diff mbox

[uq/master] kvmvapic: Disable if there is insufficient memory

Message ID 502A32BB.2000607@siemens.com
State New
Headers show

Commit Message

Jan Kiszka Aug. 14, 2012, 11:12 a.m. UTC
We need at least 1M of RAM to map the option ROM. Otherwise, we will
corrupt host memory or even crash.

Reported-by: Markus Armbruster <armbru@redhat.com>
Signed-off-by: Jan Kiszka <jan.kiszka@siemens.com>
---
 hw/apic_common.c |    4 +++-
 1 files changed, 3 insertions(+), 1 deletions(-)

Comments

Markus Armbruster Aug. 14, 2012, 11:40 a.m. UTC | #1
Jan Kiszka <jan.kiszka@siemens.com> writes:

> We need at least 1M of RAM to map the option ROM. Otherwise, we will
> corrupt host memory or even crash.

Let's put a reproducer in the commit message, if it's not too much
trouble.  Here's mine:

    $ qemu-system-x86_64 -nodefaults --enable-kvm -vnc :0 -m 640k
    Segmentation fault (core dumped)

> Reported-by: Markus Armbruster <armbru@redhat.com>
> Signed-off-by: Jan Kiszka <jan.kiszka@siemens.com>

Tested-by: Markus Armbruster <armbru@redhat.com>
diff mbox

Patch

diff --git a/hw/apic_common.c b/hw/apic_common.c
index 58e63b0..371f95d 100644
--- a/hw/apic_common.c
+++ b/hw/apic_common.c
@@ -299,7 +299,9 @@  static int apic_init_common(SysBusDevice *dev)
 
     sysbus_init_mmio(dev, &s->io_memory);
 
-    if (!vapic && s->vapic_control & VAPIC_ENABLE_MASK) {
+    /* Note: We need at least 1M to map the VAPIC option ROM */
+    if (!vapic && s->vapic_control & VAPIC_ENABLE_MASK &&
+        ram_size >= 1024 * 1024) {
         vapic = sysbus_create_simple("kvmvapic", -1, NULL);
     }
     s->vapic = vapic;