QEMU With E2K User Support
Go to file
Raphael Norwitz 4fdecf0543 Fix vhost-user buffer over-read on ram hot-unplug
The VHOST_USER_PROTOCOL_F_CONFIGURE_MEM_SLOTS vhost-user protocol
feature introduced a shadow-table, used by the backend to dynamically
determine how a vdev's memory regions have changed since the last
vhost_user_set_mem_table() call. On hot-remove, a memmove() operation
is used to overwrite the removed shadow region descriptor(s). The size
parameter of this memmove was off by 1 such that if a VM with a backend
supporting the VHOST_USER_PROTOCOL_F_CONFIGURE_MEM_SLOTS filled it's
shadow-table (by performing the maximum number of supported hot-add
operatons) and attempted to remove the last region, Qemu would read an
out of bounds value and potentially crash.

This change fixes the memmove() bounds such that this erroneous read can
never happen.

Signed-off-by: Peter Turschmid <peter.turschm@nutanix.com>
Signed-off-by: Raphael Norwitz <raphael.norwitz@nutanix.com>
Message-Id: <1594799958-31356-1-git-send-email-raphael.norwitz@nutanix.com>
Fixes: f1aeb14b08 ("Transmit vhost-user memory regions individually")
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
Cc: qemu-stable@nongnu.org
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
2020-07-27 10:28:28 -04:00
.github .github: Enable repo-lockdown bot to refuse GitHub pull requests 2020-04-07 16:19:18 +01:00
.gitlab-ci.d gitlab-ci/containers: Add missing wildcard where we should look for changes 2020-07-15 11:52:43 +01:00
accel tcg: update comments for save_iotlb_data in cputlb 2020-07-24 14:25:11 -07:00
audio ossaudio: fix out of bounds write 2020-07-13 11:38:40 +02:00
authz qom: Drop parameter @errp of object_property_add() & friends 2020-05-15 07:07:58 +02:00
backends tpm_emulator: Report an error if chardev is missing 2020-07-24 12:44:13 -04:00
block Block layer patches: 2020-07-21 19:25:48 +01:00
bsd-user linux-user/sparc64: Fix the handling of window spill trap 2020-06-29 13:00:23 +02:00
capstone@22ead3e0bf disas: Add capstone as submodule 2017-10-26 11:56:20 +02:00
chardev chardev: Extract system emulation specific code 2020-07-13 11:59:47 +04:00
contrib qemu-option: Use returned bool to check for failure 2020-07-10 15:17:35 +02:00
crypto qom: Put name parameter before value / visitor parameter 2020-07-10 15:18:08 +02:00
default-configs hw/avr: Add limited support for some Arduino boards 2020-07-11 11:02:05 +02:00
disas disas/sh4: Add missing fallthrough annotations 2020-07-13 11:40:52 +02:00
docs docs/fuzz: add instructions for generating a coverage report 2020-07-21 07:29:18 +02:00
dtc@85e5d83984 Makefile: dtc: update, build the libfdt target 2020-06-16 14:49:05 +01:00
dump error: Eliminate error_propagate() manually 2020-07-10 15:18:08 +02:00
fpu fpu/softfloat: fix up float16 nan recognition 2020-07-15 11:52:43 +01:00
fsdev 9p: null terminate fs driver options list 2020-07-10 12:48:06 +02:00
gdb-xml target/avr: CPU class: Add GDB support 2020-07-10 17:58:32 +02:00
hw Fix vhost-user buffer over-read on ram hot-unplug 2020-07-27 10:28:28 -04:00
include hw/pci-host: save/restore pci host config register 2020-07-27 10:24:39 -04:00
io io/task: Move 'qom/object.h' header to source 2020-06-10 12:09:37 -04:00
libdecnumber build: remove CONFIG_LIBDECNUMBER 2017-10-16 18:03:52 +02:00
linux-headers linux-headers: update again to 5.8 2020-07-10 19:26:55 -04:00
linux-user linux-user: fix print_syscall_err() when syscall returned value is negative 2020-07-14 09:29:14 +02:00
migration migration/block-dirty-bitmap: fix add_bitmaps_to_list 2020-07-17 08:18:51 -05:00
monitor monitor/misc: Remove unused "chardev/char-mux.h" include 2020-07-13 11:59:47 +04:00
nbd nbd: make nbd_export_close_all() synchronous 2020-07-17 14:20:57 +02:00
net qom: Change object_get_canonical_path_component() not to malloc 2020-07-21 16:23:43 +02:00
pc-bios pseries: Update SLOF firmware image 2020-07-20 09:21:39 +10:00
plugins qemu/qemu-plugin: Make qemu_plugin_hwaddr_is_io() hwaddr argument const 2020-05-15 15:25:16 +01:00
po translations: Add Swedish language 2020-06-15 20:51:10 +02:00
python/qemu python/machine: Change default timeout to 30 seconds 2020-07-25 17:27:10 +01:00
qapi Remove VXHS block device 2020-07-17 14:20:57 +02:00
qga qga: Use qemu_get_host_name() instead of g_get_host_name() 2020-07-13 17:44:58 -05:00
qobject qobject: Eliminate qdict_iter(), use qdict_first(), qdict_next() 2020-04-30 06:51:15 +02:00
qom qom: Make info qom-tree sort children more efficiently 2020-07-21 17:39:37 +02:00
replay replay: synchronize on every virtual timer callback 2020-06-26 06:45:30 -04:00
roms pseries: Update SLOF firmware image 2020-07-20 09:21:39 +10:00
scripts coccinelle/err-bad-newline: Fix for Python 3, and add patterns 2020-07-24 12:56:44 +02:00
scsi qom: Change object_get_canonical_path_component() not to malloc 2020-07-21 16:23:43 +02:00
slirp@2faae0f778 slirp: update to fix CVE-2020-1983 2020-04-21 18:39:20 +01:00
softmmu Revert "tpm: Clean up error reporting in tpm_init_tpmdev()" 2020-07-24 12:44:13 -04:00
storage-daemon qemu-storage-daemon: Add --monitor option 2020-03-06 17:21:28 +01:00
stubs Revert "tpm: Clean up error reporting in tpm_init_tpmdev()" 2020-07-24 12:44:13 -04:00
target pseries: fix kvmppc_set_fwnmi() 2020-07-27 11:09:25 +10:00
tcg tcg: Save/restore vecop_list around minmax fallback 2020-07-16 13:09:22 -07:00
tests Block layer patches: 2020-07-21 19:25:48 +01:00
tools/virtiofsd virtiofsd: Allow addition or removal of capabilities 2020-07-03 16:23:05 +01:00
trace trace/simple: Fix unauthorized enable 2020-06-24 11:21:00 +01:00
ui bugfixes for audio, usb, ui and docs. 2020-07-13 16:58:44 +01:00
util module: ignore NULL type 2020-07-21 10:56:51 +02:00
.cirrus.yml .cirrus.yml: add bash to the brew packages 2020-07-11 15:53:29 +01:00
.dir-locals.el Add .dir-locals.el file to configure emacs coding style 2015-10-08 19:46:01 +03:00
.editorconfig editorconfig: add setting for shell scripts 2019-06-12 17:53:22 +01:00
.exrc qemu: add .exrc 2012-09-07 09:02:44 +03:00
.gdbinit .gdbinit: load QEMU sub-commands when gdb starts 2017-06-07 14:38:45 +01:00
.gitignore .gitignore: un-ignore .gitlab-ci.d 2020-07-11 15:53:00 +01:00
.gitlab-ci.yml gitlab-ci.yml: Add oss-fuzz build tests 2020-07-21 07:21:54 +02:00
.gitmodules hw/ppc/prep: Remove the deprecated "prep" machine and the OpenHackware BIOS 2020-02-02 14:07:57 +11:00
.gitpublish Add a git-publish configuration file 2018-03-05 09:03:17 +00:00
.mailmap MAINTAINERS: Update Radoslaw Biernacki email address 2020-07-07 12:38:50 +02:00
.patchew.yml ci: store Patchew configuration in the tree 2019-06-03 14:03:02 +02:00
.readthedocs.yml .readthedocs.yml: specify some minimum python requirements 2020-02-07 15:15:16 +01:00
.shippable.yml shippable: pull images from registry instead of building 2020-07-11 15:53:00 +01:00
.travis.yml .travis.yml: skip ppc64abi32-linux-user with plugins 2020-07-15 11:57:17 +01:00
block.c block: Require aligned image size to avoid assertion failure 2020-07-17 14:20:57 +02:00
blockdev-nbd.c blockdev-nbd: Boxed argument type for nbd-server-add 2020-03-06 17:21:28 +01:00
blockdev.c block: Add support to warn on backing file change without format 2020-07-14 15:18:59 +02:00
blockjob.c block: Add BdrvChildRole to BdrvChild 2020-05-18 19:05:25 +02:00
bootdevice.c error: Eliminate error_propagate() manually 2020-07-10 15:18:08 +02:00
Changelog Use HTTPS for qemu.org and other domains 2017-11-21 13:34:13 +00:00
CODING_STYLE.rst docs: split the CODING_STYLE doc into distinct groups 2019-09-05 14:41:00 +01:00
configure configure: Allow to build tools without pixman 2020-07-24 17:36:03 +02:00
COPYING COPYING: update from FSF 2008-10-12 17:54:42 +00:00
COPYING.LIB COPYING.LIB: Synchronize the LGPL 2.1 with the version from gnu.org 2019-01-30 11:01:22 +01:00
cpus-common.c cpus: Move CPU code from exec.c to cpus-common.c 2020-07-10 18:02:24 -04:00
device_tree.c device_tree: Constify compat in qemu_fdt_node_path() 2020-04-30 15:35:41 +01:00
disas.c disas: Let disas::read_memory() handler return EIO on error 2020-06-10 12:10:23 -04:00
dma-helpers.c icount: make dma reads deterministic 2020-06-17 14:53:39 +02:00
exec-vary.c exec: Cache TARGET_PAGE_MASK for TARGET_PAGE_BITS_VARY 2019-10-28 10:35:20 +01:00
exec.c cpus: Move CPU code from exec.c to cpus-common.c 2020-07-10 18:02:24 -04:00
gdbstub.c qom: Change object_get_canonical_path_component() not to malloc 2020-07-21 16:23:43 +02:00
gitdm.config contrib: gitdm: add a mapping for Janus Technologies 2019-03-12 19:31:29 +00:00
hmp-commands-info.hx memory: Make 'info mtree' not display disabled regions by default 2020-06-10 12:10:49 -04:00
hmp-commands.hx hmp: Make json format optional for qom-set 2020-06-17 17:48:39 +01:00
iothread.c qom: Change object_get_canonical_path_component() not to malloc 2020-07-21 16:23:43 +02:00
job-qmp.c job: take each job's lock individually in job_txn_apply 2020-04-07 14:34:47 +02:00
job.c job: take each job's lock individually in job_txn_apply 2020-04-07 14:34:47 +02:00
Kconfig Makefile: simplify MINIKCONF rules 2020-07-10 18:02:21 -04:00
Kconfig.host accel/Kconfig: Extract accel selectors into their own config 2020-07-10 18:02:21 -04:00
LICENSE tcg/LICENSE: Remove out of date claim about TCG subdirectory licensing 2019-11-11 15:11:21 +01:00
MAINTAINERS MAINTAINERS: Extend the device fuzzing section 2020-07-21 08:40:42 +02:00
Makefile Makefile: Remove config-devices.mak on "make clean" 2020-07-20 11:02:46 +01:00
Makefile.objs chardev: enable modules, use for braille 2020-07-07 15:33:59 +02:00
Makefile.target softmmu: move softmmu only files from root 2020-07-10 18:02:24 -04:00
memory_ldst.inc.c memory: Single byte swap along the I/O path 2019-09-03 08:30:39 -07:00
module-common.c all: Clean up includes 2016-02-04 17:41:30 +00:00
os-posix.c qemu/osdep: Document os_find_datadir() return value 2020-07-21 16:13:04 +02:00
os-win32.c qemu/osdep: Document os_find_datadir() return value 2020-07-21 16:13:04 +02:00
qdev-monitor.c qdev: Fix device_add DRIVER,help to print to monitor 2020-07-21 17:22:44 +02:00
qemu-bridge-helper.c build: rename CONFIG_LIBCAP to CONFIG_LIBCAP_NG 2019-12-17 19:35:47 +01:00
qemu-edid.c Include qemu-common.h exactly where needed 2019-06-12 13:20:20 +02:00
qemu-img-cmds.hx block/amend: add 'force' option 2020-07-06 08:49:28 +02:00
qemu-img.c qemu-img resize: Require --shrink for shrinking all image formats 2020-07-17 14:20:57 +02:00
qemu-io-cmds.c block-backend: Add flags to blk_truncate() 2020-04-30 17:51:07 +02:00
qemu-io.c qemu-io: adds option to use aio engine 2020-01-30 20:59:42 +00:00
qemu-keymap.c Include qemu-common.h exactly where needed 2019-06-12 13:20:20 +02:00
qemu-nbd.c error: Use error_reportf_err() where appropriate 2020-05-27 07:45:30 +02:00
qemu-options-wrapper.h qemu-img: remove references to GEN_DOCS 2018-05-20 08:35:54 +03:00
qemu-options.h Clean up ill-advised or unusual header guards 2016-07-12 16:20:46 +02:00
qemu-options.hx ipmi: Fix a man page entry 2020-07-17 11:39:46 -05:00
qemu-seccomp.c seccomp: report more useful errors from seccomp 2019-03-27 13:11:38 +01:00
qemu-storage-daemon.c qemu-storage-daemon: add missing cleanup calls 2020-07-03 09:37:03 +02:00
qemu.nsi qemu.nsi: Install Sphinx documentation 2020-03-09 16:45:00 +00:00
qemu.sasl Default to GSSAPI (Kerberos) instead of DIGEST-MD5 for SASL 2017-05-09 14:41:47 +01:00
README.rst docs: merge HACKING.rst contents into CODING_STYLE.rst 2019-09-05 14:27:06 +01:00
replication.c replication: Introduce new APIs to do replication operation 2016-09-13 11:00:56 +01:00
replication.h Include qemu/module.h where needed, drop it from qemu-common.h 2019-06-12 13:18:33 +02:00
rules.mak build-sys: Move the print-variable rule to rules.mak 2020-03-09 15:59:31 +01:00
thunk.c linux-user: Add strace support for printing arguments of ioctl() 2020-07-04 18:08:51 +02:00
tpm.c tpm: Improve help on TPM types when none are available 2020-07-24 12:44:13 -04:00
trace-events trace: add mmu_index to mem_info 2019-10-28 15:12:38 +00:00
VERSION Update version for v5.1.0-rc1 release 2020-07-21 20:28:59 +01:00
version.rc Use HTTPS for qemu.org and other domains 2017-11-21 13:34:13 +00:00

===========
QEMU README
===========

QEMU is a generic and open source machine & userspace emulator and
virtualizer.

QEMU is capable of emulating a complete machine in software without any
need for hardware virtualization support. By using dynamic translation,
it achieves very good performance. QEMU can also integrate with the Xen
and KVM hypervisors to provide emulated hardware while allowing the
hypervisor to manage the CPU. With hypervisor support, QEMU can achieve
near native performance for CPUs. When QEMU emulates CPUs directly it is
capable of running operating systems made for one machine (e.g. an ARMv7
board) on a different machine (e.g. an x86_64 PC board).

QEMU is also capable of providing userspace API virtualization for Linux
and BSD kernel interfaces. This allows binaries compiled against one
architecture ABI (e.g. the Linux PPC64 ABI) to be run on a host using a
different architecture ABI (e.g. the Linux x86_64 ABI). This does not
involve any hardware emulation, simply CPU and syscall emulation.

QEMU aims to fit into a variety of use cases. It can be invoked directly
by users wishing to have full control over its behaviour and settings.
It also aims to facilitate integration into higher level management
layers, by providing a stable command line interface and monitor API.
It is commonly invoked indirectly via the libvirt library when using
open source applications such as oVirt, OpenStack and virt-manager.

QEMU as a whole is released under the GNU General Public License,
version 2. For full licensing details, consult the LICENSE file.


Building
========

QEMU is multi-platform software intended to be buildable on all modern
Linux platforms, OS-X, Win32 (via the Mingw64 toolchain) and a variety
of other UNIX targets. The simple steps to build QEMU are:


.. code-block:: shell

  mkdir build
  cd build
  ../configure
  make

Additional information can also be found online via the QEMU website:

* `<https://qemu.org/Hosts/Linux>`_
* `<https://qemu.org/Hosts/Mac>`_
* `<https://qemu.org/Hosts/W32>`_


Submitting patches
==================

The QEMU source code is maintained under the GIT version control system.

.. code-block:: shell

   git clone https://git.qemu.org/git/qemu.git

When submitting patches, one common approach is to use 'git
format-patch' and/or 'git send-email' to format & send the mail to the
qemu-devel@nongnu.org mailing list. All patches submitted must contain
a 'Signed-off-by' line from the author. Patches should follow the
guidelines set out in the CODING_STYLE.rst file.

Additional information on submitting patches can be found online via
the QEMU website

* `<https://qemu.org/Contribute/SubmitAPatch>`_
* `<https://qemu.org/Contribute/TrivialPatches>`_

The QEMU website is also maintained under source control.

.. code-block:: shell

  git clone https://git.qemu.org/git/qemu-web.git

* `<https://www.qemu.org/2017/02/04/the-new-qemu-website-is-up/>`_

A 'git-publish' utility was created to make above process less
cumbersome, and is highly recommended for making regular contributions,
or even just for sending consecutive patch series revisions. It also
requires a working 'git send-email' setup, and by default doesn't
automate everything, so you may want to go through the above steps
manually for once.

For installation instructions, please go to

*  `<https://github.com/stefanha/git-publish>`_

The workflow with 'git-publish' is:

.. code-block:: shell

  $ git checkout master -b my-feature
  $ # work on new commits, add your 'Signed-off-by' lines to each
  $ git publish

Your patch series will be sent and tagged as my-feature-v1 if you need to refer
back to it in the future.

Sending v2:

.. code-block:: shell

  $ git checkout my-feature # same topic branch
  $ # making changes to the commits (using 'git rebase', for example)
  $ git publish

Your patch series will be sent with 'v2' tag in the subject and the git tip
will be tagged as my-feature-v2.

Bug reporting
=============

The QEMU project uses Launchpad as its primary upstream bug tracker. Bugs
found when running code built from QEMU git or upstream released sources
should be reported via:

* `<https://bugs.launchpad.net/qemu/>`_

If using QEMU via an operating system vendor pre-built binary package, it
is preferable to report bugs to the vendor's own bug tracker first. If
the bug is also known to affect latest upstream code, it can also be
reported via launchpad.

For additional information on bug reporting consult:

* `<https://qemu.org/Contribute/ReportABug>`_


Contact
=======

The QEMU community can be contacted in a number of ways, with the two
main methods being email and IRC

* `<mailto:qemu-devel@nongnu.org>`_
* `<https://lists.nongnu.org/mailman/listinfo/qemu-devel>`_
* #qemu on irc.oftc.net

Information on additional methods of contacting the community can be
found online via the QEMU website:

* `<https://qemu.org/Contribute/StartHere>`_