All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Marc-André Lureau" <marcandre.lureau@redhat.com>
To: qemu-devel@nongnu.org
Subject: [GIT PULL 07/14] hw/display/qxl: validate replayed commands in qxl_post_load
Date: Sun, 13 Sep 2026 14:41:25 +0400	[thread overview]
Message-ID: <20260913-ui-v1-7-7a8d89d0423a@redhat.com> (raw)
In-Reply-To: <20260913-ui-v1-0-7a8d89d0423a@redhat.com>

From: Andrey Drobyshev <andrey.drobyshev@virtuozzo.com>

On incoming migration qxl_post_load() replays the tracked cursor and
surface commands by handing their guest addresses straight to spice,
without revalidating them. Those addresses were checked when the guest
submitted them, but the guest may have freed or reused that memory
before migration, so qxl's tracked pointer can be stale. spice-server
then re-parses the command from that memory and, for a stale cursor,
reads a garbage shape pointer -- aborting the target in memslot_get_virt()
(again, spice-server function) and failing the migration.

Validate each replayed command with qxl_guest_phys2virt(report_bug=false)
before adding it to the replay list, and for a cursor also validate the
nested shape pointer. Commands that no longer resolve are skipped rather
than replayed. report_bug is false so a stale pointer is not mistaken for
a live guest error, which would needlessly disable a healthy guest's
display.

Message-ID: <20260825172051.435372-3-andrey.drobyshev@virtuozzo.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Signed-off-by: Andrey Drobyshev <andrey.drobyshev@virtuozzo.com>
---
 hw/display/qxl.c | 38 +++++++++++++++++++++++++++++++++++++-
 1 file changed, 37 insertions(+), 1 deletion(-)

diff --git a/hw/display/qxl.c b/hw/display/qxl.c
index b6bc182fc2c3..fb77f217b1c6 100644
--- a/hw/display/qxl.c
+++ b/hw/display/qxl.c
@@ -2390,6 +2390,37 @@ static void qxl_create_memslots(PCIQXLDevice *d)
     }
 }
 
+/*
+ * Validate a command tracked for loadvm replay before handing its guest
+ * address to spice-server.
+ */
+static bool qxl_loadvm_cmd_valid(PCIQXLDevice *d, QXLPHYSICAL data,
+                                 uint32_t type)
+{
+    switch (type) {
+    case QXL_CMD_SURFACE:
+        return qxl_guest_phys2virt(d, data,
+                                   sizeof(QXLSurfaceCmd), false) != NULL;
+
+    case QXL_CMD_CURSOR: {
+        QXLCursorCmd *cmd = qxl_guest_phys2virt(d, data, sizeof(QXLCursorCmd),
+                                                false);
+
+        if (!cmd) {
+            return false;
+        }
+        if (le32_to_cpu(cmd->type) == QXL_CURSOR_SET) {
+            return qxl_guest_phys2virt(d, le64_to_cpu(cmd->u.set.shape),
+                                       sizeof(QXLCursor), false) != NULL;
+        }
+        return true;
+    }
+
+    default:
+        g_assert_not_reached();
+    }
+}
+
 static int qxl_post_load(void *opaque, int version)
 {
     PCIQXLDevice* d = opaque;
@@ -2428,12 +2459,17 @@ static int qxl_post_load(void *opaque, int version)
             if (d->guest_surfaces.cmds[in] == 0) {
                 continue;
             }
+            if (!qxl_loadvm_cmd_valid(d, d->guest_surfaces.cmds[in],
+                                      QXL_CMD_SURFACE)) {
+                continue;
+            }
             cmds[out].cmd.data = d->guest_surfaces.cmds[in];
             cmds[out].cmd.type = QXL_CMD_SURFACE;
             cmds[out].group_id = MEMSLOT_GROUP_GUEST;
             out++;
         }
-        if (d->guest_cursor) {
+        if (d->guest_cursor &&
+            qxl_loadvm_cmd_valid(d, d->guest_cursor, QXL_CMD_CURSOR)) {
             cmds[out].cmd.data = d->guest_cursor;
             cmds[out].cmd.type = QXL_CMD_CURSOR;
             cmds[out].group_id = MEMSLOT_GROUP_GUEST;

-- 
2.55.0.543.g5ebe2ebe4ea8



  parent reply	other threads:[~2026-09-13 10:44 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-13 10:41 [GIT PULL 00/14] UI/display queue Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 01/14] ui/dbus: fix cursor race, copy cursor data Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 02/14] hw/display/qxl: hold ssd.lock while replacing ssd.cursor Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 03/14] ui/cursor: make the cursor refcount atomic Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 04/14] docs/sphinx/dbus: register build dependency Marc-André Lureau
2026-09-14  5:45   ` Mauro Carvalho Chehab
2026-09-13 10:41 ` [GIT PULL 05/14] ui/dbus: add org.qemu.Display1.UIInfo interface Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 06/14] hw/display/qxl: factor out qxl_guest_phys2virt() Marc-André Lureau
2026-09-13 10:41 ` Marc-André Lureau [this message]
2026-09-13 10:41 ` [GIT PULL 08/14] hw/display/qxl: trace skipped stale loadvm commands Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 09/14] ui/gtk: Remove glFlush() after eglSwapBuffers() Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 10/14] ui/gtk: Work around the gtk-menu-bar-accel leak Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 11/14] vhost-user-gpu: validate command buffer size in submit_3d Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 12/14] virtio-gpu-virgl: guard new_blob with VIRGL_VERSION_MAJORS>=1 Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 13/14] ui/gtk: Handle empty notebook state in menu handlers Marc-André Lureau
2026-09-13 10:41 ` [GIT PULL 14/14] ui/gtk: Clean up GL resources on tab detach, re-attach, and VC free Marc-André Lureau
2026-09-14  3:09 ` [GIT PULL 00/14] UI/display queue Richard Henderson

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260913-ui-v1-7-7a8d89d0423a@redhat.com \
    --to=marcandre.lureau@redhat.com \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.