From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from dpdk.org (dpdk.org [92.243.14.124]) by inbox.dpdk.org (Postfix) with ESMTP id DE7C7A0527 for ; Mon, 9 Nov 2020 19:43:45 +0100 (CET) Received: from [92.243.14.124] (localhost [127.0.0.1]) by dpdk.org (Postfix) with ESMTP id CE02D72ED; Mon, 9 Nov 2020 19:43:44 +0100 (CET) Received: from mail-wm1-f44.google.com (mail-wm1-f44.google.com [209.85.128.44]) by dpdk.org (Postfix) with ESMTP id E3CC969C8 for ; Mon, 9 Nov 2020 19:43:43 +0100 (CET) Received: by mail-wm1-f44.google.com with SMTP id h62so440253wme.3 for ; Mon, 09 Nov 2020 10:43:43 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=CJowS8r0+b0SdxcWsBnDzQP3tkITEXQ9fGyD28q8q2c=; b=bRg6/smvnK5UmiORZTsu2xVmemstQbbyBdQk+XPemHCuukGEfDqSueCkyIYKxkvYGf kWt3LHozl+DyvFtpGAQeCgx/bZagMYewqQNbM+KDtFpr/crmkAiLMVXUNJkFFjBqERul RziReTXYePTyMpCQ7SpN9Gx9f+XO4ht2nblQ+ibwWio66QST6qzofJ9TKd+uA/BZLgur QzGi+vYZS8cntoq7Uz6/MYUBSqzEcZiW6tyUfVqpwZjULJJ+kbsPsFw7KRnmZXRDXAm2 fKWxvuUQ0+0EIdNeRiprKQCVqibha2iOD82booVCCwdsM/kQhRdF4u+KJiMaAZVlEK8M FpcA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:in-reply-to :references:mime-version:content-transfer-encoding; bh=CJowS8r0+b0SdxcWsBnDzQP3tkITEXQ9fGyD28q8q2c=; b=W3dYDu9kU5I3CiV/hv2vghONkGuckAAJoKAH3EOWs4f2hnodIqWpYDDunjoY4zDCJP w9cx87UyCj1b0H3CejTkbgnQSfmk34uGMbromlbx3OsVTh/Fv/Ck/PdIAZp8fIKbGVqA L32UPD1VWGys7KTH/8y39DNVqTy9/yV+hr4GGzDjhzqifkNaYhHI52lpl/hRklra2NQ+ HMomNMzBasbA8qI2q6dPjlL0qz0WyYjU8gzE2Ppf34+8ZhjioDS2oKKjAvF4D0QIj+Wj mxv6wJz6m6QcQNw1Zwt5/+JCijzhMKnWvqeB7XSRkj9Hr+oUTvl4Dmrpi6ryV4tYU2Xy i1CQ== X-Gm-Message-State: AOAM533tjZdfkOi3w1D2acmQX+WKj1DdozwvMxyES6kSvW68xBdE5xvH qFZ690Mlevs6XYtpF2YlryY= X-Google-Smtp-Source: ABdhPJxxsQyJbIjQQisPNWsCP470/gmpfzSf0BjMLlC19z2gaSsRDU8RCjBWiqo+R9+99bN+Eskjbw== X-Received: by 2002:a1c:e056:: with SMTP id x83mr566541wmg.83.1604947422725; Mon, 09 Nov 2020 10:43:42 -0800 (PST) Received: from localhost ([88.98.246.218]) by smtp.gmail.com with ESMTPSA id t5sm318148wmg.19.2020.11.09.10.43.41 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 09 Nov 2020 10:43:41 -0800 (PST) From: luca.boccassi@gmail.com To: Maxime Coquelin Cc: Chenbo Xia , dpdk stable Date: Mon, 9 Nov 2020 18:40:32 +0000 Message-Id: <20201109184111.3463090-44-luca.boccassi@gmail.com> X-Mailer: git-send-email 2.27.0 In-Reply-To: <20201109184111.3463090-1-luca.boccassi@gmail.com> References: <20201028104606.3504127-207-luca.boccassi@gmail.com> <20201109184111.3463090-1-luca.boccassi@gmail.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Subject: [dpdk-stable] patch 'vhost: validate index in inflight API' has been queued to stable release 19.11.6 X-BeenThere: stable@dpdk.org X-Mailman-Version: 2.1.15 Precedence: list List-Id: patches for DPDK stable branches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: stable-bounces@dpdk.org Sender: "stable" Hi, FYI, your patch has been queued to stable release 19.11.6 Note it hasn't been pushed to http://dpdk.org/browse/dpdk-stable yet. It will be pushed if I get no objections before 11/11/20. So please shout if anyone has objections. Also note that after the patch there's a diff of the upstream commit vs the patch applied to the branch. This will indicate if there was any rebasing needed to apply to the stable branch. If there were code changes for rebasing (ie: not only metadata diffs), please double check that the rebase was correctly done. Queued patches are on a temporary branch at: https://github.com/bluca/dpdk-stable This queued commit can be viewed at: https://github.com/bluca/dpdk-stable/commit/4a20f64e544bdefdca8332bc790aef591ac401e5 Thanks. Luca Boccassi --- >From 4a20f64e544bdefdca8332bc790aef591ac401e5 Mon Sep 17 00:00:00 2001 From: Maxime Coquelin Date: Mon, 19 Oct 2020 19:34:13 +0200 Subject: [PATCH] vhost: validate index in inflight API [ upstream commit d2475e890307a6edd9fdfcfc83b82d543881545e ] This patch validates the queue index parameter, in order to ensure neither out-of-bound accesses nor NULL pointer dereferencing happen. Fixes: 4d891f77ddfa ("vhost: add APIs to get inflight ring") Signed-off-by: Maxime Coquelin Reviewed-by: Chenbo Xia --- lib/librte_vhost/vhost.c | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/lib/librte_vhost/vhost.c b/lib/librte_vhost/vhost.c index 2e3dd0e0cf..9f3eadeba6 100644 --- a/lib/librte_vhost/vhost.c +++ b/lib/librte_vhost/vhost.c @@ -1505,15 +1505,23 @@ rte_vhost_get_vring_base_from_inflight(int vid, uint16_t *last_used_idx) { struct rte_vhost_inflight_info_packed *inflight_info; + struct vhost_virtqueue *vq; struct virtio_net *dev = get_device(vid); if (dev == NULL || last_avail_idx == NULL || last_used_idx == NULL) return -1; + if (queue_id >= VHOST_MAX_VRING) + return -1; + + vq = dev->virtqueue[queue_id]; + if (!vq) + return -1; + if (!vq_is_packed(dev)) return -1; - inflight_info = dev->virtqueue[queue_id]->inflight_packed; + inflight_info = vq->inflight_packed; if (!inflight_info) return -1; -- 2.27.0 --- Diff of the applied patch vs upstream commit (please double-check if non-empty: --- --- - 2020-11-09 18:40:12.914445641 +0000 +++ 0044-vhost-validate-index-in-inflight-API.patch 2020-11-09 18:40:11.167311842 +0000 @@ -1 +1 @@ -From d2475e890307a6edd9fdfcfc83b82d543881545e Mon Sep 17 00:00:00 2001 +From 4a20f64e544bdefdca8332bc790aef591ac401e5 Mon Sep 17 00:00:00 2001 @@ -5,0 +6,2 @@ +[ upstream commit d2475e890307a6edd9fdfcfc83b82d543881545e ] + @@ -11 +12,0 @@ -Cc: stable@dpdk.org @@ -20 +21 @@ -index b9afe46ca2..f78bdfcc94 100644 +index 2e3dd0e0cf..9f3eadeba6 100644 @@ -23 +24 @@ -@@ -1523,15 +1523,23 @@ rte_vhost_get_vring_base_from_inflight(int vid, +@@ -1505,15 +1505,23 @@ rte_vhost_get_vring_base_from_inflight(int vid,