pitsidianakis Coverity points out one g_malloc0 overflow, but it seems to be a false positive. Add a check to it regardless to fortify the code, and also add checks for every other g_malloc0 use. Resolves: Coverity CID 1547527 Signed-off-by: Manos Pitsidianakis <manos.pitsidianakis@linaro.org> --- hw/audio/virtio-snd.c | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/hw/audio/virtio-snd.c b/hw/audio/virtio-snd.c index 93fbcfb43f7fdcfd5c164b496015da743822f5eb..694bcebb60f6c866346470672cc798b3271ae34f 100644 --- a/hw/audio/virtio-snd.c +++ b/hw/audio/virtio-snd.c @@ -850,7 +850,7 @@ static void virtio_snd_handle_tx_xfer(VirtIODevice *vdev, VirtQueue *vq) VirtIOSound *vsnd = VIRTIO_SND(vdev); VirtIOSoundPCMBuffer *buffer; VirtQueueElement *elem; - size_t msg_sz, size; + size_t msg_sz, size, tmp; virtio_snd_pcm_xfer hdr; uint32_t stream_id; /* @@ -880,6 +880,8 @@ static void virtio_snd_handle_tx_xfer(VirtIODevice *vdev, VirtQueue *vq) if (msg_sz != sizeof(virtio_snd_pcm_xfer)) { goto tx_err; } + assert(iov_size(elem->out_sg, elem->out_num) >= msg_sz); + size = iov_size(elem->out_sg, elem->out_num) - msg_sz; stream_id = le32_to_cpu(hdr.stream_id); if (stream_id >= vsnd->snd_conf.streams @@ -892,9 +894,11 @@ static void virtio_snd_handle_tx_xfer(VirtIODevice *vdev, VirtQueue *vq) goto tx_err; } + /* Check for g_malloc0 overflow. */ + if (!g_size_checked_add(&tmp, sizeof(VirtIOSoundPCMBuffer), size)) { + goto tx_err; + } WITH_QEMU_LOCK_GUARD(&stream->queue_mutex) { - size = iov_size(elem->out_sg, elem->out_num) - msg_sz; - buffer = g_malloc0(sizeof(VirtIOSoundPCMBuffer) + size); buffer->elem = elem; buffer->populated = false; @@ -932,7 +936,7 @@ static void virtio_snd_handle_rx_xfer(VirtIODevice *vdev, VirtQueue *vq) VirtIOSound *vsnd = VIRTIO_SND(vdev); VirtIOSoundPCMBuffer *buffer; VirtQueueElement *elem; - size_t msg_sz, size; + size_t msg_sz, size, tmp; virtio_snd_pcm_xfer hdr; uint32_t stream_id; /* @@ -977,6 +981,10 @@ static void virtio_snd_handle_rx_xfer(VirtIODevice *vdev, VirtQueue *vq) goto rx_err; } size -= sizeof(virtio_snd_pcm_status); + /* Check for g_malloc0 overflow. */ + if (!g_size_checked_add(&tmp, sizeof(VirtIOSoundPCMBuffer), size)) { + goto rx_err; + } WITH_QEMU_LOCK_GUARD(&stream->queue_mutex) { buffer = g_malloc0(sizeof(VirtIOSoundPCMBuffer) + size); buffer->elem = elem; -- 2.47.3 ^ permalink raw reply related [flat|nested] 7+ messages in thread
* Re: [PATCH v3 0/2] More virtio-snd fortifications/coverity fixes 2026-04-20 5:07 [PATCH v3 0/2] More virtio-snd fortifications/coverity fixes Manos Pitsidianakis 2026-04-20 5:07 ` [PATCH v3 1/2] virtio-snd: check rx buffer descriptor size Manos Pitsidianakis 2026-04-20 5:07 ` [PATCH v3 2/2] virtio-snd: check for overflow before g_malloc0 Manos Pitsidianakis @ 2026-07-08 9:09 ` Michael Tokarev 2026-07-08 12:01 ` Manos Pitsidianakis 2 siblings, 1 reply; 7+ messages in thread From: Michael Tokarev @ 2026-07-08 9:09 UTC (permalink / raw) To: Manos Pitsidianakis, qemu-devel Cc: Gerd Hoffmann, Michael S. Tsirkin, Philippe Mathieu-Daudé, Alex Bennée, Richard Henderson, qemu-stable On 20.04.2026 08:07, Manos Pitsidianakis wrote: > Added checks for stuff coverity pointed out (CID 1547527). > > Signed-off-by: Manos Pitsidianakis <manos.pitsidianakis@linaro.org> > --- > Changes in v3: > - Added Coverity CID in patch message (thanks Alex) > - Link to v2: https://lore.kernel.org/qemu-devel/20260417-virtio-fixups-v2-0-4a0d8636a628@linaro.org > > Changes in v2: > - Use g_size_checked_add (thanks rth) > - Link to v1: https://lore.kernel.org/qemu-devel/20260416-virtio-fixups-v1-0-ec14e2de0852@linaro.org Hi! It looks like this patchset has been lost somehow. Is it still needed? /mjt > --- > Manos Pitsidianakis (2): > virtio-snd: check rx buffer descriptor size > virtio-snd: check for overflow before g_malloc0 > > hw/audio/virtio-snd.c | 24 +++++++++++++++++------- > 1 file changed, 17 insertions(+), 7 deletions(-) > --- > base-commit: da6c4fe60fee30dd77267764d55b38af9cb89d4b > change-id: 20260415-virtio-fixups-3bc3a1a1cd27 > > -- > γαῖα πυρί μιχθήτω > > ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v3 0/2] More virtio-snd fortifications/coverity fixes 2026-07-08 9:09 ` [PATCH v3 0/2] More virtio-snd fortifications/coverity fixes Michael Tokarev @ 2026-07-08 12:01 ` Manos Pitsidianakis 2026-07-25 9:50 ` Michael S. Tsirkin 2026-07-25 11:52 ` Michael S. Tsirkin 0 siblings, 2 replies; 7+ messages in thread From: Manos Pitsidianakis @ 2026-07-08 12:01 UTC (permalink / raw) To: Michael Tokarev Cc: qemu-devel, Gerd Hoffmann, Michael S. Tsirkin, Philippe Mathieu-Daudé, Alex Bennée, Richard Henderson, qemu-stable On Wed, Jul 8, 2026 at 12:09 PM Michael Tokarev <mjt@tls.msk.ru> wrote: > > On 20.04.2026 08:07, Manos Pitsidianakis wrote: > > Added checks for stuff coverity pointed out (CID 1547527). > > > > Signed-off-by: Manos Pitsidianakis <manos.pitsidianakis@linaro.org> > > --- > > Changes in v3: > > - Added Coverity CID in patch message (thanks Alex) > > - Link to v2: https://lore.kernel.org/qemu-devel/20260417-virtio-fixups-v2-0-4a0d8636a628@linaro.org > > > > Changes in v2: > > - Use g_size_checked_add (thanks rth) > > - Link to v1: https://lore.kernel.org/qemu-devel/20260416-virtio-fixups-v1-0-ec14e2de0852@linaro.org > > Hi! > > It looks like this patchset has been lost somehow. Is it still needed? > > /mjt Patch 2 is still unreviewed it seems. I might send a new series with more patches soon. Thanks for the reminder! > > > --- > > Manos Pitsidianakis (2): > > virtio-snd: check rx buffer descriptor size > > virtio-snd: check for overflow before g_malloc0 > > > > hw/audio/virtio-snd.c | 24 +++++++++++++++++------- > > 1 file changed, 17 insertions(+), 7 deletions(-) > > --- > > base-commit: da6c4fe60fee30dd77267764d55b38af9cb89d4b > > change-id: 20260415-virtio-fixups-3bc3a1a1cd27 > > > > -- > > γαῖα πυρί μιχθήτω > > > > > -- Manos Pitsidianakis Emulation and Virtualization Engineer at Linaro Ltd ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v3 0/2] More virtio-snd fortifications/coverity fixes 2026-07-08 12:01 ` Manos Pitsidianakis @ 2026-07-25 9:50 ` Michael S. Tsirkin 2026-07-25 11:52 ` Michael S. Tsirkin 1 sibling, 0 replies; 7+ messages in thread From: Michael S. Tsirkin @ 2026-07-25 9:50 UTC (permalink / raw) To: Manos Pitsidianakis Cc: Michael Tokarev, qemu-devel, Gerd Hoffmann, Philippe Mathieu-Daudé, Alex Bennée, Richard Henderson, qemu-stable On Wed, Jul 08, 2026 at 03:01:19PM +0300, Manos Pitsidianakis wrote: > On Wed, Jul 8, 2026 at 12:09 PM Michael Tokarev <mjt@tls.msk.ru> wrote: > > > > On 20.04.2026 08:07, Manos Pitsidianakis wrote: > > > Added checks for stuff coverity pointed out (CID 1547527). > > > > > > Signed-off-by: Manos Pitsidianakis <manos.pitsidianakis@linaro.org> > > > --- > > > Changes in v3: > > > - Added Coverity CID in patch message (thanks Alex) > > > - Link to v2: https://lore.kernel.org/qemu-devel/20260417-virtio-fixups-v2-0-4a0d8636a628@linaro.org > > > > > > Changes in v2: > > > - Use g_size_checked_add (thanks rth) > > > - Link to v1: https://lore.kernel.org/qemu-devel/20260416-virtio-fixups-v1-0-ec14e2de0852@linaro.org > > > > Hi! > > > > It looks like this patchset has been lost somehow. Is it still needed? > > > > /mjt > > Patch 2 is still unreviewed it seems. I might send a new series with > more patches soon. Thanks for the reminder! so you will repost all this? > > > > > --- > > > Manos Pitsidianakis (2): > > > virtio-snd: check rx buffer descriptor size > > > virtio-snd: check for overflow before g_malloc0 > > > > > > hw/audio/virtio-snd.c | 24 +++++++++++++++++------- > > > 1 file changed, 17 insertions(+), 7 deletions(-) > > > --- > > > base-commit: da6c4fe60fee30dd77267764d55b38af9cb89d4b > > > change-id: 20260415-virtio-fixups-3bc3a1a1cd27 > > > > > > -- > > > γαῖα πυρί μιχθήτω > > > > > > > > > > -- > Manos Pitsidianakis > Emulation and Virtualization Engineer at Linaro Ltd ^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH v3 0/2] More virtio-snd fortifications/coverity fixes 2026-07-08 12:01 ` Manos Pitsidianakis 2026-07-25 9:50 ` Michael S. Tsirkin @ 2026-07-25 11:52 ` Michael S. Tsirkin 1 sibling, 0 replies; 7+ messages in thread From: Michael S. Tsirkin @ 2026-07-25 11:52 UTC (permalink / raw) To: Manos Pitsidianakis Cc: Michael Tokarev, qemu-devel, Gerd Hoffmann, Philippe Mathieu-Daudé, Alex Bennée, Richard Henderson, qemu-stable On Wed, Jul 08, 2026 at 03:01:19PM +0300, Manos Pitsidianakis wrote: > On Wed, Jul 8, 2026 at 12:09 PM Michael Tokarev <mjt@tls.msk.ru> wrote: > > > > On 20.04.2026 08:07, Manos Pitsidianakis wrote: > > > Added checks for stuff coverity pointed out (CID 1547527). > > > > > > Signed-off-by: Manos Pitsidianakis <manos.pitsidianakis@linaro.org> > > > --- > > > Changes in v3: > > > - Added Coverity CID in patch message (thanks Alex) > > > - Link to v2: https://lore.kernel.org/qemu-devel/20260417-virtio-fixups-v2-0-4a0d8636a628@linaro.org > > > > > > Changes in v2: > > > - Use g_size_checked_add (thanks rth) > > > - Link to v1: https://lore.kernel.org/qemu-devel/20260416-virtio-fixups-v1-0-ec14e2de0852@linaro.org > > > > Hi! > > > > It looks like this patchset has been lost somehow. Is it still needed? > > > > /mjt > > Patch 2 is still unreviewed it seems. I might send a new series with > more patches soon. Thanks for the reminder! I think a bigger problem is that we allocate as much as guest wants in the 1st place. Want to look into this? > > > > > --- > > > Manos Pitsidianakis (2): > > > virtio-snd: check rx buffer descriptor size > > > virtio-snd: check for overflow before g_malloc0 > > > > > > hw/audio/virtio-snd.c | 24 +++++++++++++++++------- > > > 1 file changed, 17 insertions(+), 7 deletions(-) > > > --- > > > base-commit: da6c4fe60fee30dd77267764d55b38af9cb89d4b > > > change-id: 20260415-virtio-fixups-3bc3a1a1cd27 > > > > > > -- > > > γαῖα πυρί μιχθήτω > > > > > > > > > > -- > Manos Pitsidianakis > Emulation and Virtualization Engineer at Linaro Ltd ^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2026-07-25 11:53 UTC | newest] Thread overview: 7+ messages (download: mbox.gz follow: Atom feed -- links below jump to the message on this page -- 2026-04-20 5:07 [PATCH v3 0/2] More virtio-snd fortifications/coverity fixes Manos Pitsidianakis 2026-04-20 5:07 ` [PATCH v3 1/2] virtio-snd: check rx buffer descriptor size Manos Pitsidianakis 2026-04-20 5:07 ` [PATCH v3 2/2] virtio-snd: check for overflow before g_malloc0 Manos Pitsidianakis 2026-07-08 9:09 ` [PATCH v3 0/2] More virtio-snd fortifications/coverity fixes Michael Tokarev 2026-07-08 12:01 ` Manos Pitsidianakis 2026-07-25 9:50 ` Michael S. Tsirkin 2026-07-25 11:52 ` Michael S. Tsirkin
This is an external index of several public inboxes, see mirroring instructions on how to clone and mirror all data and code used by this external index.