Go to file
Simon Gaiser 2e63eb2bec xen/pt: Set is_express to avoid out-of-bounds write
The passed-through device might be an express device. In this case the
old code allocated a too small emulated config space in
pci_config_alloc() since pci_config_size() returned the size for a
non-express device. This leads to an out-of-bound write in
xen_pt_config_reg_init(), which sometimes results in crashes. So set
is_express as already done for KVM in vfio-pci.

Shortened ASan report:

==17512==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x611000041648 at pc 0x55e0fdac51ff bp 0x7ffe4af07410 sp 0x7ffe4af07408
WRITE of size 2 at 0x611000041648 thread T0
    #0 0x55e0fdac51fe in memcpy /usr/include/x86_64-linux-gnu/bits/string3.h:53
    #1 0x55e0fdac51fe in stw_he_p include/qemu/bswap.h:330
    #2 0x55e0fdac51fe in stw_le_p include/qemu/bswap.h:379
    #3 0x55e0fdac51fe in pci_set_word include/hw/pci/pci.h:490
    #4 0x55e0fdac51fe in xen_pt_config_reg_init hw/xen/xen_pt_config_init.c:1991
    #5 0x55e0fdac51fe in xen_pt_config_init hw/xen/xen_pt_config_init.c:2067
    #6 0x55e0fdabcf4d in xen_pt_realize hw/xen/xen_pt.c:830
    #7 0x55e0fdf59666 in pci_qdev_realize hw/pci/pci.c:2034
    #8 0x55e0fdda7d3d in device_set_realized hw/core/qdev.c:914
[...]

0x611000041648 is located 8 bytes to the right of 256-byte region [0x611000041540,0x611000041640)
allocated by thread T0 here:
    #0 0x7ff596a94bb8 in __interceptor_calloc (/usr/lib/x86_64-linux-gnu/libasan.so.4+0xd9bb8)
    #1 0x7ff57da66580 in g_malloc0 (/lib/x86_64-linux-gnu/libglib-2.0.so.0+0x50580)
    #2 0x55e0fdda7d3d in device_set_realized hw/core/qdev.c:914
[...]

Signed-off-by: Simon Gaiser <hw42@ipsumj.de>
Acked-by: Stefano Stabellini <sstabellini@kernel.org>
Signed-off-by: Stefano Stabellini <sstabellini@kernel.org>
2017-12-14 16:11:53 -08:00
accel tcg: Fix compilation without TCG 2017-11-23 10:02:44 +00:00
audio buildsys: Move audio libs to per object 2017-09-22 10:20:34 +08:00
backends tpm: move recv_data_callback to TPM interface 2017-10-19 11:42:33 -04:00
block block/nfs: fix nfs_client_open for filesize greater than 1TB 2017-11-29 15:28:15 +01:00
bsd-user tcg: introduce regions to split code_gen_buffer 2017-10-24 13:53:42 -07:00
capstone@22ead3e0bf disas: Add capstone as submodule 2017-10-26 11:56:20 +02:00
chardev char: don't skip client cleanup if 'connected' flag is unset 2017-10-12 12:10:37 +02:00
contrib libvhost-user: Support VHOST_USER_SET_SLAVE_REQ_FD 2017-10-12 16:57:50 +02:00
crypto crypto: afalg: fix a NULL pointer dereference 2017-11-08 11:05:09 +00:00
default-configs build-sys: restrict vmcoreinfo to fw_cfg+dma capable targets 2017-11-16 17:46:53 +02:00
disas target/arm: Move BE32 disassembler fixup 2017-10-25 11:54:52 +02:00
docs QAPI & interop: Clarify events emitted by 'block-job-cancel' 2017-11-27 14:59:35 +01:00
dtc@558cd81bdd dtc: Revert unintentional submodule downgrade from commit c2cabb3422 2017-03-16 14:11:15 +00:00
fpu softfloat: define floatx80_round() 2017-06-29 20:27:39 +02:00
fsdev fsdev: fix memory leak in main() 2017-09-05 14:01:16 +02:00
gdb-xml s390x/gdb: add gs registers 2017-07-14 12:29:49 +02:00
hw xen/pt: Set is_express to avoid out-of-bounds write 2017-12-14 16:11:53 -08:00
include ui: generate qcode to linux mappings 2017-12-14 15:24:30 -08:00
io trivial patches for 2017-10-16 2017-10-17 13:13:03 +01:00
libdecnumber build: remove CONFIG_LIBDECNUMBER 2017-10-16 18:03:52 +02:00
linux-headers linux-headers: sync against v4.14-rc1 2017-09-29 10:58:31 +02:00
linux-user linux-user: Fix calculation of auxv length 2017-11-20 16:15:41 +02:00
migration migration/ram.c: do not set 'postcopy_running' in POSTCOPY_INCOMING_END 2017-11-22 08:50:37 +01:00
nbd nbd/server: CVE-2017-15118 Stack smash on large export name 2017-11-28 06:58:01 -06:00
net colo-compare: fix the dangerous assignment 2017-11-20 11:08:00 +08:00
pc-bios Use qemu.org domain name 2017-11-21 13:34:13 +00:00
po po: add missing translations in de, fr, it, zh 2016-12-14 18:47:19 +00:00
qapi QAPI & interop: Clarify events emitted by 'block-job-cancel' 2017-11-27 14:59:35 +01:00
qga qga: replace GetIfEntry with GetIfEntry2 for interface stats 2017-11-20 14:45:31 -06:00
qobject qapi: Add qobject_is_equal() 2017-11-17 18:21:30 +01:00
qom tcg: Add CPUState cflags_next_tb 2017-10-24 13:53:41 -07:00
replay migration: pre_save return int 2017-09-27 11:35:59 +01:00
roms seabios: update to 1.11 final 2017-11-14 15:36:08 +01:00
scripts dump-guest-memory.py: fix No symbol "vmcoreinfo_find" 2017-12-01 19:05:58 +02:00
scsi qemu-pr-helper: use new libmultipath API 2017-10-18 10:15:09 +02:00
slirp slirp: don't zero the whole ti_i when m == NULL 2017-11-09 18:59:22 +01:00
stubs tpm: add stubs 2017-10-25 01:05:04 -04:00
target target/arm: Generate UNDEF for 32-bit Thumb2 insns 2017-12-11 17:11:27 +00:00
tcg tcg/s390x: Use constant pool for prologue 2017-11-03 09:33:45 +01:00
tests blockjob: remove clock argument from block_job_sleep_ns 2017-11-29 15:11:02 +01:00
trace Convert single line fprintf(.../n) to warn_report() 2017-09-19 14:09:34 +02:00
ui ui: generate qcode to linux mappings 2017-12-14 15:24:30 -08:00
util sockets: avoid crash when cleaning up sockets for an invalid FD 2017-11-28 10:48:04 +00:00
.dir-locals.el Add .dir-locals.el file to configure emacs coding style 2015-10-08 19:46:01 +03:00
.editorconfig add editorconfig 2017-07-20 09:56:56 +02:00
.exrc
.gdbinit .gdbinit: load QEMU sub-commands when gdb starts 2017-06-07 14:38:45 +01:00
.gitignore ui: add qemu-keymap and shader to .gitignore 2017-10-23 08:10:18 +02:00
.gitmodules disas: Add capstone as submodule 2017-10-26 11:56:20 +02:00
.mailmap MAINTAINERS: Update Paul Burton's email address 2017-11-06 07:36:43 -08:00
.shippable.yml shippable: add win32/64 targets 2017-07-18 10:58:36 +01:00
.travis.yml travis: move make -j flag out of script 2017-07-18 09:39:19 +01:00
arch_init.c audio: Rename hw/audio/audio.h to hw/audio/soundhw.h 2017-05-19 10:48:54 +02:00
balloon.c trace: switch to modular code generation for sub-directories 2017-01-31 17:11:18 +00:00
block.c block: Close a BlockDriverState completely even when bs->drv is NULL 2017-11-21 14:54:02 +01:00
blockdev-nbd.c nbd: Fix regression on resiliency to port scan 2017-06-15 11:04:05 +02:00
blockdev.c block: move ThrottleGroup membership to ThrottleGroupMember 2017-09-05 16:47:51 +02:00
blockjob.c blockjob: Make block_job_pause_all() keep a reference to the jobs 2017-12-04 17:44:51 +01:00
bootdevice.c Makefile: Move bootdevice.o to common-obj-y 2017-07-04 14:39:27 +02:00
bt-host.c all: Clean up includes 2016-02-04 17:41:30 +00:00
bt-vhci.c all: Clean up includes 2016-02-04 17:41:30 +00:00
Changelog Use HTTPS for qemu.org and other domains 2017-11-21 13:34:13 +00:00
CODING_STYLE coding_style: add point about 0x in trace-events 2017-08-01 12:13:07 +01:00
configure configure: Deal with OpenBSD/i386 emulation linker 2017-11-23 16:52:24 +00:00
COPYING
COPYING.LIB
COPYING.PYTHON scripts: add argparse module for Python 2.6 compatibility 2017-08-30 12:02:11 +01:00
cpus-common.c *_run_on_cpu: introduce run_on_cpu_data type 2016-10-31 15:00:25 +01:00
cpus.c tcg: enable multiple TCG contexts in softmmu 2017-10-24 13:53:42 -07:00
device_tree.c device_tree: fix compiler warnings (clang 5) 2017-05-07 09:57:51 +03:00
device-hotplug.c blockdev: Split monitor reference from BB creation 2016-03-17 15:47:56 +01:00
disas.c disas: Dump insn bytes along with capstone disassembly 2017-11-09 08:46:38 +01:00
dma-helpers.c block: explicitly acquire aiocontext in bottom halves that need it 2017-02-21 11:39:39 +00:00
dump.c kdump: set vmcoreinfo location 2017-10-15 05:54:40 +03:00
exec.c exec.c: Factor out before/after actions for notdirty memory writes 2017-11-21 12:09:25 +00:00
gdbstub.c Use qemu_tolower() and qemu_toupper(), not tolower() and toupper() 2017-07-21 10:32:41 +01:00
HACKING HACKING: document #include order 2017-01-03 16:38:47 +00:00
hmp-commands-info.hx hmp-commands-info: Change "@findex FOO" to "@findex info FOO" 2017-10-05 10:08:39 +01:00
hmp-commands.hx migrate: HMP migate_continue 2017-10-23 18:03:31 +02:00
hmp.c hmp: Replace error_report_err 2017-10-30 18:29:45 +00:00
hmp.h migrate: HMP migate_continue 2017-10-23 18:03:31 +02:00
ioport.c trace: switch to modular code generation for sub-directories 2017-01-31 17:11:18 +00:00
iothread.c iothread: delay the context release to finalize 2017-10-03 14:36:19 -04:00
LICENSE vfio: move hw/misc/vfio.c to hw/vfio/pci.c Move vfio.h into include/hw/vfio 2014-12-19 15:24:06 -07:00
MAINTAINERS Use HTTPS for qemu.org and other domains 2017-11-21 13:34:13 +00:00
Makefile ui: generate qcode to linux mappings 2017-12-14 15:24:30 -08:00
Makefile.objs tpm: add stubs 2017-10-25 01:05:04 -04:00
Makefile.target Fix build of console and GUI executables for Windows 2017-11-23 10:46:42 +00:00
memory_ldst.inc.c exec: introduce memory_ldst.inc.c 2016-12-22 16:00:23 +01:00
memory_mapping.c dump: fix memory_mapping_filter leak 2017-06-04 18:42:55 +03:00
memory.c memory: reuse section_from_flat_range() 2017-10-18 10:15:00 +02:00
module-common.c all: Clean up includes 2016-02-04 17:41:30 +00:00
monitor.c monitor: fix dangling CPU pointer 2017-10-30 18:46:32 +00:00
numa.c NUMA: Enable adding NUMA node implicitly 2017-11-16 17:46:53 +02:00
os-posix.c os-posix: Drop misleading comment 2017-10-16 21:01:37 +03:00
os-win32.c shutdown: Add source information to SHUTDOWN and RESET 2017-05-23 13:28:17 +02:00
qapi-schema.json target/s390x: change CPU type name to "s390x-cpu" 2017-10-30 08:56:28 +01:00
qdev-monitor.c pci-assign: Remove 2017-11-05 14:52:10 +01:00
qdict-test-data.txt
qemu-bridge-helper.c all: Remove unnecessary glib.h includes 2016-06-07 18:19:24 +03:00
qemu-doc.texi docs: Add image locking subsection 2017-11-27 11:25:41 +01:00
qemu-ga.texi qemu-ga: Remove stray 'q' in documentation 2016-10-28 18:17:23 +03:00
qemu-img-cmds.hx qemu-img: add --shrink flag for resize 2017-09-26 15:00:32 +02:00
qemu-img.c block: Add errp to bdrv_snapshot_goto() 2017-11-21 14:48:22 +01:00
qemu-img.texi qemu-img.1: Image invalidation on qemu-img commit 2017-10-26 14:59:18 +02:00
qemu-io-cmds.c qemu-io: Relax 'alloc' now that block-status doesn't assert 2017-10-26 14:45:57 +02:00
qemu-io.c qemu-io: Add -C for opening with copy-on-read 2017-10-06 16:28:58 +02:00
qemu-keymap.c tools: add qemu-keymap 2017-10-16 14:50:54 +02:00
qemu-nbd.c qapi: Change data type of the FOO_lookup generated for enum FOO 2017-09-04 13:09:13 +02:00
qemu-nbd.texi nbd: Add qemu-nbd -D for human-readable description 2016-11-02 09:28:55 +01:00
qemu-option-trace.texi docs: update manpage for stderr->log rename 2017-02-13 13:38:31 +00:00
qemu-options-wrapper.h hxtool: emit Texinfo headings as @subsection 2017-01-16 17:52:35 +01:00
qemu-options.h Clean up ill-advised or unusual header guards 2016-07-12 16:20:46 +02:00
qemu-options.hx qemu-options: Mention locking option of file driver 2017-11-27 11:25:41 +01:00
qemu-seccomp.c seccomp: add resourcecontrol argument to command line 2017-09-15 10:15:06 +02:00
qemu-tech.texi qemu-doc: merge qemu-tech and qemu-doc 2016-10-07 10:05:54 +02:00
qemu.nsi Use HTTPS for qemu.org and other domains 2017-11-21 13:34:13 +00:00
qemu.sasl Default to GSSAPI (Kerberos) instead of DIGEST-MD5 for SASL 2017-05-09 14:41:47 +01:00
qmp.c qmp: introduce query-memory-size-summary command 2017-09-14 15:52:10 +01:00
qtest.c qtest: Don't perform side effects inside assertion 2017-09-15 09:05:19 +02:00
README Use HTTPS for qemu.org and other domains 2017-11-21 13:34:13 +00:00
replication.c replication: Introduce new APIs to do replication operation 2016-09-13 11:00:56 +01:00
replication.h replication: Introduce new APIs to do replication operation 2016-09-13 11:00:56 +01:00
rules.mak docs: create interop/ subdirectory 2017-06-15 11:18:39 +02:00
thunk.c thunk: assert nb_fields is valid 2017-07-31 13:06:39 +03:00
tpm.c tpm: remove unnecessary #ifdef CONFIG_TPM 2017-10-25 01:05:35 -04:00
trace-events memory: trace FlatView creation and destruction 2017-09-22 01:06:51 +02:00
VERSION Update version for v2.11.0 release 2017-12-13 14:31:09 +00:00
version.rc Use HTTPS for qemu.org and other domains 2017-11-21 13:34:13 +00:00
vl.c NUMA: Enable adding NUMA node implicitly 2017-11-16 17:46:53 +02:00

         QEMU README
         ===========

QEMU is a generic and open source machine & userspace emulator and
virtualizer.

QEMU is capable of emulating a complete machine in software without any
need for hardware virtualization support. By using dynamic translation,
it achieves very good performance. QEMU can also integrate with the Xen
and KVM hypervisors to provide emulated hardware while allowing the
hypervisor to manage the CPU. With hypervisor support, QEMU can achieve
near native performance for CPUs. When QEMU emulates CPUs directly it is
capable of running operating systems made for one machine (e.g. an ARMv7
board) on a different machine (e.g. an x86_64 PC board).

QEMU is also capable of providing userspace API virtualization for Linux
and BSD kernel interfaces. This allows binaries compiled against one
architecture ABI (e.g. the Linux PPC64 ABI) to be run on a host using a
different architecture ABI (e.g. the Linux x86_64 ABI). This does not
involve any hardware emulation, simply CPU and syscall emulation.

QEMU aims to fit into a variety of use cases. It can be invoked directly
by users wishing to have full control over its behaviour and settings.
It also aims to facilitate integration into higher level management
layers, by providing a stable command line interface and monitor API.
It is commonly invoked indirectly via the libvirt library when using
open source applications such as oVirt, OpenStack and virt-manager.

QEMU as a whole is released under the GNU General Public License,
version 2. For full licensing details, consult the LICENSE file.


Building
========

QEMU is multi-platform software intended to be buildable on all modern
Linux platforms, OS-X, Win32 (via the Mingw64 toolchain) and a variety
of other UNIX targets. The simple steps to build QEMU are:

  mkdir build
  cd build
  ../configure
  make

Additional information can also be found online via the QEMU website:

  https://qemu.org/Hosts/Linux
  https://qemu.org/Hosts/Mac
  https://qemu.org/Hosts/W32


Submitting patches
==================

The QEMU source code is maintained under the GIT version control system.

   git clone git://git.qemu.org/qemu.git

When submitting patches, the preferred approach is to use 'git
format-patch' and/or 'git send-email' to format & send the mail to the
qemu-devel@nongnu.org mailing list. All patches submitted must contain
a 'Signed-off-by' line from the author. Patches should follow the
guidelines set out in the HACKING and CODING_STYLE files.

Additional information on submitting patches can be found online via
the QEMU website

  https://qemu.org/Contribute/SubmitAPatch
  https://qemu.org/Contribute/TrivialPatches


Bug reporting
=============

The QEMU project uses Launchpad as its primary upstream bug tracker. Bugs
found when running code built from QEMU git or upstream released sources
should be reported via:

  https://bugs.launchpad.net/qemu/

If using QEMU via an operating system vendor pre-built binary package, it
is preferable to report bugs to the vendor's own bug tracker first. If
the bug is also known to affect latest upstream code, it can also be
reported via launchpad.

For additional information on bug reporting consult:

  https://qemu.org/Contribute/ReportABug


Contact
=======

The QEMU community can be contacted in a number of ways, with the two
main methods being email and IRC

 - qemu-devel@nongnu.org
   https://lists.nongnu.org/mailman/listinfo/qemu-devel
 - #qemu on irc.oftc.net

Information on additional methods of contacting the community can be
found online via the QEMU website:

  https://qemu.org/Contribute/StartHere

-- End