* [PATCH v2] vfio/pci: Fix a use-after-free issue
@ 2023-05-17 2:46 Zhenzhong Duan
2023-05-17 6:11 ` Cédric Le Goater
` (2 more replies)
0 siblings, 3 replies; 6+ messages in thread
From: Zhenzhong Duan @ 2023-05-17 2:46 UTC (permalink / raw)
To: qemu-devel; +Cc: minwoo.im, alex.williamson, clg, chao.p.peng
vbasedev->name is freed wrongly which leads to garbage VFIO trace log.
Fix it by allocating a dup of vbasedev->name and then free the dup.
Fixes: 2dca1b37a7 ("vfio/pci: add support for VF token")
Suggested-by: Alex Williamson <alex.williamson@redhat.com>
Signed-off-by: Zhenzhong Duan <zhenzhong.duan@intel.com>
---
v2: "toke" -> "token", Cedric
Update with Alex suggested change
hw/vfio/pci.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/hw/vfio/pci.c b/hw/vfio/pci.c
index bf27a3990564..73874a94de12 100644
--- a/hw/vfio/pci.c
+++ b/hw/vfio/pci.c
@@ -2994,7 +2994,7 @@ static void vfio_realize(PCIDevice *pdev, Error **errp)
qemu_uuid_unparse(&vdev->vf_token, uuid);
name = g_strdup_printf("%s vf_token=%s", vbasedev->name, uuid);
} else {
- name = vbasedev->name;
+ name = g_strdup(vbasedev->name);
}
ret = vfio_get_device(group, name, vbasedev, errp);
--
2.34.1
^ permalink raw reply related [flat|nested] 6+ messages in thread
* Re: [PATCH v2] vfio/pci: Fix a use-after-free issue
2023-05-17 2:46 [PATCH v2] vfio/pci: Fix a use-after-free issue Zhenzhong Duan
@ 2023-05-17 6:11 ` Cédric Le Goater
2023-05-23 17:00 ` Matthew Rosato
2023-05-24 6:08 ` Philippe Mathieu-Daudé
2 siblings, 0 replies; 6+ messages in thread
From: Cédric Le Goater @ 2023-05-17 6:11 UTC (permalink / raw)
To: Zhenzhong Duan, qemu-devel; +Cc: minwoo.im, alex.williamson, chao.p.peng
On 5/17/23 04:46, Zhenzhong Duan wrote:
> vbasedev->name is freed wrongly which leads to garbage VFIO trace log.
> Fix it by allocating a dup of vbasedev->name and then free the dup.
>
> Fixes: 2dca1b37a7 ("vfio/pci: add support for VF token")
> Suggested-by: Alex Williamson <alex.williamson@redhat.com>
> Signed-off-by: Zhenzhong Duan <zhenzhong.duan@intel.com>
Reviewed-by: Cédric Le Goater <clg@redhat.com>
Thanks,
C.
> ---
> v2: "toke" -> "token", Cedric
> Update with Alex suggested change
>
> hw/vfio/pci.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/hw/vfio/pci.c b/hw/vfio/pci.c
> index bf27a3990564..73874a94de12 100644
> --- a/hw/vfio/pci.c
> +++ b/hw/vfio/pci.c
> @@ -2994,7 +2994,7 @@ static void vfio_realize(PCIDevice *pdev, Error **errp)
> qemu_uuid_unparse(&vdev->vf_token, uuid);
> name = g_strdup_printf("%s vf_token=%s", vbasedev->name, uuid);
> } else {
> - name = vbasedev->name;
> + name = g_strdup(vbasedev->name);
> }
>
> ret = vfio_get_device(group, name, vbasedev, errp);
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH v2] vfio/pci: Fix a use-after-free issue
2023-05-17 2:46 [PATCH v2] vfio/pci: Fix a use-after-free issue Zhenzhong Duan
2023-05-17 6:11 ` Cédric Le Goater
@ 2023-05-23 17:00 ` Matthew Rosato
2023-05-23 17:17 ` Alex Williamson
2023-05-24 6:08 ` Philippe Mathieu-Daudé
2 siblings, 1 reply; 6+ messages in thread
From: Matthew Rosato @ 2023-05-23 17:00 UTC (permalink / raw)
To: Zhenzhong Duan, qemu-devel; +Cc: minwoo.im, alex.williamson, clg, chao.p.peng
On 5/16/23 10:46 PM, Zhenzhong Duan wrote:
> vbasedev->name is freed wrongly which leads to garbage VFIO trace log.
> Fix it by allocating a dup of vbasedev->name and then free the dup.
>
> Fixes: 2dca1b37a7 ("vfio/pci: add support for VF token")
> Suggested-by: Alex Williamson <alex.williamson@redhat.com>
> Signed-off-by: Zhenzhong Duan <zhenzhong.duan@intel.com>
Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
Also verified that this resolves an issue seen on s390, as we were seeing not just garbage logs but QEMU crashes in certain cases e.g. during device unplug. Thanks!
> ---
> v2: "toke" -> "token", Cedric
> Update with Alex suggested change
>
> hw/vfio/pci.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/hw/vfio/pci.c b/hw/vfio/pci.c
> index bf27a3990564..73874a94de12 100644
> --- a/hw/vfio/pci.c
> +++ b/hw/vfio/pci.c
> @@ -2994,7 +2994,7 @@ static void vfio_realize(PCIDevice *pdev, Error **errp)
> qemu_uuid_unparse(&vdev->vf_token, uuid);
> name = g_strdup_printf("%s vf_token=%s", vbasedev->name, uuid);
> } else {
> - name = vbasedev->name;
> + name = g_strdup(vbasedev->name);
> }
>
> ret = vfio_get_device(group, name, vbasedev, errp);
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH v2] vfio/pci: Fix a use-after-free issue
2023-05-23 17:00 ` Matthew Rosato
@ 2023-05-23 17:17 ` Alex Williamson
2023-05-23 17:52 ` Alex Williamson
0 siblings, 1 reply; 6+ messages in thread
From: Alex Williamson @ 2023-05-23 17:17 UTC (permalink / raw)
To: Matthew Rosato; +Cc: Zhenzhong Duan, qemu-devel, minwoo.im, clg, chao.p.peng
On Tue, 23 May 2023 13:00:53 -0400
Matthew Rosato <mjrosato@linux.ibm.com> wrote:
> On 5/16/23 10:46 PM, Zhenzhong Duan wrote:
> > vbasedev->name is freed wrongly which leads to garbage VFIO trace log.
> > Fix it by allocating a dup of vbasedev->name and then free the dup.
> >
> > Fixes: 2dca1b37a7 ("vfio/pci: add support for VF token")
> > Suggested-by: Alex Williamson <alex.williamson@redhat.com>
> > Signed-off-by: Zhenzhong Duan <zhenzhong.duan@intel.com>
>
> Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
>
> Also verified that this resolves an issue seen on s390, as we were
> seeing not just garbage logs but QEMU crashes in certain cases e.g.
> during device unplug. Thanks!
Thanks for the testing and reminder, I'll get a pull request out for
this. Thanks,
Alex
> > ---
> > v2: "toke" -> "token", Cedric
> > Update with Alex suggested change
> >
> > hw/vfio/pci.c | 2 +-
> > 1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/hw/vfio/pci.c b/hw/vfio/pci.c
> > index bf27a3990564..73874a94de12 100644
> > --- a/hw/vfio/pci.c
> > +++ b/hw/vfio/pci.c
> > @@ -2994,7 +2994,7 @@ static void vfio_realize(PCIDevice *pdev,
> > Error **errp) qemu_uuid_unparse(&vdev->vf_token, uuid);
> > name = g_strdup_printf("%s vf_token=%s", vbasedev->name,
> > uuid); } else {
> > - name = vbasedev->name;
> > + name = g_strdup(vbasedev->name);
> > }
> >
> > ret = vfio_get_device(group, name, vbasedev, errp);
>
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH v2] vfio/pci: Fix a use-after-free issue
2023-05-23 17:17 ` Alex Williamson
@ 2023-05-23 17:52 ` Alex Williamson
0 siblings, 0 replies; 6+ messages in thread
From: Alex Williamson @ 2023-05-23 17:52 UTC (permalink / raw)
To: Matthew Rosato; +Cc: Zhenzhong Duan, qemu-devel, minwoo.im, clg, chao.p.peng
On Tue, 23 May 2023 11:17:47 -0600
Alex Williamson <alex.williamson@redhat.com> wrote:
> On Tue, 23 May 2023 13:00:53 -0400
> Matthew Rosato <mjrosato@linux.ibm.com> wrote:
>
> > On 5/16/23 10:46 PM, Zhenzhong Duan wrote:
> > > vbasedev->name is freed wrongly which leads to garbage VFIO trace log.
> > > Fix it by allocating a dup of vbasedev->name and then free the dup.
> > >
> > > Fixes: 2dca1b37a7 ("vfio/pci: add support for VF token")
> > > Suggested-by: Alex Williamson <alex.williamson@redhat.com>
> > > Signed-off-by: Zhenzhong Duan <zhenzhong.duan@intel.com>
> >
> > Reviewed-by: Matthew Rosato <mjrosato@linux.ibm.com>
> >
> > Also verified that this resolves an issue seen on s390, as we were
> > seeing not just garbage logs but QEMU crashes in certain cases e.g.
> > during device unplug. Thanks!
>
> Thanks for the testing and reminder, I'll get a pull request out for
> this. Thanks,
Actually Cedric volunteered to bundle this with some pending patches,
so...
Acked-by: Alex Williamson <alex.williamson@redhat.com>
> > > ---
> > > v2: "toke" -> "token", Cedric
> > > Update with Alex suggested change
> > >
> > > hw/vfio/pci.c | 2 +-
> > > 1 file changed, 1 insertion(+), 1 deletion(-)
> > >
> > > diff --git a/hw/vfio/pci.c b/hw/vfio/pci.c
> > > index bf27a3990564..73874a94de12 100644
> > > --- a/hw/vfio/pci.c
> > > +++ b/hw/vfio/pci.c
> > > @@ -2994,7 +2994,7 @@ static void vfio_realize(PCIDevice *pdev,
> > > Error **errp) qemu_uuid_unparse(&vdev->vf_token, uuid);
> > > name = g_strdup_printf("%s vf_token=%s", vbasedev->name,
> > > uuid); } else {
> > > - name = vbasedev->name;
> > > + name = g_strdup(vbasedev->name);
> > > }
> > >
> > > ret = vfio_get_device(group, name, vbasedev, errp);
> >
>
^ permalink raw reply [flat|nested] 6+ messages in thread
* Re: [PATCH v2] vfio/pci: Fix a use-after-free issue
2023-05-17 2:46 [PATCH v2] vfio/pci: Fix a use-after-free issue Zhenzhong Duan
2023-05-17 6:11 ` Cédric Le Goater
2023-05-23 17:00 ` Matthew Rosato
@ 2023-05-24 6:08 ` Philippe Mathieu-Daudé
2 siblings, 0 replies; 6+ messages in thread
From: Philippe Mathieu-Daudé @ 2023-05-24 6:08 UTC (permalink / raw)
To: Zhenzhong Duan, qemu-devel; +Cc: minwoo.im, alex.williamson, clg, chao.p.peng
On 17/5/23 04:46, Zhenzhong Duan wrote:
> vbasedev->name is freed wrongly which leads to garbage VFIO trace log.
> Fix it by allocating a dup of vbasedev->name and then free the dup.
>
> Fixes: 2dca1b37a7 ("vfio/pci: add support for VF token")
> Suggested-by: Alex Williamson <alex.williamson@redhat.com>
> Signed-off-by: Zhenzhong Duan <zhenzhong.duan@intel.com>
> ---
> v2: "toke" -> "token", Cedric
> Update with Alex suggested change
>
> hw/vfio/pci.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
Reviewed-by: Philippe Mathieu-Daudé <philmd@linaro.org>
^ permalink raw reply [flat|nested] 6+ messages in thread
end of thread, other threads:[~2023-05-24 6:08 UTC | newest]
Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2023-05-17 2:46 [PATCH v2] vfio/pci: Fix a use-after-free issue Zhenzhong Duan
2023-05-17 6:11 ` Cédric Le Goater
2023-05-23 17:00 ` Matthew Rosato
2023-05-23 17:17 ` Alex Williamson
2023-05-23 17:52 ` Alex Williamson
2023-05-24 6:08 ` Philippe Mathieu-Daudé
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).