QEMU With E2K User Support
Go to file
Murilo Opsfelder Araujo c4365735a7 block/nbd: fix segmentation fault when .desc is not null-terminated
The find_desc_by_name() from util/qemu-option.c relies on the .name not being
NULL to call strcmp(). This check becomes unsafe when the list is not
NULL-terminated, which is the case of nbd_runtime_opts in block/nbd.c, and can
result in segmentation fault when strcmp() tries to access an invalid memory:

    #0 0x00007fff8c75f7d4 in __strcmp_power9 () from /lib64/libc.so.6
    #1 0x00000000102d3ec8 in find_desc_by_name (desc=0x1036d6f0, name=0x28e46670 "server.path") at util/qemu-option.c:166
    #2 0x00000000102d93e0 in qemu_opts_absorb_qdict (opts=0x28e47a80, qdict=0x28e469a0, errp=0x7fffec247c98) at util/qemu-option.c:1026
    #3 0x000000001012a2e4 in nbd_open (bs=0x28e42290, options=0x28e469a0, flags=24578, errp=0x7fffec247d80) at block/nbd.c:406
    #4 0x00000000100144e8 in bdrv_open_driver (bs=0x28e42290, drv=0x1036e070 <bdrv_nbd_unix>, node_name=0x0, options=0x28e469a0, open_flags=24578, errp=0x7fffec247f50) at block.c:1135
    #5 0x0000000010015b04 in bdrv_open_common (bs=0x28e42290, file=0x0, options=0x28e469a0, errp=0x7fffec247f50) at block.c:1395

>From gdb, the desc[i].name was not NULL and resulted in strcmp() accessing an
invalid memory:

    >>> p desc[5]
    $8 = {
      name = 0x1037f098 "R27A",
      type = 1561964883,
      help = 0xc0bbb23e <error: Cannot access memory at address 0xc0bbb23e>,
      def_value_str = 0x2 <error: Cannot access memory at address 0x2>
    }
    >>> p desc[6]
    $9 = {
      name = 0x103dac78 <__gcov0.do_qemu_init_bdrv_nbd_init> "\001",
      type = 272101528,
      help = 0x29ec0b754403e31f <error: Cannot access memory at address 0x29ec0b754403e31f>,
      def_value_str = 0x81f343b9 <error: Cannot access memory at address 0x81f343b9>
    }

This patch fixes the segmentation fault in strcmp() by adding a NULL element at
the end of nbd_runtime_opts.desc list, which is the common practice to most of
other structs like runtime_opts in block/null.c. Thus, the desc[i].name != NULL
check becomes safe because it will not evaluate to true when .desc list reached
its end.

Reported-by: R. Nageswara Sastry <nasastry@in.ibm.com>
Buglink: https://bugs.launchpad.net/qemu/+bug/1727259
Signed-off-by: Murilo Opsfelder Araujo <muriloo@linux.vnet.ibm.com>
Message-Id: <20180105133241.14141-2-muriloo@linux.vnet.ibm.com>
CC: qemu-stable@nongnu.org
Fixes: 7ccc44fd7d
Signed-off-by: Eric Blake <eblake@redhat.com>
2018-01-08 09:12:23 -06:00
accel i386: hvf: add code base from Google's QEMU repository 2017-12-22 15:01:20 +01:00
audio
backends tpm: tpm_emulator: get and set buffer size of device 2017-12-14 23:39:15 -05:00
block block/nbd: fix segmentation fault when .desc is not null-terminated 2018-01-08 09:12:23 -06:00
bsd-user misc: remove headers implicitly included 2017-12-18 17:07:02 +03:00
capstone@22ead3e0bf disas: Add capstone as submodule 2017-10-26 11:56:20 +02:00
chardev chardev: convert the socket server to QIONetListener 2017-12-21 09:30:32 +01:00
contrib contrib: add systemd unit files 2017-12-20 22:29:26 +01:00
crypto crypto: afalg: fix a NULL pointer dereference 2017-11-08 11:05:09 +00:00
default-configs xilinx_spips: Add support for the ZynqMP Generic QSPI 2017-12-13 17:59:22 +00:00
disas nios2: remove duplicated includes (in code commented out) 2017-12-18 17:07:02 +03:00
docs qapi-docs: fix a comment typo 2017-12-20 19:18:33 +01:00
dtc@558cd81bdd
fpu
fsdev
gdb-xml
hw Block layer patches 2018-01-08 13:44:01 +00:00
include Block layer patches 2018-01-08 13:44:01 +00:00
io io: introduce a network socket listener API 2017-12-15 15:07:26 +00:00
libdecnumber build: remove CONFIG_LIBDECNUMBER 2017-10-16 18:03:52 +02:00
linux-headers linux-headers: update to 4.15-rc1 2017-12-13 17:59:23 +00:00
linux-user target/sh4: Use cmpxchg for movco when parallel_cpus 2017-12-18 23:29:31 +01:00
migration Remove empty statements 2017-12-18 17:07:02 +03:00
nbd nbd/server: Optimize final chunk of sparse read 2018-01-08 09:12:23 -06:00
net net: Remove the legacy "-net channel" parameter 2017-12-22 10:05:26 +08:00
pc-bios pc-bios/s390-ccw.img: update image 2017-12-14 17:56:54 +01:00
po
qapi block: Document that x-blockdev-change breaks quorum children list 2017-12-22 15:03:41 +01:00
qga sockets: remove obsolete code that updated listen address 2017-12-21 09:22:44 +01:00
qobject qapi: Add qobject_is_equal() 2017-11-17 18:21:30 +01:00
qom tcg: Add CPUState cflags_next_tb 2017-10-24 13:53:41 -07:00
replay
roms seabios: update to 1.11 final 2017-11-14 15:36:08 +01:00
scripts * NBD and chardev conversion to QIONetListener (Daniel) 2017-12-21 16:34:23 +00:00
scsi scsi: replace hex constants with #defines 2017-12-21 09:30:32 +01:00
slirp slirp: don't zero the whole ti_i when m == NULL 2017-11-09 18:59:22 +01:00
stubs tpm: add stubs 2017-10-25 01:05:04 -04:00
target Initial support for the HVF accelerator 2018-01-08 11:39:50 +00:00
tcg tcg/s390x: Use constant pool for prologue 2017-11-03 09:33:45 +01:00
tests test-bdrv-drain: Test graph changes in drained section 2017-12-22 15:05:32 +01:00
trace trace: Try using tracefs first 2017-12-18 14:37:36 +00:00
ui ui: generate qcode to linux mappings 2017-12-14 15:24:30 -08:00
util * NBD and chardev conversion to QIONetListener (Daniel) 2017-12-21 16:34:23 +00:00
.dir-locals.el
.editorconfig
.exrc
.gdbinit
.gitignore .gitignore: remove vscclient 2017-12-18 17:07:02 +03:00
.gitmodules disas: Add capstone as submodule 2017-10-26 11:56:20 +02:00
.mailmap MAINTAINERS: Update Paul Burton's email address 2017-11-06 07:36:43 -08:00
.shippable.yml
.travis.yml
arch_init.c
balloon.c
block.c block: Keep nodes drained between reopen_queue/multiple 2017-12-22 15:05:32 +01:00
blockdev-nbd.c blockdev: convert internal NBD server to QIONetListener 2017-12-21 09:30:32 +01:00
blockdev.c block: Remove the obsolete -drive boot=on|off parameter 2017-12-22 15:03:41 +01:00
blockjob.c blockjob: Pause job on draining any job BDS 2017-12-22 15:05:32 +01:00
bootdevice.c
bt-host.c
bt-vhci.c
Changelog Use HTTPS for qemu.org and other domains 2017-11-21 13:34:13 +00:00
CODING_STYLE
configure i386: hvf: add code base from Google's QEMU repository 2017-12-22 15:01:20 +01:00
COPYING
COPYING.LIB
COPYING.PYTHON
cpus-common.c
cpus.c i386: hvf: add code base from Google's QEMU repository 2017-12-22 15:01:20 +01:00
device_tree.c
device-hotplug.c
disas.c disas: Dump insn bytes along with capstone disassembly 2017-11-09 08:46:38 +01:00
dma-helpers.c
dump.c kdump: set vmcoreinfo location 2017-10-15 05:54:40 +03:00
exec.c exec: Don't reuse unassigned_mem_ops for io_mem_rom 2017-12-21 09:30:32 +01:00
gdbstub.c gdbstub: add tracing 2017-12-18 14:37:36 +00:00
HACKING
hmp-commands-info.hx
hmp-commands.hx hmp-commands: Remove the deprecated usb_add and usb_del 2017-12-14 10:16:52 +00:00
hmp.c block: Don't acquire AioContext in hmp_qemu_io() 2017-12-22 15:03:41 +01:00
hmp.h migrate: HMP migate_continue 2017-10-23 18:03:31 +02:00
ioport.c
iothread.c iothread: fix iothread_stop() race condition 2017-12-19 10:25:09 +00:00
LICENSE
MAINTAINERS MAITAINERS: List Fam Zheng as reviewer for SCSI patches 2017-12-21 09:22:44 +01:00
Makefile Makefile: add more targets to the UNCHECKED_GOALS rule 2017-12-18 17:07:02 +03:00
Makefile.objs tpm: add stubs 2017-10-25 01:05:04 -04:00
Makefile.target Fix build of console and GUI executables for Windows 2017-11-23 10:46:42 +00:00
memory_ldst.inc.c
memory_mapping.c
memory.c memory: remove unused memory_region_set_global_locking() 2017-12-18 17:07:02 +03:00
module-common.c
monitor.c misc: remove old i386 dependency 2017-12-18 17:07:02 +03:00
numa.c numa: remove unused #include 2017-12-18 17:07:02 +03:00
os-posix.c os-posix: Drop misleading comment 2017-10-16 21:01:37 +03:00
os-win32.c
qapi-schema.json qmp: remove qmp_cpu 2017-12-20 19:18:33 +01:00
qdev-monitor.c pci-assign: Remove 2017-11-05 14:52:10 +01:00
qdict-test-data.txt
qemu-bridge-helper.c
qemu-doc.texi Block layer patches 2018-01-08 13:44:01 +00:00
qemu-ga.texi
qemu-img-cmds.hx
qemu-img.c block: Add errp to bdrv_snapshot_goto() 2017-11-21 14:48:22 +01:00
qemu-img.texi qemu-img.1: Image invalidation on qemu-img commit 2017-10-26 14:59:18 +02:00
qemu-io-cmds.c block: Keep nodes drained between reopen_queue/multiple 2017-12-22 15:05:32 +01:00
qemu-io.c
qemu-keymap.c tools: add qemu-keymap 2017-10-16 14:50:54 +02:00
qemu-nbd.c blockdev: convert qemu-nbd server to QIONetListener 2017-12-21 09:30:32 +01:00
qemu-nbd.texi
qemu-option-trace.texi
qemu-options-wrapper.h qemu-options: Remove stray colons from output of --help 2017-12-20 09:04:27 +01:00
qemu-options.h
qemu-options.hx Block layer patches 2018-01-08 13:44:01 +00:00
qemu-seccomp.c
qemu-tech.texi
qemu.nsi Use HTTPS for qemu.org and other domains 2017-11-21 13:34:13 +00:00
qemu.sasl
qmp.c qmp: remove qmp_cpu 2017-12-20 19:18:33 +01:00
qtest.c
README Use HTTPS for qemu.org and other domains 2017-11-21 13:34:13 +00:00
replication.c
replication.h
rules.mak
thunk.c
tpm.c tpm: remove tpm_register_model() 2017-12-14 23:39:15 -05:00
trace-events gdbstub: add tracing 2017-12-18 14:37:36 +00:00
VERSION Open 2.12 development tree 2017-12-13 17:05:59 +00:00
version.rc Use HTTPS for qemu.org and other domains 2017-11-21 13:34:13 +00:00
vl.c block: Remove the deprecated -hdachs option 2017-12-22 15:03:41 +01:00

         QEMU README
         ===========

QEMU is a generic and open source machine & userspace emulator and
virtualizer.

QEMU is capable of emulating a complete machine in software without any
need for hardware virtualization support. By using dynamic translation,
it achieves very good performance. QEMU can also integrate with the Xen
and KVM hypervisors to provide emulated hardware while allowing the
hypervisor to manage the CPU. With hypervisor support, QEMU can achieve
near native performance for CPUs. When QEMU emulates CPUs directly it is
capable of running operating systems made for one machine (e.g. an ARMv7
board) on a different machine (e.g. an x86_64 PC board).

QEMU is also capable of providing userspace API virtualization for Linux
and BSD kernel interfaces. This allows binaries compiled against one
architecture ABI (e.g. the Linux PPC64 ABI) to be run on a host using a
different architecture ABI (e.g. the Linux x86_64 ABI). This does not
involve any hardware emulation, simply CPU and syscall emulation.

QEMU aims to fit into a variety of use cases. It can be invoked directly
by users wishing to have full control over its behaviour and settings.
It also aims to facilitate integration into higher level management
layers, by providing a stable command line interface and monitor API.
It is commonly invoked indirectly via the libvirt library when using
open source applications such as oVirt, OpenStack and virt-manager.

QEMU as a whole is released under the GNU General Public License,
version 2. For full licensing details, consult the LICENSE file.


Building
========

QEMU is multi-platform software intended to be buildable on all modern
Linux platforms, OS-X, Win32 (via the Mingw64 toolchain) and a variety
of other UNIX targets. The simple steps to build QEMU are:

  mkdir build
  cd build
  ../configure
  make

Additional information can also be found online via the QEMU website:

  https://qemu.org/Hosts/Linux
  https://qemu.org/Hosts/Mac
  https://qemu.org/Hosts/W32


Submitting patches
==================

The QEMU source code is maintained under the GIT version control system.

   git clone git://git.qemu.org/qemu.git

When submitting patches, the preferred approach is to use 'git
format-patch' and/or 'git send-email' to format & send the mail to the
qemu-devel@nongnu.org mailing list. All patches submitted must contain
a 'Signed-off-by' line from the author. Patches should follow the
guidelines set out in the HACKING and CODING_STYLE files.

Additional information on submitting patches can be found online via
the QEMU website

  https://qemu.org/Contribute/SubmitAPatch
  https://qemu.org/Contribute/TrivialPatches


Bug reporting
=============

The QEMU project uses Launchpad as its primary upstream bug tracker. Bugs
found when running code built from QEMU git or upstream released sources
should be reported via:

  https://bugs.launchpad.net/qemu/

If using QEMU via an operating system vendor pre-built binary package, it
is preferable to report bugs to the vendor's own bug tracker first. If
the bug is also known to affect latest upstream code, it can also be
reported via launchpad.

For additional information on bug reporting consult:

  https://qemu.org/Contribute/ReportABug


Contact
=======

The QEMU community can be contacted in a number of ways, with the two
main methods being email and IRC

 - qemu-devel@nongnu.org
   https://lists.nongnu.org/mailman/listinfo/qemu-devel
 - #qemu on irc.oftc.net

Information on additional methods of contacting the community can be
found online via the QEMU website:

  https://qemu.org/Contribute/StartHere

-- End