From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from lists1p.gnu.org (lists1p.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.lore.kernel.org (Postfix) with ESMTPS id 9D36DC79FBD for ; Wed, 9 Sep 2026 17:58:21 +0000 (UTC) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists1p.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1x4MXy-00016s-L8; Wed, 09 Sep 2026 13:57:23 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists1p.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MXw-00016a-1E for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:20 -0400 Received: from us-smtp-delivery-124.mimecast.com ([170.10.129.124]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1x4MXu-0004cZ-Lw for qemu-devel@nongnu.org; Wed, 09 Sep 2026 13:57:19 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1788976636; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=yHRcM+f+qh3837ppHP4zrC+XzjGtSY5yOhH9gpZDcdU=; b=SDd5HNMOH3thjAz4UNM6P485jkIcc4IemZL9YKRaSiAXSEZQxGMDv3y9x5/3bVo0bcx1n5 DLmyx4jutUAbaAssz8xJveWjIbc60o+ZY4djvLHy5+TfqR0MGNr2JfQFlRLbyhDutfKx9u 8gbgWUt8AJXThbLZkvhH8YIjFacGnQM= Received: from mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (ec2-35-165-154-97.us-west-2.compute.amazonaws.com [35.165.154.97]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-67-0urfthlEMaKYGvHa_4Pfcg-1; Wed, 09 Sep 2026 13:57:13 -0400 X-MC-Unique: 0urfthlEMaKYGvHa_4Pfcg-1 X-Mimecast-MFC-AGG-ID: 0urfthlEMaKYGvHa_4Pfcg_1788976632 Received: from mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com [10.30.177.12]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mx-prod-mc-06.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTPS id 7064F1800632; Wed, 9 Sep 2026 17:57:12 +0000 (UTC) Received: from berrange.csb (headnet03.pony-001.prod.iad2.dc.redhat.com [10.2.32.114]) by mx-prod-int-03.mail-002.prod.us-west-2.aws.redhat.com (Postfix) with ESMTP id 28489195608E; Wed, 9 Sep 2026 17:57:09 +0000 (UTC) From: =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= To: qemu-devel@nongnu.org Cc: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , Peter Maydell , Stefan Hajnoczi , "Michael S. Tsirkin" , Paolo Bonzini , Markus Armbruster , =?UTF-8?q?Alex=20Benn=C3=A9e?= , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , =?UTF-8?q?Daniel=20P=2E=20Berrang=C3=A9?= Subject: [PATCH 04/14] system: check security for accelerator types Date: Wed, 9 Sep 2026 18:56:46 +0100 Message-ID: <20260909175656.1572689-5-berrange@redhat.com> In-Reply-To: <20260909175656.1572689-1-berrange@redhat.com> References: <20260909175656.1572689-1-berrange@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Scanned-By: MIMEDefang 3.0 on 10.30.177.12 Received-SPF: pass client-ip=170.10.129.124; envelope-from=berrange@redhat.com; helo=us-smtp-delivery-124.mimecast.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: qemu development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+qemu-devel=archiver.kernel.org@nongnu.org Sender: qemu-devel-bounces+qemu-devel=archiver.kernel.org@nongnu.org This wires up the accelerator creation code to apply the compat policy security check. When multiple -accel options are given, normal fallback logic applies. IOW, if one is rejected by the security check, it will carry on to try the next accelerator until one passes the security check. Signed-off-by: Daniel P. Berrangé --- system/vl.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/system/vl.c b/system/vl.c index 9bd7664b85..0c6e44f21c 100644 --- a/system/vl.c +++ b/system/vl.c @@ -2412,6 +2412,11 @@ static int do_configure_accelerator(void *opaque, QemuOpts *opts, Error **errp) } goto bad; } + + if (!object_class_check_security(OBJECT_CLASS(ac), errp)) { + goto bad; + } + accel = ACCEL(object_new_with_class(OBJECT_CLASS(ac))); object_apply_compat_props(OBJECT(accel)); qemu_opt_foreach(opts, accelerator_set_property, -- 2.55.0