QEMU With E2K User Support
Go to file
Greg Kurz 9c6b899f7a 9pfs: local: set the path of the export root to "."
The local backend was recently converted to using "at*()" syscalls in order
to ensure all accesses happen below the shared directory. This requires that
we only pass relative paths, otherwise the dirfd argument to the "at*()"
syscalls is ignored and the path is treated as an absolute path in the host.
This is actually the case for paths in all fids, with the notable exception
of the root fid, whose path is "/". This causes the following backend ops to
act on the "/" directory of the host instead of the virtfs shared directory
when the export root is involved:
- lstat
- chmod
- chown
- utimensat

ie, chmod /9p_mount_point in the guest will be converted to chmod / in the
host for example. This could cause security issues with a privileged QEMU.

All "*at()" syscalls are being passed an open file descriptor. In the case
of the export root, this file descriptor points to the path in the host that
was passed to -fsdev.

The fix is thus as simple as changing the path of the export root fid to be
"." instead of "/".

This is CVE-2017-7471.

Cc: qemu-stable@nongnu.org
Reported-by: Léo Gaspard <leo@gaspard.io>
Signed-off-by: Greg Kurz <groug@kaod.org>
Reviewed-by: Eric Blake <eblake@redhat.com>
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
2017-04-18 14:01:43 +01:00
audio audio/sdlaudio: Allow audio playback with SDL2 2017-03-01 15:12:03 +01:00
backends cryptodev fixes 2017-03-23 13:43:32 +00:00
block block/io: Comment out permission assertions 2017-04-11 16:09:31 +01:00
bsd-user bsd-user: align use of mmap_lock to that of linux-user 2017-03-28 10:50:40 +01:00
chardev char: Fix socket with "type": "vsock" address 2017-04-03 17:11:39 +02:00
contrib contrib: add libvhost-user 2016-12-16 01:14:38 +02:00
crypto crypto: assert cipher algorithm is always valid 2017-02-27 13:37:14 +00:00
default-configs ACPI: Add Virtual Machine Generation ID support 2017-03-02 07:14:27 +02:00
disas disas/cris.c: Avoid unintentional sign extension 2017-04-03 14:06:59 +01:00
docs trace: fix tcg tracing build breakage 2017-03-28 11:07:46 +01:00
dtc@558cd81bdd dtc: Revert unintentional submodule downgrade from commit c2cabb3422 2017-03-16 14:11:15 +00:00
fpu softfloat: Use correct type in float64_to_uint64_round_to_zero() 2017-02-28 09:03:38 +03:00
fsdev throttle: factor out duplicate code 2017-02-28 10:31:46 +01:00
gdb-xml target-ppc: gdbstub: Add VSX support 2016-01-30 23:37:38 +11:00
hw 9pfs: local: set the path of the export root to "." 2017-04-18 14:01:43 +01:00
include block: Introduce bdrv_coroutine_enter 2017-04-11 20:07:15 +08:00
io io: fix FD socket handling in DNS lookup 2017-04-04 16:17:03 +01:00
libdecnumber libdecnumber: Clean up includes 2016-02-16 14:29:27 +00:00
linux-headers update Linux headers to 4.11 2017-02-28 16:18:49 +00:00
linux-user target-arm queue: 2017-02-28 14:50:17 +00:00
migration block: Ignore guest dev permissions during incoming migration 2017-04-07 14:44:05 +02:00
nbd nbd-client: fix handling of hungup connections 2017-03-27 16:50:36 +02:00
net COLO-compare: Fix trace_event print bug 2017-03-14 15:39:55 +08:00
pc-bios Update OpenBIOS images to f233c3f built from submodule. 2017-03-15 19:42:08 +00:00
pixman@87eea99e44
po po: add missing translations in de, fr, it, zh 2016-12-14 18:47:19 +00:00
qapi sheepdog: Fix blockdev-add 2017-04-03 17:11:39 +02:00
qga qga: don't fail if mount doesn't have slave devices 2017-03-30 14:12:57 -05:00
qobject qobject: Propagate parse errors through qobject_from_json() 2017-03-07 16:07:47 +01:00
qom qom: Fix regression with 'qom-type' 2017-03-23 17:59:40 +00:00
replay replay: assert time only goes forward 2017-04-10 10:23:38 +01:00
roms Update OpenBIOS images to f233c3f built from submodule. 2017-03-15 19:42:08 +00:00
scripts scripts/qemugdb/mtree.py: fix up mtree dump 2017-04-07 15:24:56 +01:00
slirp slirp: Send RDNSS in RA only if host has an IPv6 DNS server 2017-03-29 00:51:25 +02:00
stubs cpus: define QEMUTimerListNotifyCB for QEMU system emulation 2017-03-14 13:28:29 +01:00
target target/i386/misc_helper: wrap BQL around another IRQ generator 2017-04-10 10:14:50 +01:00
tcg tcg/sparc: Zero extend address argument to ld/st helpers 2017-04-03 12:59:37 +01:00
tests block: Use bdrv_coroutine_enter to start I/O coroutines 2017-04-11 20:07:15 +08:00
trace trace: fix tcg tracing build breakage 2017-03-28 11:07:46 +01:00
ui io vnc sockets: Clean up SocketAddressKind switches 2017-04-03 17:11:39 +02:00
util async: Introduce aio_co_enter 2017-04-11 20:07:15 +08:00
.dir-locals.el Add .dir-locals.el file to configure emacs coding style 2015-10-08 19:46:01 +03:00
.exrc
.gitignore qapi: Clean up build of generated documentation 2017-03-16 07:13:02 +01:00
.gitmodules ppc: add skiboot firmware for the pnv platform 2016-10-28 09:36:58 +11:00
.mailmap
.shippable.yml .shippable: add s390x-cross target 2017-02-28 20:31:01 +08:00
.travis.yml .travis.yml: split VM based builds 2017-02-10 13:19:56 +00:00
accel.c clean-up: removed duplicate #includes 2016-10-28 18:17:24 +03:00
arch_init.c nios2: Add support for Nios-II R1 2017-01-24 13:10:36 -08:00
atomic_template.h tcg: Add atomic128 helpers 2016-10-26 08:29:01 -07:00
balloon.c trace: switch to modular code generation for sub-directories 2017-01-31 17:11:18 +00:00
block.c block/io: Comment out permission assertions 2017-04-11 16:09:31 +01:00
blockdev-nbd.c nbd sockets vnc: Mark problematic address family tests TODO 2017-04-03 17:11:39 +02:00
blockdev.c block: Fix unpaired aio_disable_external in external snapshot 2017-04-07 14:44:06 +02:00
blockjob.c blockjob: Use bdrv_coroutine_enter to start coroutine 2017-04-11 20:07:15 +08:00
bootdevice.c error: Remove NULL checks on error_propagate() calls 2016-06-20 16:38:13 +02:00
bt-host.c all: Clean up includes 2016-02-04 17:41:30 +00:00
bt-vhci.c all: Clean up includes 2016-02-04 17:41:30 +00:00
Changelog
CODING_STYLE CODING_STYLE: Mention preferred comment form 2017-02-28 09:03:38 +03:00
configure configure: on Windows minimum glib version must be 2.30 2017-04-10 12:54:35 +01:00
COPYING
COPYING.LIB
cpu-exec-common.c ui/console: ensure do_safe_dpy_refresh holds BQL 2017-03-28 10:52:24 +01:00
cpu-exec.c cpu-exec: update icount after each TB_EXIT 2017-04-10 10:23:38 +01:00
cpus-common.c *_run_on_cpu: introduce run_on_cpu_data type 2016-10-31 15:00:25 +01:00
cpus.c cpus: call cpu_update_icount on read 2017-04-10 10:23:38 +01:00
cputlb.c cputlb: Don't assume do_unassigned_access() never returns 2017-02-28 12:08:15 +00:00
device_tree.c qemu-common: stop including qemu/bswap.h from qemu-common.h 2016-05-19 16:42:28 +02:00
device-hotplug.c blockdev: Split monitor reference from BB creation 2016-03-17 15:47:56 +01:00
disas.c Fix Thumb-1 BE32 execution and disassembly. 2017-02-07 18:29:59 +00:00
dma-helpers.c block: explicitly acquire aiocontext in bottom halves that need it 2017-02-21 11:39:39 +00:00
dump.c error: Remove NULL checks on error_propagate() calls 2016-06-20 16:38:13 +02:00
exec.c exec: revert MemoryRegionCache 2017-04-03 13:41:53 +02:00
gdbstub.c gdbstub: Fix vCont behaviour 2017-02-16 14:06:56 +01:00
HACKING HACKING: document #include order 2017-01-03 16:38:47 +00:00
hax-stub.c Plumb the HAXM-based hardware acceleration support 2017-01-19 22:07:46 +01:00
hmp-commands-info.hx qmp/hmp: add query-vm-generation-id and 'info vm-generation-id' commands 2017-03-02 07:14:27 +02:00
hmp-commands.hx COLO: Add 'x-colo-lost-heartbeat' command to trigger failover 2016-10-30 15:17:39 +05:30
hmp.c Bugfix: Handle error if VM Generation ID device not present 2017-03-15 19:37:19 +02:00
hmp.h qmp/hmp: add query-vm-generation-id and 'info vm-generation-id' commands 2017-03-02 07:14:27 +02:00
ioport.c trace: switch to modular code generation for sub-directories 2017-01-31 17:11:18 +00:00
iothread.c monitor: add poll-* properties into query-iothreads result 2017-02-21 18:29:01 +00:00
kvm-all.c qemu-timer: do not include sysemu/cpus.h from util/qemu-timer.h 2017-03-14 13:28:18 +01:00
kvm-stub.c KVM: move SIG_IPI handling to kvm-all.c 2017-03-03 16:40:02 +01:00
LICENSE vfio: move hw/misc/vfio.c to hw/vfio/pci.c Move vfio.h into include/hw/vfio 2014-12-19 15:24:06 -07:00
MAINTAINERS MAINTAINERS: Add myself for files I touched recently 2017-03-21 10:42:12 +01:00
Makefile qapi: Drop excessive Make dependencies on qapi2texi.py 2017-03-21 10:42:15 +01:00
Makefile.objs target-mips: replace few LOG_DISAS() with trace points 2017-03-20 11:06:32 +00:00
Makefile.target makefile: merge GENERATED_HEADERS & GENERATED_SOURCES variables 2017-03-16 11:51:15 +08:00
memory_ldst.inc.c exec: introduce memory_ldst.inc.c 2016-12-22 16:00:23 +01:00
memory_mapping.c memory: Replace skip_dump flag with "ram_device" 2016-10-31 09:53:03 -06:00
memory.c clear pending status before calling memory commit 2017-03-24 11:48:48 +01:00
module-common.c all: Clean up includes 2016-02-04 17:41:30 +00:00
monitor.c qemu-timer: do not include sysemu/cpus.h from util/qemu-timer.h 2017-03-14 13:28:18 +01:00
numa.c numa,spapr: align default numa node memory size to 256MB 2017-03-22 11:32:42 +11:00
os-posix.c use g_path_get_dirname instead of dirname 2016-07-17 09:59:21 +02:00
os-win32.c all: Clean up includes 2016-02-04 17:41:30 +00:00
page_cache.c coccinelle: Remove unnecessary variables for function return value 2016-06-20 16:38:13 +02:00
qapi-schema.json qapi-schema: SocketAddressFlat variants 'vsock' and 'fd' 2017-04-03 17:11:39 +02:00
qdev-monitor.c migrate: Introduce a 'dc->vmsd' check to avoid segfault for --only-migratable 2017-02-28 11:30:22 +00:00
qdict-test-data.txt
qemu-bridge-helper.c all: Remove unnecessary glib.h includes 2016-06-07 18:19:24 +03:00
qemu-doc.texi nios2 target support 2017-01-25 13:30:23 +00:00
qemu-ga.texi qemu-ga: Remove stray 'q' in documentation 2016-10-28 18:17:23 +03:00
qemu-img-cmds.hx qemu-img: img_create does not support image-opts, fix docs 2017-04-07 14:44:06 +02:00
qemu-img.c qemu-img: print short help on getopt failure 2017-03-27 16:50:36 +02:00
qemu-img.texi qemu-img: make convert async 2017-02-28 20:40:31 +01:00
qemu-io-cmds.c qemu-io-cmds: Use bdrv_coroutine_enter 2017-04-11 20:07:15 +08:00
qemu-io.c qemu-io: Return non-zero exit code on failure 2017-02-12 00:47:42 +01:00
qemu-nbd.c qemu-ga: obey LISTEN_PID when using systemd socket activation 2017-03-19 11:12:12 +01:00
qemu-nbd.texi nbd: Add qemu-nbd -D for human-readable description 2016-11-02 09:28:55 +01:00
qemu-option-trace.texi docs: update manpage for stderr->log rename 2017-02-13 13:38:31 +00:00
qemu-options-wrapper.h hxtool: emit Texinfo headings as @subsection 2017-01-16 17:52:35 +01:00
qemu-options.h Clean up ill-advised or unusual header guards 2016-07-12 16:20:46 +02:00
qemu-options.hx docs: Add a note about mixing bootindex with "-boot order" 2017-03-14 13:26:36 +01:00
qemu-seccomp.c seccomp: adding getrusage to the whitelist 2016-09-21 11:26:02 +02:00
qemu-tech.texi qemu-doc: merge qemu-tech and qemu-doc 2016-10-07 10:05:54 +02:00
qemu.nsi qemu-doc: merge qemu-tech and qemu-doc 2016-10-07 10:05:54 +02:00
qemu.sasl
qmp.c block: Ignore guest dev permissions during incoming migration 2017-04-07 14:44:05 +02:00
qtest.c qtest: fix a memory leak 2017-03-01 00:09:28 +04:00
README README: Add linux to macOS build info 2017-01-24 23:26:52 +03:00
replication.c replication: Introduce new APIs to do replication operation 2016-09-13 11:00:56 +01:00
replication.h replication: Introduce new APIs to do replication operation 2016-09-13 11:00:56 +01:00
rules.mak qapi: Clean up build of generated documentation 2017-03-16 07:13:02 +01:00
softmmu_template.h cputlb: Tidy some macros 2016-10-26 08:29:00 -07:00
spice-qemu-char.c spice-char: fix segfault in char_spice_finalize 2017-03-03 16:40:03 +01:00
tcg-runtime.c tcg: Add opcode for ctpop 2017-01-10 08:48:56 -08:00
tci.c tcg/tci: Add support for fence 2016-09-16 08:12:12 -07:00
thunk.c thunk: Rename args and fields in host-target bitmask conversion code 2016-06-07 18:19:24 +03:00
tpm.c qapi: Don't special-case simple union wrappers 2016-03-18 10:29:26 +01:00
trace-events qmp: Drop duplicated QMP command object checks 2017-03-05 09:14:19 +01:00
translate-all.c qemu-timer: do not include sysemu/cpus.h from util/qemu-timer.h 2017-03-14 13:28:18 +01:00
translate-all.h trace: Add per-vCPU tracing states for events with the 'vcpu' property 2016-07-18 18:23:12 +01:00
translate-common.c Merge branch 'icount-update' into HEAD 2017-03-03 16:39:18 +01:00
user-exec-stub.c stubs: group stubs for user-mode emulation 2017-01-16 17:52:35 +01:00
user-exec.c user-exec: handle synchronous signals from QEMU gracefully 2017-03-28 10:50:35 +01:00
VERSION Update version for v2.9.0-rc4 release 2017-04-11 17:18:03 +01:00
version.rc
vl.c main-loop: remove now unnecessary optimization 2017-03-14 13:29:21 +01:00
xen-common-stub.c char: rename CharDriverState Chardev 2017-01-27 18:07:59 +01:00
xen-common.c char: rename CharDriverState Chardev 2017-01-27 18:07:59 +01:00
xen-hvm-stub.c fix MSI injection on Xen 2016-02-06 20:44:10 +02:00
xen-hvm.c trace: switch to modular code generation for sub-directories 2017-01-31 17:11:18 +00:00
xen-mapcache.c trace: switch to modular code generation for sub-directories 2017-01-31 17:11:18 +00:00

         QEMU README
         ===========

QEMU is a generic and open source machine & userspace emulator and
virtualizer.

QEMU is capable of emulating a complete machine in software without any
need for hardware virtualization support. By using dynamic translation,
it achieves very good performance. QEMU can also integrate with the Xen
and KVM hypervisors to provide emulated hardware while allowing the
hypervisor to manage the CPU. With hypervisor support, QEMU can achieve
near native performance for CPUs. When QEMU emulates CPUs directly it is
capable of running operating systems made for one machine (e.g. an ARMv7
board) on a different machine (e.g. an x86_64 PC board).

QEMU is also capable of providing userspace API virtualization for Linux
and BSD kernel interfaces. This allows binaries compiled against one
architecture ABI (e.g. the Linux PPC64 ABI) to be run on a host using a
different architecture ABI (e.g. the Linux x86_64 ABI). This does not
involve any hardware emulation, simply CPU and syscall emulation.

QEMU aims to fit into a variety of use cases. It can be invoked directly
by users wishing to have full control over its behaviour and settings.
It also aims to facilitate integration into higher level management
layers, by providing a stable command line interface and monitor API.
It is commonly invoked indirectly via the libvirt library when using
open source applications such as oVirt, OpenStack and virt-manager.

QEMU as a whole is released under the GNU General Public License,
version 2. For full licensing details, consult the LICENSE file.


Building
========

QEMU is multi-platform software intended to be buildable on all modern
Linux platforms, OS-X, Win32 (via the Mingw64 toolchain) and a variety
of other UNIX targets. The simple steps to build QEMU are:

  mkdir build
  cd build
  ../configure
  make

Additional information can also be found online via the QEMU website:

  http://qemu-project.org/Hosts/Linux
  http://qemu-project.org/Hosts/Mac
  http://qemu-project.org/Hosts/W32


Submitting patches
==================

The QEMU source code is maintained under the GIT version control system.

   git clone git://git.qemu-project.org/qemu.git

When submitting patches, the preferred approach is to use 'git
format-patch' and/or 'git send-email' to format & send the mail to the
qemu-devel@nongnu.org mailing list. All patches submitted must contain
a 'Signed-off-by' line from the author. Patches should follow the
guidelines set out in the HACKING and CODING_STYLE files.

Additional information on submitting patches can be found online via
the QEMU website

  http://qemu-project.org/Contribute/SubmitAPatch
  http://qemu-project.org/Contribute/TrivialPatches


Bug reporting
=============

The QEMU project uses Launchpad as its primary upstream bug tracker. Bugs
found when running code built from QEMU git or upstream released sources
should be reported via:

  https://bugs.launchpad.net/qemu/

If using QEMU via an operating system vendor pre-built binary package, it
is preferable to report bugs to the vendor's own bug tracker first. If
the bug is also known to affect latest upstream code, it can also be
reported via launchpad.

For additional information on bug reporting consult:

  http://qemu-project.org/Contribute/ReportABug


Contact
=======

The QEMU community can be contacted in a number of ways, with the two
main methods being email and IRC

 - qemu-devel@nongnu.org
   http://lists.nongnu.org/mailman/listinfo/qemu-devel
 - #qemu on irc.oftc.net

Information on additional methods of contacting the community can be
found online via the QEMU website:

  http://qemu-project.org/Contribute/StartHere

-- End