Go to file
Claudio Fontana 36f18c6989 pci: fix overflow in snprintf string formatting
the code in pcibus_get_fw_dev_path contained the potential for a
stack buffer overflow of 1 byte, potentially writing to the stack an
extra NUL byte.

This overflow could happen if the PCI slot is >= 0x10000000,
and the PCI function is >= 0x10000000, due to the size parameter
of snprintf being incorrectly calculated in the call:

    if (PCI_FUNC(d->devfn))
        snprintf(path + off, sizeof(path) + off, ",%x", PCI_FUNC(d->devfn));

since the off obtained from a previous call to snprintf is added
instead of subtracted from the total available size of the buffer.

Without the accurate size guard from snprintf, we end up writing in the
worst case:

name (32) + "@" (1) + SLOT (8) + "," (1) + FUNC (8) + term NUL (1) = 51 bytes

In order to provide something more robust, replace all of the code in
pcibus_get_fw_dev_path with a single call to g_strdup_printf,
so there is no need to rely on manual calculations.

Found by compiling QEMU with FORTIFY_SOURCE=3 as the error:

*** buffer overflow detected ***: terminated

Thread 1 "qemu-system-x86" received signal SIGABRT, Aborted.
[Switching to Thread 0x7ffff642c380 (LWP 121307)]
0x00007ffff71ff55c in __pthread_kill_implementation () from /lib64/libc.so.6
(gdb) bt
 #0  0x00007ffff71ff55c in __pthread_kill_implementation () at /lib64/libc.so.6
 #1  0x00007ffff71ac6f6 in raise () at /lib64/libc.so.6
 #2  0x00007ffff7195814 in abort () at /lib64/libc.so.6
 #3  0x00007ffff71f279e in __libc_message () at /lib64/libc.so.6
 #4  0x00007ffff729767a in __fortify_fail () at /lib64/libc.so.6
 #5  0x00007ffff7295c36 in  () at /lib64/libc.so.6
 #6  0x00007ffff72957f5 in __snprintf_chk () at /lib64/libc.so.6
 #7  0x0000555555b1c1fd in pcibus_get_fw_dev_path ()
 #8  0x0000555555f2bde4 in qdev_get_fw_dev_path_helper.constprop ()
 #9  0x0000555555f2bd86 in qdev_get_fw_dev_path_helper.constprop ()
 #10 0x00005555559a6e5d in get_boot_device_path ()
 #11 0x00005555559a712c in get_boot_devices_list ()
 #12 0x0000555555b1a3d0 in fw_cfg_machine_reset ()
 #13 0x0000555555bf4c2d in pc_machine_reset ()
 #14 0x0000555555c66988 in qemu_system_reset ()
 #15 0x0000555555a6dff6 in qdev_machine_creation_done ()
 #16 0x0000555555c79186 in qmp_x_exit_preconfig.part ()
 #17 0x0000555555c7b459 in qemu_init ()
 #18 0x0000555555960a29 in main ()

Found-by: Dario Faggioli <Dario Faggioli <dfaggioli@suse.com>
Found-by: Martin Liška <martin.liska@suse.com>
Cc: qemu-stable@nongnu.org
Signed-off-by: Claudio Fontana <cfontana@suse.de>
Message-Id: <20220531114707.18830-1-cfontana@suse.de>
Reviewed-by: Ani Sinha <ani@anisinha.ca>
2022-06-09 19:32:49 -04:00
.github/workflows
.gitlab/issue_templates
.gitlab-ci.d tests: run 'device-crash-test' from tests/venv 2022-06-06 09:26:54 +02:00
accel replay: rewrite async event handling 2022-06-06 09:26:53 +02:00
audio introduce -audio as a replacement for -soundhw 2022-05-14 12:33:44 +02:00
authz
backends hostmem: default the amount of prealloc-threads to smp-cpus 2022-05-23 10:56:01 +02:00
block coroutine-lock: qemu_co_queue_restart_all is a coroutine-only qemu_co_enter_all 2022-05-12 12:29:44 +02:00
bsd-user Clean up decorations and whitespace around header guards 2022-05-11 16:50:32 +02:00
chardev QIOChannel: Add flags on io_writev and introduce io_flush callback 2022-05-16 13:56:24 +01:00
common-user
configs target/loongarch: Add gdb support. 2022-06-06 18:14:13 +00:00
contrib contrib/elf2dmp: add ELF dump header checking 2022-05-25 21:26:35 +02:00
crypto test/crypto: Add test suite for crypto akcipher 2022-05-26 11:41:54 +01:00
disas disas: Remove old libopcode ppc disassembler 2022-05-09 08:21:05 +02:00
docs hw/cxl: Make the CXL fixed memory window setup a machine parameter. 2022-06-09 19:32:49 -04:00
dtc@b6910bec11
dump
ebpf
fpu
fsdev
gdb-xml target/loongarch: Add gdb support. 2022-06-06 18:14:13 +00:00
hw pci: fix overflow in snprintf string formatting 2022-06-09 19:32:49 -04:00
include hw/machine: Drop cxl_supported flag as no longer useful 2022-06-09 19:32:49 -04:00
io QIOChannelSocket: Implement io_writev zero copy flag & io_flush for CONFIG_LINUX 2022-05-16 13:56:24 +01:00
libdecnumber
linux-headers linux-headers: Update to v5.18-rc6 2022-05-13 08:20:11 -06:00
linux-user m68k pull request 20220602 2022-06-02 06:30:24 -07:00
meson@12f9f04ba0
migration multifd: Implement zero copy write in multifd migration (multifd-zero-copy) 2022-05-16 13:56:24 +01:00
monitor mos6522: fix linking error when CONFIG_MOS6522 is not set 2022-05-26 17:11:32 -03:00
nbd nbd/server: Allow MULTI_CONN for shared writable exports 2022-05-12 13:10:52 +02:00
net net/vmnet: implement bridged mode (vmnet-bridged) 2022-05-17 16:48:23 +08:00
pc-bios configure: enable cross compilation of vof 2022-06-01 15:47:43 +01:00
plugins Clean up header guards that don't match their file name 2022-05-11 16:49:06 +02:00
po
python python: update for mypy 0.950 2022-06-06 09:26:54 +02:00
qapi hw/cxl: Make the CXL fixed memory window setup a machine parameter. 2022-06-09 19:32:49 -04:00
qga meson: qga: do not use deprecated meson.build_root() 2022-06-06 16:04:08 +02:00
qobject
qom
replay replay: simplify async event processing 2022-06-06 09:26:53 +02:00
roms New SeaBIOS-hppa version 6 2022-05-26 12:54:29 +02:00
scripts regenerate meson-buildoptions.sh 2022-06-06 12:47:00 +02:00
scsi QIOChannel: Add flags on io_writev and introduce io_flush callback 2022-05-16 13:56:24 +01:00
semihosting linux-user: Clean up arg_start/arg_end confusion 2022-05-23 08:15:19 +02:00
slirp@9d59bb775d slirp: bump submodule past 4.7 release 2022-05-12 12:29:44 +02:00
softmmu hw/cxl: Push linking of CXL targets into i386/pc rather than in machine.c 2022-06-09 19:32:49 -04:00
storage-daemon include: move qemu_*_exec_dir() to cutils 2022-05-28 11:42:56 +02:00
stubs replay: notify vCPU when BH is scheduled 2022-06-06 09:26:53 +02:00
subprojects/libvhost-user libvhost-user: expose vu_request_to_string 2022-05-16 04:38:40 -04:00
target target/loongarch: Add gdb support. 2022-06-06 18:14:13 +00:00
tcg tcg/aarch64: Fix illegal insn from out-of-range shli 2022-06-02 08:09:46 -07:00
tests tests/acpi: Update q35/CEDT.cxl for new memory addresses. 2022-06-09 19:32:49 -04:00
tools Clean up header guards that don't match their file name 2022-05-11 16:49:06 +02:00
trace
ui ui: Switch "-display sdl" to use the QAPI parser 2022-06-03 08:03:28 +02:00
util replay: notify vCPU when BH is scheduled 2022-06-06 09:26:53 +02:00
.cirrus.yml cirrus/win32: upgrade mingw base packages 2022-05-09 08:21:14 +02:00
.dir-locals.el
.editorconfig
.exrc
.gdbinit
.gitattributes
.gitignore
.gitlab-ci.yml
.gitmodules capstone: Remove the capstone submodule 2022-05-18 08:54:22 +02:00
.gitpublish
.mailmap MAINTAINERS/.mailmap: update email for Leif Lindholm 2022-05-09 11:47:53 +01:00
.patchew.yml
.readthedocs.yml
.travis.yml
block.c block: Classify bdrv_get_flags() as I/O function 2022-05-04 15:55:23 +02:00
blockdev-nbd.c nbd/server: Allow MULTI_CONN for shared writable exports 2022-05-12 13:10:52 +02:00
blockdev.c
blockjob.c
configure target/loongarch: 'make check-tcg' support 2022-06-06 18:14:13 +00:00
COPYING
COPYING.LIB
cpu.c
cpus-common.c
disas.c disas: Remove old libopcode ppc disassembler 2022-05-09 08:21:05 +02:00
event-loop-base.c util/event-loop-base: Introduce options to set the thread pool size 2022-05-09 10:43:23 +01:00
gdbstub.c
gitdm.config
hmp-commands-info.hx mos6522: fix linking error when CONFIG_MOS6522 is not set 2022-05-26 17:11:32 -03:00
hmp-commands.hx net/vmnet: update hmp-commands.hx 2022-05-17 16:48:23 +08:00
iothread.c util/event-loop-base: Introduce options to set the thread pool size 2022-05-09 10:43:23 +01:00
job-qmp.c
job.c
Kconfig
Kconfig.host meson: use have_vhost_* variables to pick sources 2022-05-07 07:46:58 +02:00
LICENSE
MAINTAINERS tests/tcg/loongarch64: Add hello/memory test in loongarch64 system 2022-06-06 18:14:13 +00:00
Makefile build: add a more generic way to specify make->ninja dependencies 2022-06-01 15:47:43 +01:00
memory_ldst.c.inc
meson_options.txt * Remove Ubuntu 18.04 containers (not supported anymore) 2022-05-20 08:04:30 -07:00
meson.build target/loongarch: Add disassembler 2022-06-06 18:09:03 +00:00
module-common.c
os-posix.c
os-win32.c
page-vary-common.c
page-vary.c
qemu-bridge-helper.c
qemu-edid.c
qemu-img-cmds.hx
qemu-img.c
qemu-io-cmds.c
qemu-io.c include: move qemu_*_exec_dir() to cutils 2022-05-28 11:42:56 +02:00
qemu-keymap.c
qemu-nbd.c qemu-nbd: Pass max connections to blockdev layer 2022-05-12 13:10:52 +02:00
qemu-options.hx hw/cxl: Make the CXL fixed memory window setup a machine parameter. 2022-06-09 19:32:49 -04:00
qemu.nsi
qemu.sasl
README.rst
replication.c
trace-events
VERSION
version.rc

===========
QEMU README
===========

QEMU is a generic and open source machine & userspace emulator and
virtualizer.

QEMU is capable of emulating a complete machine in software without any
need for hardware virtualization support. By using dynamic translation,
it achieves very good performance. QEMU can also integrate with the Xen
and KVM hypervisors to provide emulated hardware while allowing the
hypervisor to manage the CPU. With hypervisor support, QEMU can achieve
near native performance for CPUs. When QEMU emulates CPUs directly it is
capable of running operating systems made for one machine (e.g. an ARMv7
board) on a different machine (e.g. an x86_64 PC board).

QEMU is also capable of providing userspace API virtualization for Linux
and BSD kernel interfaces. This allows binaries compiled against one
architecture ABI (e.g. the Linux PPC64 ABI) to be run on a host using a
different architecture ABI (e.g. the Linux x86_64 ABI). This does not
involve any hardware emulation, simply CPU and syscall emulation.

QEMU aims to fit into a variety of use cases. It can be invoked directly
by users wishing to have full control over its behaviour and settings.
It also aims to facilitate integration into higher level management
layers, by providing a stable command line interface and monitor API.
It is commonly invoked indirectly via the libvirt library when using
open source applications such as oVirt, OpenStack and virt-manager.

QEMU as a whole is released under the GNU General Public License,
version 2. For full licensing details, consult the LICENSE file.


Documentation
=============

Documentation can be found hosted online at
`<https://www.qemu.org/documentation/>`_. The documentation for the
current development version that is available at
`<https://www.qemu.org/docs/master/>`_ is generated from the ``docs/``
folder in the source tree, and is built by `Sphinx
<https://www.sphinx-doc.org/en/master/>_`.


Building
========

QEMU is multi-platform software intended to be buildable on all modern
Linux platforms, OS-X, Win32 (via the Mingw64 toolchain) and a variety
of other UNIX targets. The simple steps to build QEMU are:


.. code-block:: shell

  mkdir build
  cd build
  ../configure
  make

Additional information can also be found online via the QEMU website:

* `<https://wiki.qemu.org/Hosts/Linux>`_
* `<https://wiki.qemu.org/Hosts/Mac>`_
* `<https://wiki.qemu.org/Hosts/W32>`_


Submitting patches
==================

The QEMU source code is maintained under the GIT version control system.

.. code-block:: shell

   git clone https://gitlab.com/qemu-project/qemu.git

When submitting patches, one common approach is to use 'git
format-patch' and/or 'git send-email' to format & send the mail to the
qemu-devel@nongnu.org mailing list. All patches submitted must contain
a 'Signed-off-by' line from the author. Patches should follow the
guidelines set out in the `style section
<https://www.qemu.org/docs/master/devel/style.html>` of
the Developers Guide.

Additional information on submitting patches can be found online via
the QEMU website

* `<https://wiki.qemu.org/Contribute/SubmitAPatch>`_
* `<https://wiki.qemu.org/Contribute/TrivialPatches>`_

The QEMU website is also maintained under source control.

.. code-block:: shell

  git clone https://gitlab.com/qemu-project/qemu-web.git

* `<https://www.qemu.org/2017/02/04/the-new-qemu-website-is-up/>`_

A 'git-publish' utility was created to make above process less
cumbersome, and is highly recommended for making regular contributions,
or even just for sending consecutive patch series revisions. It also
requires a working 'git send-email' setup, and by default doesn't
automate everything, so you may want to go through the above steps
manually for once.

For installation instructions, please go to

*  `<https://github.com/stefanha/git-publish>`_

The workflow with 'git-publish' is:

.. code-block:: shell

  $ git checkout master -b my-feature
  $ # work on new commits, add your 'Signed-off-by' lines to each
  $ git publish

Your patch series will be sent and tagged as my-feature-v1 if you need to refer
back to it in the future.

Sending v2:

.. code-block:: shell

  $ git checkout my-feature # same topic branch
  $ # making changes to the commits (using 'git rebase', for example)
  $ git publish

Your patch series will be sent with 'v2' tag in the subject and the git tip
will be tagged as my-feature-v2.

Bug reporting
=============

The QEMU project uses GitLab issues to track bugs. Bugs
found when running code built from QEMU git or upstream released sources
should be reported via:

* `<https://gitlab.com/qemu-project/qemu/-/issues>`_

If using QEMU via an operating system vendor pre-built binary package, it
is preferable to report bugs to the vendor's own bug tracker first. If
the bug is also known to affect latest upstream code, it can also be
reported via GitLab.

For additional information on bug reporting consult:

* `<https://wiki.qemu.org/Contribute/ReportABug>`_


ChangeLog
=========

For version history and release notes, please visit
`<https://wiki.qemu.org/ChangeLog/>`_ or look at the git history for
more detailed information.


Contact
=======

The QEMU community can be contacted in a number of ways, with the two
main methods being email and IRC

* `<mailto:qemu-devel@nongnu.org>`_
* `<https://lists.nongnu.org/mailman/listinfo/qemu-devel>`_
* #qemu on irc.oftc.net

Information on additional methods of contacting the community can be
found online via the QEMU website:

* `<https://wiki.qemu.org/Contribute/StartHere>`_