QEMU With E2K User Support
Go to file
Greg Kurz 7a95434e0c 9pfs: local: forbid client access to metadata (CVE-2017-7493)
When using the mapped-file security mode, we shouldn't let the client mess
with the metadata. The current code already tries to hide the metadata dir
from the client by skipping it in local_readdir(). But the client can still
access or modify it through several other operations. This can be used to
escalate privileges in the guest.

Affected backend operations are:
- local_mknod()
- local_mkdir()
- local_open2()
- local_symlink()
- local_link()
- local_unlinkat()
- local_renameat()
- local_rename()
- local_name_to_path()

Other operations are safe because they are only passed a fid path, which
is computed internally in local_name_to_path().

This patch converts all the functions listed above to fail and return
EINVAL when being passed the name of the metadata dir. This may look
like a poor choice for errno, but there's no such thing as an illegal
path name on Linux and I could not think of anything better.

This fixes CVE-2017-7493.

Reported-by: Leo Gaspard <leo@gaspard.io>
Signed-off-by: Greg Kurz <groug@kaod.org>
Reviewed-by: Eric Blake <eblake@redhat.com>
2017-05-15 15:20:57 +02:00
audio audio: fix WAVState leak 2017-05-04 09:15:45 +02:00
backends hostmem: use host_memory_backend_mr_inited() where proper 2017-04-20 15:22:41 -03:00
block -----BEGIN PGP SIGNATURE----- 2017-05-12 10:39:23 -04:00
bsd-user util: Use g_malloc/g_free in envlist.c 2017-05-07 09:57:51 +03:00
chardev QAPI patches for 2017-05-04 2017-05-09 15:49:14 -04:00
contrib libvhost-user: replace vasprintf() to fix build 2017-05-05 12:10:00 +02:00
crypto crypto: qcrypto_random_bytes() now works on windows w/o any other crypto libs 2017-05-09 14:41:47 +01:00
default-configs s390x/3270: Mark non-migratable and enable the device 2017-05-04 10:34:37 +02:00
disas disas/cris.c: Avoid unintentional sign extension 2017-04-03 14:06:59 +01:00
docs trace: fix tcg tracing build breakage 2017-03-28 11:07:46 +01:00
dtc@558cd81bdd dtc: Revert unintentional submodule downgrade from commit c2cabb3422 2017-03-16 14:11:15 +00:00
fpu softfloat: Use correct type in float64_to_uint64_round_to_zero() 2017-02-28 09:03:38 +03:00
fsdev throttle: factor out duplicate code 2017-02-28 10:31:46 +01:00
gdb-xml target/i386: Add GDB XML register description support 2017-05-05 12:09:59 +02:00
hw 9pfs: local: forbid client access to metadata (CVE-2017-7493) 2017-05-15 15:20:57 +02:00
include -----BEGIN PGP SIGNATURE----- 2017-05-12 10:39:23 -04:00
io sockets: Limit SocketAddressLegacy to external interfaces 2017-05-09 09:14:40 +02:00
libdecnumber libdecnumber: Clean up includes 2016-02-16 14:29:27 +00:00
linux-headers update Linux headers to 4.11 2017-02-28 16:18:49 +00:00
linux-user trivial patches for 2017-05-10 2017-05-10 12:31:19 -04:00
migration block: New BdrvChildRole.activate() for blk_resume_after_migration() 2017-05-11 12:08:24 +02:00
nbd nbd-client: fix handling of hungup connections 2017-03-27 16:50:36 +02:00
net sockets: Limit SocketAddressLegacy to external interfaces 2017-05-09 09:14:40 +02:00
pc-bios A large set of small patches. I have not included yet vhost-user-scsi, 2017-05-08 13:29:40 -04:00
pixman@87eea99e44 pixman: update internal copy to pixman-0.32.6 2014-09-15 08:14:19 +02:00
po po: add missing translations in de, fr, it, zh 2016-12-14 18:47:19 +00:00
qapi blkdebug: Add ability to override unmap geometries 2017-05-11 14:28:06 +02:00
qga trivial patches for 2017-05-10 2017-05-10 12:31:19 -04:00
qobject qobject: Use simpler QDict/QList scalar insertion macros 2017-05-09 09:13:51 +02:00
qom trace: add sanity check 2017-05-12 10:37:40 -04:00
replay monitor: Remove monitor parameter from save_vmstate 2017-05-04 10:32:58 +02:00
roms sgabios: update for "fix wrong video attrs for int 10h,ah==13h" 2017-05-05 12:09:59 +02:00
scripts trivial patches for 2017-05-10 2017-05-10 12:31:19 -04:00
slirp slirp: VMStatify remaining except for loop 2017-04-29 18:44:16 +02:00
stubs move xen-hvm.c to hw/i386/xen/ 2017-04-25 11:04:34 -07:00
target QAPI patches for 2017-05-04 2017-05-09 15:49:14 -04:00
tcg tcg/mips: fix field extraction opcode 2017-05-06 12:48:53 +02:00
tests Block layer patches 2017-05-12 10:39:08 -04:00
trace trace: fix tcg tracing build breakage 2017-03-28 11:07:46 +01:00
ui sockets: Limit SocketAddressLegacy to external interfaces 2017-05-09 09:14:40 +02:00
util -----BEGIN PGP SIGNATURE----- 2017-05-12 10:39:23 -04:00
.dir-locals.el Add .dir-locals.el file to configure emacs coding style 2015-10-08 19:46:01 +03:00
.exrc qemu: add .exrc 2012-09-07 09:02:44 +03:00
.gitignore qapi: Clean up build of generated documentation 2017-03-16 07:13:02 +01:00
.gitmodules ppc: add skiboot firmware for the pnv platform 2016-10-28 09:36:58 +11:00
.mailmap Update mailmap 2013-09-05 09:40:31 -05:00
.shippable.yml .shippable: add s390x-cross target 2017-02-28 20:31:01 +08:00
.travis.yml coroutine: remove GThread implementation 2017-05-12 10:36:46 -04:00
accel.c clean-up: removed duplicate #includes 2016-10-28 18:17:24 +03:00
arch_init.c nios2: Add support for Nios-II R1 2017-01-24 13:10:36 -08:00
atomic_template.h tcg: Add atomic128 helpers 2016-10-26 08:29:01 -07:00
balloon.c trace: switch to modular code generation for sub-directories 2017-01-31 17:11:18 +00:00
block.c block: Fix write/resize permissions for inactive images 2017-05-11 12:08:24 +02:00
blockdev-nbd.c sockets: Limit SocketAddressLegacy to external interfaces 2017-05-09 09:14:40 +02:00
blockdev.c blockdev: use drained_begin/end for qmp_block_resize 2017-05-11 12:08:24 +02:00
blockjob.c blockjob: Use bdrv_coroutine_enter to start coroutine 2017-04-11 20:07:15 +08:00
bootdevice.c error: Remove NULL checks on error_propagate() calls 2016-06-20 16:38:13 +02:00
bt-host.c all: Clean up includes 2016-02-04 17:41:30 +00:00
bt-vhci.c all: Clean up includes 2016-02-04 17:41:30 +00:00
Changelog Use qemu-project.org domain name 2013-10-11 09:34:56 -07:00
CODING_STYLE CODING_STYLE: Mention preferred comment form 2017-02-28 09:03:38 +03:00
configure coroutine: remove GThread implementation 2017-05-12 10:36:46 -04:00
COPYING COPYING: update from FSF 2008-10-12 17:54:42 +00:00
COPYING.LIB Update FSF address in GPL/LGPL boilerplate 2009-01-04 22:05:52 +00:00
cpu-exec-common.c ui/console: ensure do_safe_dpy_refresh holds BQL 2017-03-28 10:52:24 +01:00
cpu-exec.c cpu-exec: update icount after each TB_EXIT 2017-04-10 10:23:38 +01:00
cpus-common.c *_run_on_cpu: introduce run_on_cpu_data type 2016-10-31 15:00:25 +01:00
cpus.c cpus: call cpu_update_icount on read 2017-04-10 10:23:38 +01:00
cputlb.c cputlb: Don't assume do_unassigned_access() never returns 2017-02-28 12:08:15 +00:00
device_tree.c device_tree: fix compiler warnings (clang 5) 2017-05-07 09:57:51 +03:00
device-hotplug.c blockdev: Split monitor reference from BB creation 2016-03-17 15:47:56 +01:00
disas.c Fix Thumb-1 BE32 execution and disassembly. 2017-02-07 18:29:59 +00:00
dma-helpers.c block: explicitly acquire aiocontext in bottom halves that need it 2017-02-21 11:39:39 +00:00
dump.c dump: Acquire BQL around vm_start() in dump thread 2017-05-05 12:10:00 +02:00
exec.c memory: add support getting and using a dirty bitmap copy. 2017-04-24 10:12:28 +02:00
gdbstub.c gdbstub: implement remote debugging protocol escapes for command receive 2017-05-08 09:26:32 -04:00
HACKING HACKING: document #include order 2017-01-03 16:38:47 +00:00
hax-stub.c Plumb the HAXM-based hardware acceleration support 2017-01-19 22:07:46 +01:00
hmp-commands-info.hx qmp/hmp: add query-vm-generation-id and 'info vm-generation-id' commands 2017-03-02 07:14:27 +02:00
hmp-commands.hx hmp: gpa2hva and gpa2hpa hostaddr command 2017-04-26 14:42:31 +01:00
hmp.c sockets: Limit SocketAddressLegacy to external interfaces 2017-05-09 09:14:40 +02:00
hmp.h monitor: Move hmp_info_snapshots from savevm.c to hmp.c 2017-05-04 10:34:15 +02:00
ioport.c trace: switch to modular code generation for sub-directories 2017-01-31 17:11:18 +00:00
iothread.c monitor: add poll-* properties into query-iothreads result 2017-02-21 18:29:01 +00:00
kvm-all.c qemu-timer: do not include sysemu/cpus.h from util/qemu-timer.h 2017-03-14 13:28:18 +01:00
kvm-stub.c KVM: move SIG_IPI handling to kvm-all.c 2017-03-03 16:40:02 +01:00
LICENSE vfio: move hw/misc/vfio.c to hw/vfio/pci.c Move vfio.h into include/hw/vfio 2014-12-19 15:24:06 -07:00
MAINTAINERS Block layer patches 2017-05-12 10:39:08 -04:00
Makefile trace: Put all trace.o into libqemuutil.a 2017-04-21 10:45:35 +01:00
Makefile.objs target-mips: replace few LOG_DISAS() with trace points 2017-03-20 11:06:32 +00:00
Makefile.target Xen 2017/04/21 + fix 2017-04-26 10:22:31 +01:00
memory_ldst.inc.c exec: introduce memory_ldst.inc.c 2016-12-22 16:00:23 +01:00
memory_mapping.c memory: Replace skip_dump flag with "ram_device" 2016-10-31 09:53:03 -06:00
memory.c memory: add support getting and using a dirty bitmap copy. 2017-04-24 10:12:28 +02:00
module-common.c all: Clean up includes 2016-02-04 17:41:30 +00:00
monitor.c qobject: Use simpler QDict/QList scalar insertion macros 2017-05-09 09:13:51 +02:00
numa.c Remove reduntant qemu: from error functions 2017-05-07 09:57:51 +03:00
os-posix.c use g_path_get_dirname instead of dirname 2016-07-17 09:59:21 +02:00
os-win32.c all: Clean up includes 2016-02-04 17:41:30 +00:00
page_cache.c coccinelle: Remove unnecessary variables for function return value 2016-06-20 16:38:13 +02:00
qapi-schema.json sockets: Limit SocketAddressLegacy to external interfaces 2017-05-09 09:14:40 +02:00
qdev-monitor.c migration: Disable hotplug/unplug during migration 2017-04-21 12:25:40 +02:00
qdict-test-data.txt Introduce QDict test data file 2009-09-04 09:37:34 -05:00
qemu-bridge-helper.c all: Remove unnecessary glib.h includes 2016-06-07 18:19:24 +03:00
qemu-doc.texi trivial patches for 2017-05-10 2017-05-10 12:31:19 -04:00
qemu-ga.texi qemu-ga: Remove stray 'q' in documentation 2016-10-28 18:17:23 +03:00
qemu-img-cmds.hx qemu-img: Update documentation for -U 2017-05-11 11:08:40 +02:00
qemu-img.c qemu-img: wait for convert coroutines to complete 2017-05-11 12:08:24 +02:00
qemu-img.texi progress: Show current progress on SIGINFO 2017-04-28 18:48:11 +02:00
qemu-io-cmds.c qemu-io: Switch 'map' output to byte-based reporting 2017-05-11 14:28:06 +02:00
qemu-io.c qemu-io: Add --force-share option 2017-05-11 11:08:40 +02:00
qemu-nbd.c sockets: Limit SocketAddressLegacy to external interfaces 2017-05-09 09:14:40 +02:00
qemu-nbd.texi nbd: Add qemu-nbd -D for human-readable description 2016-11-02 09:28:55 +01:00
qemu-option-trace.texi docs: update manpage for stderr->log rename 2017-02-13 13:38:31 +00:00
qemu-options-wrapper.h hxtool: emit Texinfo headings as @subsection 2017-01-16 17:52:35 +01:00
qemu-options.h Clean up ill-advised or unusual header guards 2016-07-12 16:20:46 +02:00
qemu-options.hx trivial patches for 2017-05-10 2017-05-10 12:31:19 -04:00
qemu-seccomp.c seccomp: adding getrusage to the whitelist 2016-09-21 11:26:02 +02:00
qemu-tech.texi qemu-doc: merge qemu-tech and qemu-doc 2016-10-07 10:05:54 +02:00
qemu.nsi qemu-doc: merge qemu-tech and qemu-doc 2016-10-07 10:05:54 +02:00
qemu.sasl Default to GSSAPI (Kerberos) instead of DIGEST-MD5 for SASL 2017-05-09 14:41:47 +01:00
qmp.c block: New BdrvChildRole.activate() for blk_resume_after_migration() 2017-05-11 12:08:24 +02:00
qtest.c qtest: fix a memory leak 2017-03-01 00:09:28 +04:00
README README: Add linux to macOS build info 2017-01-24 23:26:52 +03:00
replication.c replication: Introduce new APIs to do replication operation 2016-09-13 11:00:56 +01:00
replication.h replication: Introduce new APIs to do replication operation 2016-09-13 11:00:56 +01:00
rules.mak qapi: Clean up build of generated documentation 2017-03-16 07:13:02 +01:00
softmmu_template.h cputlb: Tidy some macros 2016-10-26 08:29:00 -07:00
spice-qemu-char.c spice-char: fix segfault in char_spice_finalize 2017-03-03 16:40:03 +01:00
tcg-runtime.c tcg: Add opcode for ctpop 2017-01-10 08:48:56 -08:00
tci.c tcg/tci: Add support for fence 2016-09-16 08:12:12 -07:00
thunk.c thunk: Rename args and fields in host-target bitmask conversion code 2016-06-07 18:19:24 +03:00
tpm.c qapi: Don't special-case simple union wrappers 2016-03-18 10:29:26 +01:00
trace-events move xen-mapcache.c to hw/i386/xen/ 2017-04-25 11:04:34 -07:00
translate-all.c qemu-timer: do not include sysemu/cpus.h from util/qemu-timer.h 2017-03-14 13:28:18 +01:00
translate-all.h trace: Add per-vCPU tracing states for events with the 'vcpu' property 2016-07-18 18:23:12 +01:00
translate-common.c Merge branch 'icount-update' into HEAD 2017-03-03 16:39:18 +01:00
user-exec-stub.c stubs: group stubs for user-mode emulation 2017-01-16 17:52:35 +01:00
user-exec.c user-exec: handle synchronous signals from QEMU gracefully 2017-03-28 10:50:35 +01:00
VERSION Open 2.10 development tree 2017-04-20 15:42:31 +01:00
version.rc Use qemu-project.org domain name 2013-10-11 09:34:56 -07:00
vl.c trivial patches for 2017-05-10 2017-05-10 12:31:19 -04:00

         QEMU README
         ===========

QEMU is a generic and open source machine & userspace emulator and
virtualizer.

QEMU is capable of emulating a complete machine in software without any
need for hardware virtualization support. By using dynamic translation,
it achieves very good performance. QEMU can also integrate with the Xen
and KVM hypervisors to provide emulated hardware while allowing the
hypervisor to manage the CPU. With hypervisor support, QEMU can achieve
near native performance for CPUs. When QEMU emulates CPUs directly it is
capable of running operating systems made for one machine (e.g. an ARMv7
board) on a different machine (e.g. an x86_64 PC board).

QEMU is also capable of providing userspace API virtualization for Linux
and BSD kernel interfaces. This allows binaries compiled against one
architecture ABI (e.g. the Linux PPC64 ABI) to be run on a host using a
different architecture ABI (e.g. the Linux x86_64 ABI). This does not
involve any hardware emulation, simply CPU and syscall emulation.

QEMU aims to fit into a variety of use cases. It can be invoked directly
by users wishing to have full control over its behaviour and settings.
It also aims to facilitate integration into higher level management
layers, by providing a stable command line interface and monitor API.
It is commonly invoked indirectly via the libvirt library when using
open source applications such as oVirt, OpenStack and virt-manager.

QEMU as a whole is released under the GNU General Public License,
version 2. For full licensing details, consult the LICENSE file.


Building
========

QEMU is multi-platform software intended to be buildable on all modern
Linux platforms, OS-X, Win32 (via the Mingw64 toolchain) and a variety
of other UNIX targets. The simple steps to build QEMU are:

  mkdir build
  cd build
  ../configure
  make

Additional information can also be found online via the QEMU website:

  http://qemu-project.org/Hosts/Linux
  http://qemu-project.org/Hosts/Mac
  http://qemu-project.org/Hosts/W32


Submitting patches
==================

The QEMU source code is maintained under the GIT version control system.

   git clone git://git.qemu-project.org/qemu.git

When submitting patches, the preferred approach is to use 'git
format-patch' and/or 'git send-email' to format & send the mail to the
qemu-devel@nongnu.org mailing list. All patches submitted must contain
a 'Signed-off-by' line from the author. Patches should follow the
guidelines set out in the HACKING and CODING_STYLE files.

Additional information on submitting patches can be found online via
the QEMU website

  http://qemu-project.org/Contribute/SubmitAPatch
  http://qemu-project.org/Contribute/TrivialPatches


Bug reporting
=============

The QEMU project uses Launchpad as its primary upstream bug tracker. Bugs
found when running code built from QEMU git or upstream released sources
should be reported via:

  https://bugs.launchpad.net/qemu/

If using QEMU via an operating system vendor pre-built binary package, it
is preferable to report bugs to the vendor's own bug tracker first. If
the bug is also known to affect latest upstream code, it can also be
reported via launchpad.

For additional information on bug reporting consult:

  http://qemu-project.org/Contribute/ReportABug


Contact
=======

The QEMU community can be contacted in a number of ways, with the two
main methods being email and IRC

 - qemu-devel@nongnu.org
   http://lists.nongnu.org/mailman/listinfo/qemu-devel
 - #qemu on irc.oftc.net

Information on additional methods of contacting the community can be
found online via the QEMU website:

  http://qemu-project.org/Contribute/StartHere

-- End