From patchwork Wed Apr 10 09:13:10 2024 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: =?utf-8?q?Philippe_Mathieu-Daud=C3=A9?= X-Patchwork-Id: 787495 Delivered-To: patch@linaro.org Received: by 2002:adf:fdd2:0:b0:346:15ad:a2a with SMTP id i18csp598309wrs; Wed, 10 Apr 2024 02:16:00 -0700 (PDT) X-Forwarded-Encrypted: i=2; AJvYcCXw8pGerPKC6j9s59oLflzVH68wD4ksM/cbtQ3XyMaAOcaqjsA4wHOaG+zywSTFSYq6Y1EFtpSDwjIvv5k1yBcY X-Google-Smtp-Source: AGHT+IEnfcSEQd4y0dnzvWOefOo0lMk9WKgJXhq4+agTQaOYR/av6yY7a399vT7O4dRPHlMRppoo X-Received: by 2002:a05:6214:d04:b0:69b:3585:e48a with SMTP id 4-20020a0562140d0400b0069b3585e48amr2102042qvh.7.1712740560548; Wed, 10 Apr 2024 02:16:00 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1712740560; cv=none; d=google.com; s=arc-20160816; b=oeUdxqCrjac3z+IjBtxfBfjFVZXvDEPjv0OBICgtKVF488QoqEcKMql+tTuW21AUVB kV4PDMkUX53q9UXGOMBicC5Z6sgWWl+LLLrKeor0aVEtD5+mLl+Y/N9n/YBBhk20zU2o wgXp34+zm+sBgOei9ETGihwFoQQUinKbe5kETb2dGzTpjgY8QspeKE2LwymWfIdqzwUw k7O8t1r2vX2Z4PQk1yTZwL81uvSlJZXz0plInDi0/ylFB9AsLs+DZs42x91YBP51ZdI5 c6k60/GCqTGfRZpv3/GiKdEyCFmQKUR/ZHF/LjjNI7FJCGIW8DPETsxPU2AUC2NI6Doe GXJw== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=sender:errors-to:list-subscribe:list-help:list-post:list-archive :list-unsubscribe:list-id:precedence:content-transfer-encoding :mime-version:references:in-reply-to:message-id:date:subject:cc:to :from:dkim-signature; bh=JTSWrkOypAhA6kMD+44qfKpFKP2exY3ZyHzORb0u98w=; fh=QLEGUdZzd2sMiFkBOoPsRdmSUq/T+vLj0CXvNLo4st0=; b=YYZxskuDmvuPGKFfTaz9+NR32HHHHFfIzv7vC+cQGMQZHOkaKft0Q3hPZK1/q0m2Hk FoD5JrA3iAjBVT81ihuUp2iF45K0UiwvsQCfy6bpEBWDIr4uvZe9M6H7tO3/R6mo5n8j PO8AcHb6DfLfyYjwiQ+tZf6ZPMTrGHFm9pvu50ULmZHq4Br/uRkLyngAw0HVy/Q6g0bk fFyTzRU9ByeA6TIlloE5tC4Jy7Wpf50dIVgIEG6VBFPLahykV5DG5VE7dGJO6hBEDfyL ythMh9uYi0ZI3e4TygwvuQaULXIMYQvibc7HDwkUbmnlDbIUrHa+mXjal0TSfQccskMk YxFA==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@linaro.org header.s=google header.b=oXsZY55L; spf=pass (google.com: domain of qemu-devel-bounces+patch=linaro.org@nongnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom="qemu-devel-bounces+patch=linaro.org@nongnu.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linaro.org Return-Path: Received: from lists.gnu.org (lists.gnu.org. [209.51.188.17]) by mx.google.com with ESMTPS id op26-20020a056214459a00b0069b32626e59si2872561qvb.54.2024.04.10.02.16.00 for (version=TLS1_2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305 bits=256/256); Wed, 10 Apr 2024 02:16:00 -0700 (PDT) Received-SPF: pass (google.com: domain of qemu-devel-bounces+patch=linaro.org@nongnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; Authentication-Results: mx.google.com; dkim=pass header.i=@linaro.org header.s=google header.b=oXsZY55L; spf=pass (google.com: domain of qemu-devel-bounces+patch=linaro.org@nongnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom="qemu-devel-bounces+patch=linaro.org@nongnu.org"; dmarc=pass (p=NONE sp=NONE dis=NONE) header.from=linaro.org Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1ruU2L-00066K-J2; Wed, 10 Apr 2024 05:14:33 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1ruU2H-000643-Tv for qemu-devel@nongnu.org; Wed, 10 Apr 2024 05:14:30 -0400 Received: from mail-ed1-x536.google.com ([2a00:1450:4864:20::536]) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1ruU2G-0005eV-9h for qemu-devel@nongnu.org; Wed, 10 Apr 2024 05:14:29 -0400 Received: by mail-ed1-x536.google.com with SMTP id 4fb4d7f45d1cf-56e6affdd21so749440a12.3 for ; Wed, 10 Apr 2024 02:14:27 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linaro.org; s=google; t=1712740466; x=1713345266; darn=nongnu.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=JTSWrkOypAhA6kMD+44qfKpFKP2exY3ZyHzORb0u98w=; b=oXsZY55LCsZxH50L8PiOssMIUl8C8XunUgnAZja1vejZbJ4HX2JtZxUJ8MDHCP1Wi/ lF8B5vge1Dx9kNpKO0N95IkuOdgdPggTBk2x36P7j5Nw127BfWFsR4UbKh5nFdyEh8Yk mq4IroeuCeFxrUzOUPDsIgHrCiQSysygaclqv8dFgySDrv2jXP+uUUtHWd+9AKr/Jy3j 4lQa7Lu9puLnA27zKwqCsx60QPUDDzo/Xi6qJH5X0ZGNfl2eCJ01WjtvMJcYwmyspEf4 /EqnRVcvr0lG/3dpSbtIUJ8t6y0obB2QjewT2So8ZO0k92tbHl583nMVnsrLrOk12nux 70bA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1712740466; x=1713345266; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=JTSWrkOypAhA6kMD+44qfKpFKP2exY3ZyHzORb0u98w=; b=kfvP7QLihbQwXCEGnAbOACADVzYb8VEfaPrEFhGpZ0T+cao75ZBIcPj2K7vk0ihRnK /gZWT7dvuncLVz/afBGqieq7qjJZ9yxuSU+hpLhgWeJ6M4OwzY9bc3dbjZcInsZSoKkJ xUec4wTuqwLDW7n4iZ53WYckzapcW8eF3R3Airr/l1jZIaUeFViacycGMmXgOYR+XW6E /Jk8bo5BRj6Ue+SR7XFN/wKHWbpGm09vbQ2hy/xKHZznL7QRiF+/IHuX4gre8fWLWLzm j6p9g6z+IZnrXkexqvZZ40PZ94VVmaFqeuIzEVEnzlq70fb4oAXZx81zuPCGAiNevm84 dv+Q== X-Gm-Message-State: AOJu0YwkuwP9x1ATK4hBEgJSYaJRVrY+t1KFS98a6+lu96HonVTVgQ4k X79abhI4qlCrB9S/tpTjpDxfOSwveYRp51poxjZiq+Ld7P6KX6SCsjgFWnTcW/Bh+9eOshIl9Pc 0 X-Received: by 2002:a50:ccdb:0:b0:56e:64b:8733 with SMTP id b27-20020a50ccdb000000b0056e064b8733mr1416801edj.40.1712740466408; Wed, 10 Apr 2024 02:14:26 -0700 (PDT) Received: from m1x-phil.lan (arl95-h02-176-184-34-173.dsl.sta.abo.bbox.fr. [176.184.34.173]) by smtp.gmail.com with ESMTPSA id cq9-20020a056402220900b0056e3418cd4asm5786842edb.20.2024.04.10.02.14.24 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Wed, 10 Apr 2024 02:14:26 -0700 (PDT) From: =?utf-8?q?Philippe_Mathieu-Daud=C3=A9?= To: qemu-devel@nongnu.org Cc: =?utf-8?q?Philippe_Mathieu-Daud=C3=A9?= , qemu-stable@nongnu.org, Zheyu Ma , zhenwei pi , "Gonglei (Arei)" Subject: [PULL 11/16] backends/cryptodev: Do not abort for invalid session ID Date: Wed, 10 Apr 2024 11:13:10 +0200 Message-ID: <20240410091315.57241-12-philmd@linaro.org> X-Mailer: git-send-email 2.41.0 In-Reply-To: <20240410091315.57241-1-philmd@linaro.org> References: <20240410091315.57241-1-philmd@linaro.org> MIME-Version: 1.0 Received-SPF: pass client-ip=2a00:1450:4864:20::536; envelope-from=philmd@linaro.org; helo=mail-ed1-x536.google.com X-Spam_score_int: -20 X-Spam_score: -2.1 X-Spam_bar: -- X-Spam_report: (-2.1 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+patch=linaro.org@nongnu.org Sender: qemu-devel-bounces+patch=linaro.org@nongnu.org Instead of aborting when a session ID is invalid, return VIRTIO_CRYPTO_INVSESS ("Invalid session id"). Reproduced using: $ cat << EOF | qemu-system-i386 -display none \ -machine q35,accel=qtest -m 512M -nodefaults \ -object cryptodev-backend-builtin,id=cryptodev0 \ -device virtio-crypto-pci,id=crypto0,cryptodev=cryptodev0 \ -qtest stdio outl 0xcf8 0x80000804 outw 0xcfc 0x06 outl 0xcf8 0x80000820 outl 0xcfc 0xe0008000 write 0x10800e 0x1 0x01 write 0xe0008016 0x1 0x01 write 0xe0008020 0x4 0x00801000 write 0xe0008028 0x4 0x00c01000 write 0xe000801c 0x1 0x01 write 0x110000 0x1 0x05 write 0x110001 0x1 0x04 write 0x108002 0x1 0x11 write 0x108008 0x1 0x48 write 0x10800c 0x1 0x01 write 0x108018 0x1 0x10 write 0x10801c 0x1 0x02 write 0x10c002 0x1 0x01 write 0xe000b005 0x1 0x00 EOF Assertion failed: (session_id < MAX_NUM_SESSIONS && builtin->sessions[session_id]), function cryptodev_builtin_close_session, file cryptodev-builtin.c, line 430. Cc: qemu-stable@nongnu.org Reported-by: Zheyu Ma Resolves: https://gitlab.com/qemu-project/qemu/-/issues/2274 Signed-off-by: Philippe Mathieu-Daudé Reviewed-by: zhenwei pi Message-Id: <20240409094757.9127-1-philmd@linaro.org> --- backends/cryptodev-builtin.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/backends/cryptodev-builtin.c b/backends/cryptodev-builtin.c index 39d0455280..a514bbb310 100644 --- a/backends/cryptodev-builtin.c +++ b/backends/cryptodev-builtin.c @@ -427,7 +427,9 @@ static int cryptodev_builtin_close_session( CRYPTODEV_BACKEND_BUILTIN(backend); CryptoDevBackendBuiltinSession *session; - assert(session_id < MAX_NUM_SESSIONS && builtin->sessions[session_id]); + if (session_id >= MAX_NUM_SESSIONS || !builtin->sessions[session_id]) { + return -VIRTIO_CRYPTO_INVSESS; + } session = builtin->sessions[session_id]; if (session->cipher) {