From mboxrd@z Thu Jan  1 00:00:00 1970
Return-Path: <stable-bounces@dpdk.org>
Received: from dpdk.org (dpdk.org [92.243.14.124])
	by inbox.dpdk.org (Postfix) with ESMTP id 96655A0527
	for <public@inbox.dpdk.org>; Mon,  9 Nov 2020 19:43:42 +0100 (CET)
Received: from [92.243.14.124] (localhost [127.0.0.1])
	by dpdk.org (Postfix) with ESMTP id 8ED3B6883;
	Mon,  9 Nov 2020 19:43:41 +0100 (CET)
Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com
 [209.85.128.43]) by dpdk.org (Postfix) with ESMTP id C7A216883
 for <stable@dpdk.org>; Mon,  9 Nov 2020 19:43:39 +0100 (CET)
Received: by mail-wm1-f43.google.com with SMTP id t67so428521wmt.5
 for <stable@dpdk.org>; Mon, 09 Nov 2020 10:43:39 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025;
 h=from:to:cc:subject:date:message-id:in-reply-to:references
 :mime-version:content-transfer-encoding;
 bh=D60Lj/NPpBVFJOfrTKJsmUPBPOUBu1UkPB9aDVxdOu4=;
 b=kjnpzUhVewcHGqIvNqIe08CUo0epTDvh3oCu2tqPTK6r82KA91GYyQ0wHDt1nm3plM
 49nbtLTFz/8FJQAGqtubvJY3lvy6UEuflpuc8lpaBj19kQ6IphyuUzGa8SAY4mXUeeib
 ymTieNNeuARdy9nghDC4FTJCxW2oUcrokgwUKjZ8Fs07AYfU4+iFacDLZ84be9Z7hCpI
 PT+1HB2xbqKBhdS2YWqfISBTneXKrXwhN2XS3+DKB+5ATOCdwEVRyM0eut8J5iUTM/pl
 Q1xol7RYg5c0KPN55PqpFrsJJIfV1xaBtbK1uGVQNuu+OnRyYSVUWLGhVA/ZHAXdjFmQ
 atMw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20161025;
 h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to
 :references:mime-version:content-transfer-encoding;
 bh=D60Lj/NPpBVFJOfrTKJsmUPBPOUBu1UkPB9aDVxdOu4=;
 b=QMHeA5m5HZ9H2Gcf0yuQC0YiVg8aLTh9N3Ko4UzfBkI4vyAJD7Ddu0dp7/tk3VU9JH
 qw3QNqAFkQgqBzp1tDB764fb47VbhH0oc276tpF3F+MonOnrdNjXpcrEmGMn8x8V7JTD
 IhI0ASxnn6+DSuiOCDdbXCoSB7IW7g/8uVhzl3tXPauwpP/AGhgnV2P2klldePaqvE+z
 5qfcClJR8Gh46NLj++X6GCU1yCwShEcXbVVLwMrp36l9N+geTyUpApTWDtxww8uKwYb8
 YEtZsC7mjE5/G+5GyuwEnucdFXoy/8Dy+uA7NWu3Lo3LcbL83Dvs1WpcOmjBuc9sAjks
 CdJA==
X-Gm-Message-State: AOAM531gjK1jxQKw7w+ajTGvruRg34zDVhr7HHZfXAT/Lnd67kfd4Nua
 ZtR47kt5nv2UHQFbTtyQaTJP7lUrBAxUazy3
X-Google-Smtp-Source: ABdhPJwU2pb2eNFSg9EjcFWy48uYPKKCgIM0+GNXFo/+kbsWiPc/wAsD0BX281k9u+K3t2LrkdwYiw==
X-Received: by 2002:a1c:a98c:: with SMTP id s134mr537901wme.159.1604947418599; 
 Mon, 09 Nov 2020 10:43:38 -0800 (PST)
Received: from localhost ([88.98.246.218])
 by smtp.gmail.com with ESMTPSA id 130sm333599wmd.18.2020.11.09.10.43.37
 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
 Mon, 09 Nov 2020 10:43:37 -0800 (PST)
From: luca.boccassi@gmail.com
To: Maxime Coquelin <maxime.coquelin@redhat.com>
Cc: Chenbo Xia <chenbo.xia@intel.com>,
	dpdk stable <stable@dpdk.org>
Date: Mon,  9 Nov 2020 18:40:29 +0000
Message-Id: <20201109184111.3463090-41-luca.boccassi@gmail.com>
X-Mailer: git-send-email 2.27.0
In-Reply-To: <20201109184111.3463090-1-luca.boccassi@gmail.com>
References: <20201028104606.3504127-207-luca.boccassi@gmail.com>
 <20201109184111.3463090-1-luca.boccassi@gmail.com>
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Subject: [dpdk-stable] patch 'vhost: validate index in available entries
	API' has been queued to stable release 19.11.6
X-BeenThere: stable@dpdk.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: patches for DPDK stable branches <stable.dpdk.org>
List-Unsubscribe: <https://mails.dpdk.org/options/stable>,
 <mailto:stable-request@dpdk.org?subject=unsubscribe>
List-Archive: <http://mails.dpdk.org/archives/stable/>
List-Post: <mailto:stable@dpdk.org>
List-Help: <mailto:stable-request@dpdk.org?subject=help>
List-Subscribe: <https://mails.dpdk.org/listinfo/stable>,
 <mailto:stable-request@dpdk.org?subject=subscribe>
Errors-To: stable-bounces@dpdk.org
Sender: "stable" <stable-bounces@dpdk.org>

Hi,

FYI, your patch has been queued to stable release 19.11.6

Note it hasn't been pushed to http://dpdk.org/browse/dpdk-stable yet.
It will be pushed if I get no objections before 11/11/20. So please
shout if anyone has objections.

Also note that after the patch there's a diff of the upstream commit vs the
patch applied to the branch. This will indicate if there was any rebasing
needed to apply to the stable branch. If there were code changes for rebasing
(ie: not only metadata diffs), please double check that the rebase was
correctly done.

Queued patches are on a temporary branch at:
https://github.com/bluca/dpdk-stable

This queued commit can be viewed at:
https://github.com/bluca/dpdk-stable/commit/d08a94deae48b03553538bbb8d6b44323c4ee304

Thanks.

Luca Boccassi

---
>From d08a94deae48b03553538bbb8d6b44323c4ee304 Mon Sep 17 00:00:00 2001
From: Maxime Coquelin <maxime.coquelin@redhat.com>
Date: Mon, 19 Oct 2020 19:34:10 +0200
Subject: [PATCH] vhost: validate index in available entries API

[ upstream commit 8c042f8191f8337da30958d0f622776861e417a5 ]

This patch validates the queue index parameter, in order
to ensure neither out-of-bound accesses nor NULL pointer
dereferencing happen.

Fixes: a67f286a6596 ("vhost: export queue free entries")

Signed-off-by: Maxime Coquelin <maxime.coquelin@redhat.com>
Reviewed-by: Chenbo Xia <chenbo.xia@intel.com>
---
 lib/librte_vhost/vhost.c | 5 +++++
 1 file changed, 5 insertions(+)

diff --git a/lib/librte_vhost/vhost.c b/lib/librte_vhost/vhost.c
index 0d65719f33..0f6c1ef8de 100644
--- a/lib/librte_vhost/vhost.c
+++ b/lib/librte_vhost/vhost.c
@@ -1258,7 +1258,12 @@ rte_vhost_avail_entries(int vid, uint16_t queue_id)
 	if (!dev)
 		return 0;
 
+	if (queue_id >= VHOST_MAX_VRING)
+		return 0;
+
 	vq = dev->virtqueue[queue_id];
+	if (!vq)
+		return 0;
 
 	rte_spinlock_lock(&vq->access_lock);
 
-- 
2.27.0

---
  Diff of the applied patch vs upstream commit (please double-check if non-empty:
---
--- -	2020-11-09 18:40:12.812494287 +0000
+++ 0041-vhost-validate-index-in-available-entries-API.patch	2020-11-09 18:40:11.163311780 +0000
@@ -1 +1 @@
-From 8c042f8191f8337da30958d0f622776861e417a5 Mon Sep 17 00:00:00 2001
+From d08a94deae48b03553538bbb8d6b44323c4ee304 Mon Sep 17 00:00:00 2001
@@ -5,0 +6,2 @@
+[ upstream commit 8c042f8191f8337da30958d0f622776861e417a5 ]
+
@@ -11 +12,0 @@
-Cc: stable@dpdk.org
@@ -20 +21 @@
-index 0c9ba3b3af..193dafc369 100644
+index 0d65719f33..0f6c1ef8de 100644
@@ -23 +24 @@
-@@ -1260,7 +1260,12 @@ rte_vhost_avail_entries(int vid, uint16_t queue_id)
+@@ -1258,7 +1258,12 @@ rte_vhost_avail_entries(int vid, uint16_t queue_id)