All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Philippe Mathieu-Daudé" <philmd@oss.qualcomm.com>
To: Thomas Huth <thuth@redhat.com>,
	qemu-devel@nongnu.org, John Snow <jsnow@redhat.com>
Cc: Alexander Bulekov <alxndr@bu.edu>,
	qemu-block@nongnu.org, qemu-stable@nongnu.org,
	qemu-trivial@nongnu.org
Subject: Re: [PATCH] hw/ide/core: Fix possible crash via NULL pointer in ide_cancel_dma_sync()
Date: Mon, 20 Jul 2026 22:36:48 +0200	[thread overview]
Message-ID: <cd8ff4ea-9d66-4be1-b8ff-e361cfaea5d2@oss.qualcomm.com> (raw)
In-Reply-To: <20260720194210.663629-1-thuth@redhat.com>

On 20/7/26 21:42, Thomas Huth wrote:
> From: Thomas Huth <thuth@redhat.com>
> 
> ide_cancel_dma_sync() is called with a "IDEState *s" for one of the
> two IDE drives on a bus (primary or secondary drive) to cancel all
> pending DMA transfers on the drive. The code then checks
> s->bus->dma->aiocb to see whether there is any IO in flight on the
> *bus* and then calls blk_drain(s->blk) to wait for its completion.
> However, s->bus->dma->aiocb might belong to the other drive on the
> bus, and if there is no disk attached to the current drive, s->blk
> is NULL. Since blk_drain() does not check its parameter for a NULL
> pointer, QEMU can crash in such a case.
> 
> Fix the problem by checking s->blk to be a valid pointer before
> calling blk_drain() in this function.
> 
> Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/905
> Reported-by: Alexander Bulekov <alxndr@bu.edu>
> Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4052
> Reported-by: dong ling
> Signed-off-by: Thomas Huth <thuth@redhat.com>
> ---
>   hw/ide/core.c | 5 ++++-
>   1 file changed, 4 insertions(+), 1 deletion(-)
> 
> diff --git a/hw/ide/core.c b/hw/ide/core.c
> index f78b00220b8..49848c8e6bd 100644
> --- a/hw/ide/core.c
> +++ b/hw/ide/core.c
> @@ -741,8 +741,11 @@ void ide_cancel_dma_sync(IDEState *s)
>        * In the future we'll be able to safely cancel the I/O if the
>        * whole DMA operation will be submitted to disk with a single
>        * aio operation with preadv/pwritev.
> +     *
> +     * Note: s->bus->dma->aiocb might belong to the adjacent IDEState,
> +     * so we have to check s->blk for not being NULL, too.
>        */
> -    if (s->bus->dma->aiocb) {
> +    if (s->bus->dma->aiocb && s->blk) {

Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>

If you don't object, I'll change to:

        if (s->blk && s->bus->dma->aiocb) {

when queueing.

>           trace_ide_cancel_dma_sync_remaining();
>           blk_drain(s->blk);
>           assert(s->bus->dma->aiocb == NULL);



  reply	other threads:[~2026-07-20 20:38 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-20 19:42 [PATCH] hw/ide/core: Fix possible crash via NULL pointer in ide_cancel_dma_sync() Thomas Huth
2026-07-20 20:36 ` Philippe Mathieu-Daudé [this message]
2026-07-21  6:44   ` Thomas Huth

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=cd8ff4ea-9d66-4be1-b8ff-e361cfaea5d2@oss.qualcomm.com \
    --to=philmd@oss.qualcomm.com \
    --cc=alxndr@bu.edu \
    --cc=jsnow@redhat.com \
    --cc=qemu-block@nongnu.org \
    --cc=qemu-devel@nongnu.org \
    --cc=qemu-stable@nongnu.org \
    --cc=qemu-trivial@nongnu.org \
    --cc=thuth@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.