From: "Michael S. Tsirkin" <mst@redhat.com>
To: qemu-devel@nongnu.org
Cc: "Eduardo Habkost" <eduardo@habkost.net>,
"Peter Maydell" <peter.maydell@linaro.org>,
"Richard Henderson" <richard.henderson@linaro.org>,
qemu-stable@nongnu.org, "Denis Lisov" <dennis.lissov@gmail.com>,
"Alexander Tsoy" <alexander@tsoy.me>,
"Paolo Bonzini" <pbonzini@redhat.com>,
"Ani Sinha" <ani@anisinha.ca>,
"Igor Mammedov" <imammedo@redhat.com>,
"Philippe Mathieu-Daudé" <philmd@redhat.com>
Subject: [PULL v2 43/55] acpi: fix QEMU crash when started with SLIC table
Date: Fri, 7 Jan 2022 06:05:13 -0500 [thread overview]
Message-ID: <20220107102526.39238-44-mst@redhat.com> (raw)
In-Reply-To: <20220107102526.39238-1-mst@redhat.com>
From: Igor Mammedov <imammedo@redhat.com>
if QEMU is started with used provided SLIC table blob,
-acpitable sig=SLIC,oem_id='CRASH ',oem_table_id="ME",oem_rev=00002210,asl_compiler_id="",asl_compiler_rev=00000000,data=/dev/null
it will assert with:
hw/acpi/aml-build.c:61:build_append_padded_str: assertion failed: (len <= maxlen)
and following backtrace:
...
build_append_padded_str (array=0x555556afe320, str=0x555556afdb2e "CRASH ME", maxlen=0x6, pad=0x20) at hw/acpi/aml-build.c:61
acpi_table_begin (desc=0x7fffffffd1b0, array=0x555556afe320) at hw/acpi/aml-build.c:1727
build_fadt (tbl=0x555556afe320, linker=0x555557ca3830, f=0x7fffffffd318, oem_id=0x555556afdb2e "CRASH ME", oem_table_id=0x555556afdb34 "ME") at hw/acpi/aml-build.c:2064
...
which happens due to acpi_table_begin() expecting NULL terminated
oem_id and oem_table_id strings, which is normally the case, but
in case of user provided SLIC table, oem_id points to table's blob
directly and as result oem_id became longer than expected.
Fix issue by handling oem_id consistently and make acpi_get_slic_oem()
return NULL terminated strings.
PS:
After [1] refactoring, oem_id semantics became inconsistent, where
NULL terminated string was coming from machine and old way pointer
into byte array coming from -acpitable option. That used to work
since build_header() wasn't expecting NULL terminated string and
blindly copied the 1st 6 bytes only.
However commit [2] broke that by replacing build_header() with
acpi_table_begin(), which was expecting NULL terminated string
and was checking oem_id size.
1) 602b45820 ("acpi: Permit OEM ID and OEM table ID fields to be changed")
2)
Fixes: 4b56e1e4eb08 ("acpi: build_fadt: use acpi_table_begin()/acpi_table_end() instead of build_header()")
Resolves: https://gitlab.com/qemu-project/qemu/-/issues/786
Signed-off-by: Igor Mammedov <imammedo@redhat.com>
Message-Id: <20211227193120.1084176-2-imammedo@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@redhat.com>
Tested-by: Denis Lisov <dennis.lissov@gmail.com>
Tested-by: Alexander Tsoy <alexander@tsoy.me>
Cc: qemu-stable@nongnu.org
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
---
hw/acpi/core.c | 4 ++--
hw/i386/acpi-build.c | 2 ++
2 files changed, 4 insertions(+), 2 deletions(-)
diff --git a/hw/acpi/core.c b/hw/acpi/core.c
index 1e004d0078..3e811bf03c 100644
--- a/hw/acpi/core.c
+++ b/hw/acpi/core.c
@@ -345,8 +345,8 @@ int acpi_get_slic_oem(AcpiSlicOem *oem)
struct acpi_table_header *hdr = (void *)(u - sizeof(hdr->_length));
if (memcmp(hdr->sig, "SLIC", 4) == 0) {
- oem->id = hdr->oem_id;
- oem->table_id = hdr->oem_table_id;
+ oem->id = g_strndup(hdr->oem_id, 6);
+ oem->table_id = g_strndup(hdr->oem_table_id, 8);
return 0;
}
}
diff --git a/hw/i386/acpi-build.c b/hw/i386/acpi-build.c
index 8383b83ee3..0234fe7588 100644
--- a/hw/i386/acpi-build.c
+++ b/hw/i386/acpi-build.c
@@ -2723,6 +2723,8 @@ void acpi_build(AcpiBuildTables *tables, MachineState *machine)
/* Cleanup memory that's no longer used. */
g_array_free(table_offsets, true);
+ g_free(slic_oem.id);
+ g_free(slic_oem.table_id);
}
static void acpi_ram_update(MemoryRegion *mr, GArray *data)
--
MST
next prev parent reply other threads:[~2022-01-07 11:58 UTC|newest]
Thread overview: 59+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-01-07 11:03 [PULL v2 00/55] virtio,pci,pc: features,fixes,cleanups Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 01/55] virtio-mem: Don't skip alignment checks when warning about block size Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 02/55] acpi: validate hotplug selector on access Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 03/55] virtio: introduce macro IRTIO_CONFIG_IRQ_IDX Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 04/55] virtio-pci: decouple notifier from interrupt process Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 05/55] virtio-pci: decouple the single vector from the " Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 06/55] vhost: introduce new VhostOps vhost_set_config_call Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 07/55] vhost-vdpa: add support for config interrupt Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 08/55] virtio: add support for configure interrupt Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 09/55] vhost: " Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 10/55] virtio-net: " Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 11/55] virtio-mmio: " Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 12/55] virtio-pci: " Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 13/55] trace-events,pci: unify trace events format Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 14/55] vhost-user-blk: reconnect on any error during realize Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 15/55] chardev/char-socket: tcp_chr_recv: don't clobber errno Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 16/55] chardev/char-socket: tcp_chr_sync_read: " Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 17/55] vhost-backend: avoid overflow on memslots_limit Michael S. Tsirkin
2022-01-07 11:03 ` [PULL v2 18/55] vhost-backend: stick to -errno error return convention Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 19/55] vhost-vdpa: " Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 20/55] vhost-user: " Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 21/55] vhost: " Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 22/55] vhost-user-blk: propagate error return from generic vhost Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 23/55] pci: Export the pci_intx() function Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 24/55] pcie_aer: Don't trigger a LSI if none are defined Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 25/55] smbios: Rename SMBIOS_ENTRY_POINT_* enums Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 26/55] hw/smbios: Use qapi for SmbiosEntryPointType Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 27/55] hw/i386: expose a "smbios-entry-point-type" PC machine property Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 28/55] hw/vhost-user-blk: turn on VIRTIO_BLK_F_SIZE_MAX feature for virtio blk device Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 29/55] util/oslib-posix: Let touch_all_pages() return an error Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 30/55] util/oslib-posix: Support MADV_POPULATE_WRITE for os_mem_prealloc() Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 31/55] util/oslib-posix: Introduce and use MemsetContext for touch_all_pages() Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 32/55] util/oslib-posix: Don't create too many threads with small memory or little pages Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 33/55] util/oslib-posix: Avoid creating a single thread with MADV_POPULATE_WRITE Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 34/55] util/oslib-posix: Support concurrent os_mem_prealloc() invocation Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 35/55] util/oslib-posix: Forward SIGBUS to MCE handler under Linux Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 36/55] virtio-mem: Support "prealloc=on" option Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 37/55] virtio: signal after wrapping packed used_idx Michael S. Tsirkin
2022-01-07 11:04 ` [PULL v2 38/55] MAINTAINERS: Add a separate entry for acpi/VIOT tables Michael S. Tsirkin
2022-01-07 11:05 ` [PULL v2 39/55] linux-headers: sync VIRTIO_MEM_F_UNPLUGGED_INACCESSIBLE Michael S. Tsirkin
2022-01-07 11:05 ` [PULL v2 40/55] virtio-mem: Support VIRTIO_MEM_F_UNPLUGGED_INACCESSIBLE Michael S. Tsirkin
2022-01-07 11:05 ` [PULL v2 41/55] virtio-mem: Set "unplugged-inaccessible=auto" for the 7.0 machine on x86 Michael S. Tsirkin
2022-01-07 11:05 ` [PULL v2 42/55] intel-iommu: correctly check passthrough during translation Michael S. Tsirkin
2022-01-07 11:05 ` Michael S. Tsirkin [this message]
2022-01-07 11:05 ` [PULL v2 44/55] tests: acpi: whitelist expected blobs before changing them Michael S. Tsirkin
2022-01-07 11:05 ` [PULL v2 45/55] tests: acpi: add SLIC table test Michael S. Tsirkin
2022-01-07 11:05 ` [PULL v2 46/55] tests: acpi: SLIC: update expected blobs Michael S. Tsirkin
2022-01-07 11:05 ` [PULL v2 47/55] acpihp: simplify acpi_pcihp_disable_root_bus Michael S. Tsirkin
2022-01-07 11:05 ` [PULL v2 48/55] hw/i386/pc: Add missing property descriptions Michael S. Tsirkin
2022-01-07 11:05 ` [PULL v2 49/55] docs: reSTify virtio-balloon-stats documentation and move to docs/interop Michael S. Tsirkin
2022-01-07 11:05 ` [PULL v2 50/55] hw/scsi/vhost-scsi: don't leak vqs on error Michael S. Tsirkin
2022-01-07 11:05 ` [PULL v2 51/55] hw/scsi/vhost-scsi: don't double close vhostfd " Michael S. Tsirkin
2022-01-07 11:05 ` [PULL v2 52/55] virtio/vhost-vsock: don't double close vhostfd, remove redundant cleanup Michael S. Tsirkin
2022-01-07 11:05 ` [PULL v2 53/55] tests: acpi: prepare for updated TPM related tables Michael S. Tsirkin
2022-01-07 11:05 ` [PULL v2 54/55] acpi: tpm: Add missing device identification objects Michael S. Tsirkin
2022-01-07 11:05 ` [PULL v2 55/55] tests: acpi: Add updated TPM related tables Michael S. Tsirkin
2022-01-07 19:38 ` [PULL v2 00/55] virtio,pci,pc: features,fixes,cleanups Richard Henderson
2022-01-08 0:34 ` Michael S. Tsirkin
2022-01-09 12:20 ` David Hildenbrand
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20220107102526.39238-44-mst@redhat.com \
--to=mst@redhat.com \
--cc=alexander@tsoy.me \
--cc=ani@anisinha.ca \
--cc=dennis.lissov@gmail.com \
--cc=eduardo@habkost.net \
--cc=imammedo@redhat.com \
--cc=pbonzini@redhat.com \
--cc=peter.maydell@linaro.org \
--cc=philmd@redhat.com \
--cc=qemu-devel@nongnu.org \
--cc=qemu-stable@nongnu.org \
--cc=richard.henderson@linaro.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).