vhost-scsi: prevent using uninitialized vqs

Message ID 20181012090752.31891-1-yuchenlin@synology.com
State New
Headers show
Series
  • vhost-scsi: prevent using uninitialized vqs
Related show

Commit Message

yuchenlin--- via Qemu-devel Oct. 12, 2018, 9:07 a.m.
From: yuchenlin <yuchenlin@synology.com>

There are 3 virtqueues (ctrl, event and cmd) for virtio scsi device,
but seabios will only set the physical address for the 3rd one (cmd).
Then in vhost_virtqueue_start(), virtio_queue_get_desc_addr()
will be 0 for ctrl and event vq.

In this case, ctrl and event vq are not initialized.
vhost_verify_ring_mappings may use uninitialized vhost_virtqueue
such that vhost_verify_ring_part_mapping returns ENOMEM.

When encountered this problem, we got the following logs:

    qemu-system-x86_64: Unable to map available ring for ring 0
    qemu-system-x86_64: Verify ring failure on region 0

Signed-off-by: Forrest Liu <forrestl@synology.com>
Signed-off-by: yuchenlin <yuchenlin@synology.com>
---
 hw/scsi/vhost-scsi.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Comments

yuchenlin--- via Qemu-devel Oct. 22, 2018, 2:17 a.m. | #1
Ping?

On 2018-10-12 17:07, yuchenlin@synology.com wrote:
> From: yuchenlin <yuchenlin@synology.com>
> 
> There are 3 virtqueues (ctrl, event and cmd) for virtio scsi device,
> but seabios will only set the physical address for the 3rd one (cmd).
> Then in vhost_virtqueue_start(), virtio_queue_get_desc_addr()
> will be 0 for ctrl and event vq.
> 
> In this case, ctrl and event vq are not initialized.
> vhost_verify_ring_mappings may use uninitialized vhost_virtqueue
> such that vhost_verify_ring_part_mapping returns ENOMEM.
> 
> When encountered this problem, we got the following logs:
> 
>     qemu-system-x86_64: Unable to map available ring for ring 0
>     qemu-system-x86_64: Verify ring failure on region 0
> 
> Signed-off-by: Forrest Liu <forrestl@synology.com>
> Signed-off-by: yuchenlin <yuchenlin@synology.com>
> ---
>  hw/scsi/vhost-scsi.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/hw/scsi/vhost-scsi.c b/hw/scsi/vhost-scsi.c
> index becf550085..7f21b4f9d6 100644
> --- a/hw/scsi/vhost-scsi.c
> +++ b/hw/scsi/vhost-scsi.c
> @@ -183,7 +183,7 @@ static void vhost_scsi_realize(DeviceState *dev,
> Error **errp)
>      }
> 
>      vsc->dev.nvqs = VHOST_SCSI_VQ_NUM_FIXED + vs->conf.num_queues;
> -    vsc->dev.vqs = g_new(struct vhost_virtqueue, vsc->dev.nvqs);
> +    vsc->dev.vqs = g_new0(struct vhost_virtqueue, vsc->dev.nvqs);
>      vsc->dev.vq_index = 0;
>      vsc->dev.backend_features = 0;
Philippe Mathieu-Daudé Oct. 22, 2018, 11:49 p.m. | #2
On 22/10/18 4:17, yuchenlin via Qemu-devel wrote:
> Ping?
> 
> On 2018-10-12 17:07, yuchenlin@synology.com wrote:
>> From: yuchenlin <yuchenlin@synology.com>
>>
>> There are 3 virtqueues (ctrl, event and cmd) for virtio scsi device,
>> but seabios will only set the physical address for the 3rd one (cmd).
>> Then in vhost_virtqueue_start(), virtio_queue_get_desc_addr()
>> will be 0 for ctrl and event vq.
>>
>> In this case, ctrl and event vq are not initialized.
>> vhost_verify_ring_mappings may use uninitialized vhost_virtqueue
>> such that vhost_verify_ring_part_mapping returns ENOMEM.
>>
>> When encountered this problem, we got the following logs:
>>
>>     qemu-system-x86_64: Unable to map available ring for ring 0
>>     qemu-system-x86_64: Verify ring failure on region 0
>>
>> Signed-off-by: Forrest Liu <forrestl@synology.com>
>> Signed-off-by: yuchenlin <yuchenlin@synology.com>

Reviewed-by: Philippe Mathieu-Daudé <philmd@redhat.com>

>> ---
>>  hw/scsi/vhost-scsi.c | 2 +-
>>  1 file changed, 1 insertion(+), 1 deletion(-)
>>
>> diff --git a/hw/scsi/vhost-scsi.c b/hw/scsi/vhost-scsi.c
>> index becf550085..7f21b4f9d6 100644
>> --- a/hw/scsi/vhost-scsi.c
>> +++ b/hw/scsi/vhost-scsi.c
>> @@ -183,7 +183,7 @@ static void vhost_scsi_realize(DeviceState *dev,
>> Error **errp)
>>      }
>>
>>      vsc->dev.nvqs = VHOST_SCSI_VQ_NUM_FIXED + vs->conf.num_queues;
>> -    vsc->dev.vqs = g_new(struct vhost_virtqueue, vsc->dev.nvqs);
>> +    vsc->dev.vqs = g_new0(struct vhost_virtqueue, vsc->dev.nvqs);
>>      vsc->dev.vq_index = 0;
>>      vsc->dev.backend_features = 0;
> 
>
Michael S. Tsirkin Oct. 23, 2018, 12:56 p.m. | #3
On Tue, Oct 23, 2018 at 01:49:16AM +0200, Philippe Mathieu-Daudé wrote:
> On 22/10/18 4:17, yuchenlin via Qemu-devel wrote:
> > Ping?
> > 
> > On 2018-10-12 17:07, yuchenlin@synology.com wrote:
> > > From: yuchenlin <yuchenlin@synology.com>
> > > 
> > > There are 3 virtqueues (ctrl, event and cmd) for virtio scsi device,
> > > but seabios will only set the physical address for the 3rd one (cmd).
> > > Then in vhost_virtqueue_start(), virtio_queue_get_desc_addr()
> > > will be 0 for ctrl and event vq.
> > > 
> > > In this case, ctrl and event vq are not initialized.
> > > vhost_verify_ring_mappings may use uninitialized vhost_virtqueue
> > > such that vhost_verify_ring_part_mapping returns ENOMEM.
> > > 
> > > When encountered this problem, we got the following logs:
> > > 
> > >     qemu-system-x86_64: Unable to map available ring for ring 0
> > >     qemu-system-x86_64: Verify ring failure on region 0
> > > 
> > > Signed-off-by: Forrest Liu <forrestl@synology.com>
> > > Signed-off-by: yuchenlin <yuchenlin@synology.com>
> 
> Reviewed-by: Philippe Mathieu-Daudé <philmd@redhat.com>

Thanks I will queue this.

> > > ---
> > >  hw/scsi/vhost-scsi.c | 2 +-
> > >  1 file changed, 1 insertion(+), 1 deletion(-)
> > > 
> > > diff --git a/hw/scsi/vhost-scsi.c b/hw/scsi/vhost-scsi.c
> > > index becf550085..7f21b4f9d6 100644
> > > --- a/hw/scsi/vhost-scsi.c
> > > +++ b/hw/scsi/vhost-scsi.c
> > > @@ -183,7 +183,7 @@ static void vhost_scsi_realize(DeviceState *dev,
> > > Error **errp)
> > >      }
> > > 
> > >      vsc->dev.nvqs = VHOST_SCSI_VQ_NUM_FIXED + vs->conf.num_queues;
> > > -    vsc->dev.vqs = g_new(struct vhost_virtqueue, vsc->dev.nvqs);
> > > +    vsc->dev.vqs = g_new0(struct vhost_virtqueue, vsc->dev.nvqs);
> > >      vsc->dev.vq_index = 0;
> > >      vsc->dev.backend_features = 0;
> > 
> >

Patch

diff --git a/hw/scsi/vhost-scsi.c b/hw/scsi/vhost-scsi.c
index becf550085..7f21b4f9d6 100644
--- a/hw/scsi/vhost-scsi.c
+++ b/hw/scsi/vhost-scsi.c
@@ -183,7 +183,7 @@  static void vhost_scsi_realize(DeviceState *dev, Error **errp)
     }
 
     vsc->dev.nvqs = VHOST_SCSI_VQ_NUM_FIXED + vs->conf.num_queues;
-    vsc->dev.vqs = g_new(struct vhost_virtqueue, vsc->dev.nvqs);
+    vsc->dev.vqs = g_new0(struct vhost_virtqueue, vsc->dev.nvqs);
     vsc->dev.vq_index = 0;
     vsc->dev.backend_features = 0;