From: "Denis V. Lunev" <den@virtuozzo.com>
To: "Denis V. Lunev" <den@openvz.org>, qemu-devel@nongnu.org
Cc: "Marc-André Lureau" <marcandre.lureau@redhat.com>
Subject: Re: [PATCH 0/2] ui/cursor: fix two races that free a cursor early
Date: Sun, 13 Sep 2026 21:57:40 +0200 [thread overview]
Message-ID: <dbfd28b4-8beb-4af5-a9e2-72a296ce41cc@virtuozzo.com> (raw)
In-Reply-To: <20260903192647.2677279-1-den@openvz.org>
On 9/3/26 21:26, Denis V. Lunev wrote:
> This email originated from an IP that might not be authorized by the domain it was sent from.
> Do not click links or open attachments unless it is an email you expected to receive.
> A guest with a qxl display can make QEMU drop more references to a
> QEMUCursor than were taken. The cursor is freed while another owner
> still points at it, and that owner's later cursor_unref() decrements
> four bytes of a chunk the allocator has handed out again. Nothing
> aborts and nothing is logged; QEMU dies later in an unrelated
> allocation, in another thread.
>
> Two defects get there, and neither fix is sufficient alone:
>
> - qxl_spice_reset_cursor() replaces qxl->ssd.cursor with no lock held,
> while every other writer of that field takes ssd.lock. It runs on a
> vCPU thread from QXL_IO_DESTROY_PRIMARY and, unlike qxl_hard_reset(),
> leaves the SPICE display worker running.
>
> - QEMUCursor.refcount is a plain int, taken and dropped from the main
> loop, the SPICE worker, ui/cocoa.m and ui/dbus-listener.c, with no
> lock common to all of them, so an increment can be lost.
>
> A qxl device starts a spice-server instance for local rendering even
> with no -spice, so this is not limited to SPICE console setups.
>
> Patch 2 also asserts that the refcount was positive. Only qxl was
> exercised here, so if another display backend drops a reference it
> never took, that assert turns a silent leak into an abort.
>
> Reproducer: a libdrm program in the guest queues cursor SET commands,
> then disables the CRTC so the driver issues QXL_IO_DESTROY_PRIMARY.
> Unpatched QEMU dies within seconds; with the series it does not. Happy
> to post it.
>
> This is independent of the pending "ui/console: fix use-after-free in
> qemu_console_set_cursor", which fixes a self-assignment ordering bug at
> the same line. With that applied the crash here is unchanged.
>
> Cc: Marc-André Lureau <marcandre.lureau@redhat.com>
> Signed-off-by: Denis V. Lunev <den@openvz.org>
>
> Denis V. Lunev (2):
> hw/display/qxl: hold ssd.lock while replacing ssd.cursor
> ui/cursor: make the cursor refcount atomic
>
> hw/display/qxl.c | 2 ++
> include/ui/console.h | 9 +++++++++
> ui/cursor.c | 17 +++++++++++------
> 3 files changed, 22 insertions(+), 6 deletions(-)
>
Hi, Marc-Andre!
You have not posted the notification that patches
have been queued. Are you going to accept them?
Unfortunately I see your review without any further
actions and patches were not landed yet.
Sorry for bothering,
Den
prev parent reply other threads:[~2026-09-13 19:58 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-03 19:26 [PATCH 0/2] ui/cursor: fix two races that free a cursor early Denis V. Lunev
2026-09-03 19:26 ` [PATCH 1/2] hw/display/qxl: hold ssd.lock while replacing ssd.cursor Denis V. Lunev
2026-09-03 19:30 ` Marc-André Lureau
2026-09-03 19:26 ` [PATCH 2/2] ui/cursor: make the cursor refcount atomic Denis V. Lunev
2026-09-03 19:29 ` Marc-André Lureau
2026-09-13 19:57 ` Denis V. Lunev [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=dbfd28b4-8beb-4af5-a9e2-72a296ce41cc@virtuozzo.com \
--to=den@virtuozzo.com \
--cc=den@openvz.org \
--cc=marcandre.lureau@redhat.com \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.