qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
* [Qemu-devel] [PATCH v2 0/2] Avoid sending zero-size packets
@ 2019-07-22 13:24 Oleinik, Alexander
  2019-07-22 13:24 ` [Qemu-devel] [PATCH v2 1/2] net: assert that tx packets have nonzero size Oleinik, Alexander
                   ` (3 more replies)
  0 siblings, 4 replies; 7+ messages in thread
From: Oleinik, Alexander @ 2019-07-22 13:24 UTC (permalink / raw)
  To: qemu-devel@nongnu.org
  Cc: pbonzini@redhat.com, bsd@redhat.com, stefanha@redhat.com,
	Oleinik, Alexander

While fuzzing the virtio-net tx vq, I ran into an assertion failure due
to iov_copy offsets larger than the total iov size. Though there is
a check to cover this, it does not execute when !n->has_vnet_hdr. This
patch tries to fix this. 
The call stack for the assertion failure:

#8 in __assert_fail (libc.so.6+0x300f1)
#9 in iov_copy iov.c:266:5
#10 in virtio_net_flush_tx virtio-net.c:2073:23
#11 in virtio_net_tx_bh virtio-net.c:2197:11
#12 in aio_bh_poll async.c:118:13
#13 in aio_dispatch aio-posix.c:460:5
#14 in aio_ctx_dispatch async.c:261:5
#15 in g_main_context_dispatch (libglib-2.0.so.0+0x4df2d)
#16 in glib_pollfds_poll main-loop.c:213:9
#17 in os_host_main_loop_wait main-loop.c:236
#18 in main_loop_wait main-loop.c:512
#19 in virtio_net_tx_fuzz virtio-net-fuzz.c:160:3

v2: add details to  comment for the change to qemu_sendv_packet_async

Alexander Oleinik (2):
  net: assert that tx packets have nonzero size
  virtio-net: check that tx packet has positive size

 hw/net/virtio-net.c | 15 +++++++++------
 net/net.c           |  9 +++++++++
 2 files changed, 18 insertions(+), 6 deletions(-)

-- 
2.20.1



^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2019-11-21 13:53 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-07-22 13:24 [Qemu-devel] [PATCH v2 0/2] Avoid sending zero-size packets Oleinik, Alexander
2019-07-22 13:24 ` [Qemu-devel] [PATCH v2 1/2] net: assert that tx packets have nonzero size Oleinik, Alexander
2019-11-07  4:21   ` Jason Wang
2019-11-21 13:51     ` Alexander Bulekov
2019-07-22 13:24 ` [Qemu-devel] [PATCH v2 2/2] virtio-net: check that tx packet has positive size Oleinik, Alexander
2019-07-23 12:55 ` [Qemu-devel] [PATCH v2 0/2] Avoid sending zero-size packets Stefan Hajnoczi
2019-11-06 15:33 ` Stefan Hajnoczi

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).