qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [PULL 0/2] vfio queue
@ 2023-05-24  8:47 Cédric Le Goater
  2023-05-24  8:47 ` [PULL 1/2] vfio/pci: Fix a use-after-free issue Cédric Le Goater
                   ` (2 more replies)
  0 siblings, 3 replies; 10+ messages in thread
From: Cédric Le Goater @ 2023-05-24  8:47 UTC (permalink / raw)
  To: qemu-devel; +Cc: Richard Henderson, Alex Williamson, Cédric Le Goater

The following changes since commit aa33508196f4e2da04625bee36e1f7be5b9267e7:

  Merge tag 'mem-2023-05-23' of https://github.com/davidhildenbrand/qemu into staging (2023-05-23 10:57:25 -0700)

are available in the Git repository at:

  https://github.com/legoater/qemu/ tags/pull-vfio-20230524

for you to fetch changes up to dbdea0dbfe2cef9ef6c752e9077e4fc98724194c:

  util/vfio-helpers: Use g_file_read_link() (2023-05-24 09:21:22 +0200)

----------------------------------------------------------------
vfio queue:

* Fix for a memory corruption due to an extra free
* Fix for a compile breakage

----------------------------------------------------------------
Akihiko Odaki (1):
      util/vfio-helpers: Use g_file_read_link()

Zhenzhong Duan (1):
      vfio/pci: Fix a use-after-free issue

 hw/vfio/pci.c       | 2 +-
 util/vfio-helpers.c | 8 +++++---
 2 files changed, 6 insertions(+), 4 deletions(-)


^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PULL 1/2] vfio/pci: Fix a use-after-free issue
  2023-05-24  8:47 [PULL 0/2] vfio queue Cédric Le Goater
@ 2023-05-24  8:47 ` Cédric Le Goater
  2023-05-24  8:47 ` [PULL 2/2] util/vfio-helpers: Use g_file_read_link() Cédric Le Goater
  2023-05-25  0:46 ` [PULL 0/2] vfio queue Richard Henderson
  2 siblings, 0 replies; 10+ messages in thread
From: Cédric Le Goater @ 2023-05-24  8:47 UTC (permalink / raw)
  To: qemu-devel
  Cc: Richard Henderson, Alex Williamson, Zhenzhong Duan,
	Cédric Le Goater, Matthew Rosato,
	Philippe Mathieu-Daudé

From: Zhenzhong Duan <zhenzhong.duan@intel.com>

vbasedev->name is freed wrongly which leads to garbage VFIO trace log.
Fix it by allocating a dup of vbasedev->name and then free the dup.

Fixes: 2dca1b37a760 ("vfio/pci: add support for VF token")
Suggested-by: Alex Williamson <alex.williamson@redhat.com>
Signed-off-by: Zhenzhong Duan <zhenzhong.duan@intel.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Acked-by: Alex Williamson <alex.williamson@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Signed-off-by: Cédric Le Goater <clg@redhat.com>
---
 hw/vfio/pci.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/hw/vfio/pci.c b/hw/vfio/pci.c
index bf27a3990564..73874a94de12 100644
--- a/hw/vfio/pci.c
+++ b/hw/vfio/pci.c
@@ -2994,7 +2994,7 @@ static void vfio_realize(PCIDevice *pdev, Error **errp)
         qemu_uuid_unparse(&vdev->vf_token, uuid);
         name = g_strdup_printf("%s vf_token=%s", vbasedev->name, uuid);
     } else {
-        name = vbasedev->name;
+        name = g_strdup(vbasedev->name);
     }
 
     ret = vfio_get_device(group, name, vbasedev, errp);
-- 
2.40.1



^ permalink raw reply related	[flat|nested] 10+ messages in thread

* [PULL 2/2] util/vfio-helpers: Use g_file_read_link()
  2023-05-24  8:47 [PULL 0/2] vfio queue Cédric Le Goater
  2023-05-24  8:47 ` [PULL 1/2] vfio/pci: Fix a use-after-free issue Cédric Le Goater
@ 2023-05-24  8:47 ` Cédric Le Goater
  2023-05-25  0:46 ` [PULL 0/2] vfio queue Richard Henderson
  2 siblings, 0 replies; 10+ messages in thread
From: Cédric Le Goater @ 2023-05-24  8:47 UTC (permalink / raw)
  To: qemu-devel
  Cc: Richard Henderson, Alex Williamson, Akihiko Odaki,
	Philippe Mathieu-Daudé, Cédric Le Goater

From: Akihiko Odaki <akihiko.odaki@daynix.com>

When _FORTIFY_SOURCE=2, glibc version is 2.35, and GCC version is
12.1.0, the compiler complains as follows:

In file included from /usr/include/features.h:490,
                 from /usr/include/bits/libc-header-start.h:33,
                 from /usr/include/stdint.h:26,
                 from /usr/lib/gcc/aarch64-unknown-linux-gnu/12.1.0/include/stdint.h:9,
                 from /home/alarm/q/var/qemu/include/qemu/osdep.h:94,
                 from ../util/vfio-helpers.c:13:
In function 'readlink',
    inlined from 'sysfs_find_group_file' at ../util/vfio-helpers.c:116:9,
    inlined from 'qemu_vfio_init_pci' at ../util/vfio-helpers.c:326:18,
    inlined from 'qemu_vfio_open_pci' at ../util/vfio-helpers.c:517:9:
/usr/include/bits/unistd.h:119:10: error: argument 2 is null but the corresponding size argument 3 value is 4095 [-Werror=nonnull]
  119 |   return __glibc_fortify (readlink, __len, sizeof (char),
      |          ^~~~~~~~~~~~~~~

This error implies the allocated buffer can be NULL. Use
g_file_read_link(), which allocates buffer automatically to avoid the
error.

Signed-off-by: Akihiko Odaki <akihiko.odaki@daynix.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Signed-off-by: Cédric Le Goater <clg@redhat.com>
---
 util/vfio-helpers.c | 8 +++++---
 1 file changed, 5 insertions(+), 3 deletions(-)

diff --git a/util/vfio-helpers.c b/util/vfio-helpers.c
index 2d8af38f886a..f8bab46c68fa 100644
--- a/util/vfio-helpers.c
+++ b/util/vfio-helpers.c
@@ -106,15 +106,17 @@ struct QEMUVFIOState {
  */
 static char *sysfs_find_group_file(const char *device, Error **errp)
 {
+    g_autoptr(GError) gerr = NULL;
     char *sysfs_link;
     char *sysfs_group;
     char *p;
     char *path = NULL;
 
     sysfs_link = g_strdup_printf("/sys/bus/pci/devices/%s/iommu_group", device);
-    sysfs_group = g_malloc0(PATH_MAX);
-    if (readlink(sysfs_link, sysfs_group, PATH_MAX - 1) == -1) {
-        error_setg_errno(errp, errno, "Failed to find iommu group sysfs path");
+    sysfs_group = g_file_read_link(sysfs_link, &gerr);
+    if (gerr) {
+        error_setg(errp, "Failed to find iommu group sysfs path: %s",
+                   gerr->message);
         goto out;
     }
     p = strrchr(sysfs_group, '/');
-- 
2.40.1



^ permalink raw reply related	[flat|nested] 10+ messages in thread

* Re: [PULL 0/2] vfio queue
  2023-05-24  8:47 [PULL 0/2] vfio queue Cédric Le Goater
  2023-05-24  8:47 ` [PULL 1/2] vfio/pci: Fix a use-after-free issue Cédric Le Goater
  2023-05-24  8:47 ` [PULL 2/2] util/vfio-helpers: Use g_file_read_link() Cédric Le Goater
@ 2023-05-25  0:46 ` Richard Henderson
  2 siblings, 0 replies; 10+ messages in thread
From: Richard Henderson @ 2023-05-25  0:46 UTC (permalink / raw)
  To: Cédric Le Goater, qemu-devel; +Cc: Alex Williamson

On 5/24/23 01:47, Cédric Le Goater wrote:
> The following changes since commit aa33508196f4e2da04625bee36e1f7be5b9267e7:
> 
>    Merge tag 'mem-2023-05-23' ofhttps://github.com/davidhildenbrand/qemu  into staging (2023-05-23 10:57:25 -0700)
> 
> are available in the Git repository at:
> 
>    https://github.com/legoater/qemu/  tags/pull-vfio-20230524
> 
> for you to fetch changes up to dbdea0dbfe2cef9ef6c752e9077e4fc98724194c:
> 
>    util/vfio-helpers: Use g_file_read_link() (2023-05-24 09:21:22 +0200)
> 
> ----------------------------------------------------------------
> vfio queue:
> 
> * Fix for a memory corruption due to an extra free
> * Fix for a compile breakage

Applied, thanks.  Please update https://wiki.qemu.org/ChangeLog/8.1 as appropriate.


r~



^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PULL 0/2] vfio queue
@ 2024-01-29  8:41 Cédric Le Goater
  2024-01-29 17:22 ` Peter Maydell
  0 siblings, 1 reply; 10+ messages in thread
From: Cédric Le Goater @ 2024-01-29  8:41 UTC (permalink / raw)
  To: qemu-devel; +Cc: Cédric Le Goater

The following changes since commit 7a1dc45af581d2b643cdbf33c01fd96271616fbd:

  Merge tag 'pull-target-arm-20240126' of https://git.linaro.org/people/pmaydell/qemu-arm into staging (2024-01-26 18:16:35 +0000)

are available in the Git repository at:

  https://github.com/legoater/qemu/ tags/pull-vfio-20240129

for you to fetch changes up to d2b668fca5652760b435ce812a743bba03d2f316:

  vfio/pci: Clear MSI-X IRQ index always (2024-01-29 08:26:25 +0100)

----------------------------------------------------------------
vfio queue:

* Array type cleanup
* Fix for IRQ enablement

----------------------------------------------------------------
Cédric Le Goater (1):
      vfio/pci: Clear MSI-X IRQ index always

Paolo Bonzini (1):
      vfio: use matching sizeof type

 hw/vfio/common.c | 2 +-
 hw/vfio/pci.c    | 8 +++++---
 2 files changed, 6 insertions(+), 4 deletions(-)


^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PULL 0/2] vfio queue
  2024-01-29  8:41 Cédric Le Goater
@ 2024-01-29 17:22 ` Peter Maydell
  0 siblings, 0 replies; 10+ messages in thread
From: Peter Maydell @ 2024-01-29 17:22 UTC (permalink / raw)
  To: Cédric Le Goater; +Cc: qemu-devel

On Mon, 29 Jan 2024 at 08:42, Cédric Le Goater <clg@redhat.com> wrote:
>
> The following changes since commit 7a1dc45af581d2b643cdbf33c01fd96271616fbd:
>
>   Merge tag 'pull-target-arm-20240126' of https://git.linaro.org/people/pmaydell/qemu-arm into staging (2024-01-26 18:16:35 +0000)
>
> are available in the Git repository at:
>
>   https://github.com/legoater/qemu/ tags/pull-vfio-20240129
>
> for you to fetch changes up to d2b668fca5652760b435ce812a743bba03d2f316:
>
>   vfio/pci: Clear MSI-X IRQ index always (2024-01-29 08:26:25 +0100)
>
> ----------------------------------------------------------------
> vfio queue:
>
> * Array type cleanup
> * Fix for IRQ enablement
>
> ----------------------------------------------------------------


Applied, thanks.

Please update the changelog at https://wiki.qemu.org/ChangeLog/9.0
for any user-visible changes.

-- PMM


^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PULL 0/2] vfio queue
@ 2024-03-10 19:19 Cédric Le Goater
  2024-03-12 11:05 ` Peter Maydell
  0 siblings, 1 reply; 10+ messages in thread
From: Cédric Le Goater @ 2024-03-10 19:19 UTC (permalink / raw)
  To: qemu-devel; +Cc: Cédric Le Goater

The following changes since commit cbccded4a2b5d685a426a437e25f67d3a375b292:

  Merge tag 'pull-riscv-to-apply-20240308-1' of https://github.com/alistair23/qemu into staging (2024-03-08 11:47:01 +0000)

are available in the Git repository at:

  https://github.com/legoater/qemu/ tags/pull-vfio-20240310

for you to fetch changes up to 0cb51c183a91e882b10ead4ddf2321296a537c47:

  vfio: allow cpr-reboot migration if suspended (2024-03-08 22:10:13 +0100)

----------------------------------------------------------------
vfio queue:

* Allow cpr-reboot for vfio

----------------------------------------------------------------
Steve Sistare (2):
      vfio: register container for cpr
      vfio: allow cpr-reboot migration if suspended

 include/hw/vfio/vfio-common.h         |  3 +++
 include/hw/vfio/vfio-container-base.h |  1 +
 hw/vfio/common.c                      |  2 +-
 hw/vfio/container.c                   | 11 +++++++++-
 hw/vfio/cpr.c                         | 39 +++++++++++++++++++++++++++++++++++
 hw/vfio/iommufd.c                     |  6 ++++++
 hw/vfio/migration.c                   |  2 +-
 hw/vfio/meson.build                   |  1 +
 8 files changed, 62 insertions(+), 3 deletions(-)
 create mode 100644 hw/vfio/cpr.c


^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PULL 0/2] vfio queue
  2024-03-10 19:19 Cédric Le Goater
@ 2024-03-12 11:05 ` Peter Maydell
  0 siblings, 0 replies; 10+ messages in thread
From: Peter Maydell @ 2024-03-12 11:05 UTC (permalink / raw)
  To: Cédric Le Goater; +Cc: qemu-devel

On Sun, 10 Mar 2024 at 19:20, Cédric Le Goater <clg@redhat.com> wrote:
>
> The following changes since commit cbccded4a2b5d685a426a437e25f67d3a375b292:
>
>   Merge tag 'pull-riscv-to-apply-20240308-1' of https://github.com/alistair23/qemu into staging (2024-03-08 11:47:01 +0000)
>
> are available in the Git repository at:
>
>   https://github.com/legoater/qemu/ tags/pull-vfio-20240310
>
> for you to fetch changes up to 0cb51c183a91e882b10ead4ddf2321296a537c47:
>
>   vfio: allow cpr-reboot migration if suspended (2024-03-08 22:10:13 +0100)
>
> ----------------------------------------------------------------
> vfio queue:
>
> * Allow cpr-reboot for vfio
>
> ----------------------------------------------------------------


Applied, thanks.

Please update the changelog at https://wiki.qemu.org/ChangeLog/9.0
for any user-visible changes.

-- PMM


^ permalink raw reply	[flat|nested] 10+ messages in thread

* [PULL 0/2] vfio queue
@ 2024-11-05 16:58 Cédric Le Goater
  2024-11-06 17:28 ` Peter Maydell
  0 siblings, 1 reply; 10+ messages in thread
From: Cédric Le Goater @ 2024-11-05 16:58 UTC (permalink / raw)
  To: qemu-devel; +Cc: Alex Williamson, Cédric Le Goater

The following changes since commit 9a7b0a8618b1293d589a631183e80791ad7bf552:

  Merge tag 'pull-aspeed-20241104' of https://github.com/legoater/qemu into staging (2024-11-05 10:06:08 +0000)

are available in the Git repository at:

  https://github.com/legoater/qemu/ tags/pull-vfio-20241105

for you to fetch changes up to 89b516152777a8b54b117d90690ed9be62ba1177:

  vfio/migration: Add vfio_save_block_precopy_empty_hit trace event (2024-11-05 15:51:14 +0100)

----------------------------------------------------------------
vfio queue:

* Added migration trace events

----------------------------------------------------------------
Maciej S. Szmigiero (2):
      vfio/migration: Add save_{iterate, complete_precopy}_start trace events
      vfio/migration: Add vfio_save_block_precopy_empty_hit trace event

 include/hw/vfio/vfio-common.h |  3 +++
 hw/vfio/migration.c           | 17 +++++++++++++++++
 hw/vfio/trace-events          |  3 +++
 3 files changed, 23 insertions(+)



^ permalink raw reply	[flat|nested] 10+ messages in thread

* Re: [PULL 0/2] vfio queue
  2024-11-05 16:58 Cédric Le Goater
@ 2024-11-06 17:28 ` Peter Maydell
  0 siblings, 0 replies; 10+ messages in thread
From: Peter Maydell @ 2024-11-06 17:28 UTC (permalink / raw)
  To: Cédric Le Goater; +Cc: qemu-devel, Alex Williamson

On Tue, 5 Nov 2024 at 16:59, Cédric Le Goater <clg@redhat.com> wrote:
>
> The following changes since commit 9a7b0a8618b1293d589a631183e80791ad7bf552:
>
>   Merge tag 'pull-aspeed-20241104' of https://github.com/legoater/qemu into staging (2024-11-05 10:06:08 +0000)
>
> are available in the Git repository at:
>
>   https://github.com/legoater/qemu/ tags/pull-vfio-20241105
>
> for you to fetch changes up to 89b516152777a8b54b117d90690ed9be62ba1177:
>
>   vfio/migration: Add vfio_save_block_precopy_empty_hit trace event (2024-11-05 15:51:14 +0100)
>
> ----------------------------------------------------------------
> vfio queue:
>
> * Added migration trace events
>


Applied, thanks.

Please update the changelog at https://wiki.qemu.org/ChangeLog/9.2
for any user-visible changes.

-- PMM


^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2024-11-06 17:28 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-05-24  8:47 [PULL 0/2] vfio queue Cédric Le Goater
2023-05-24  8:47 ` [PULL 1/2] vfio/pci: Fix a use-after-free issue Cédric Le Goater
2023-05-24  8:47 ` [PULL 2/2] util/vfio-helpers: Use g_file_read_link() Cédric Le Goater
2023-05-25  0:46 ` [PULL 0/2] vfio queue Richard Henderson
  -- strict thread matches above, loose matches on Subject: below --
2024-01-29  8:41 Cédric Le Goater
2024-01-29 17:22 ` Peter Maydell
2024-03-10 19:19 Cédric Le Goater
2024-03-12 11:05 ` Peter Maydell
2024-11-05 16:58 Cédric Le Goater
2024-11-06 17:28 ` Peter Maydell

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).