Re: [PATCH] hw/usb/hcd-xhci: Turn guest-triggerable abort() into qemu_log_mask()
Thomas Huth <[email protected]> Fri, 10 Jul 2026 16:40:36 +0200
| Newsgroups | org.nongnu.qemu-trivial,org.nongnu.qemu-devel |
|---|---|
| Message-ID | <[email protected]> |
On 10/07/2026 16.36, Philippe Mathieu-Daudé wrote: > On 10/7/26 16:27, Thomas Huth wrote: >> From: Thomas Huth <[email protected]> >> >> The FIXME macros in xhci_alloc_device_streams() can be triggered >> by a (malicious) guest. Since the macro also contains an abort() >> statement, this terminates QEMU. Turn the FIXME statements into >> a qemu_log_mask() instead to avoid that a guest can shoot itself >> this way. >> >> Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3784 >> Signed-off-by: Thomas Huth <[email protected]> >> --- >> hw/usb/hcd-xhci.c | 6 ++++-- >> 1 file changed, 4 insertions(+), 2 deletions(-) >> >> diff --git a/hw/usb/hcd-xhci.c b/hw/usb/hcd-xhci.c >> index 2cdab3ba0e4..9ff50d0b7f9 100644 >> --- a/hw/usb/hcd-xhci.c >> +++ b/hw/usb/hcd-xhci.c >> @@ -965,11 +965,13 @@ static TRBCCode xhci_alloc_device_streams(XHCIState >> *xhci, unsigned int slotid, >> * together and make an usb_device_alloc_streams call per group. >> */ >> if (epctxs[i]->nr_pstreams != req_nr_streams) { >> - FIXME("guest streams config not identical for all eps"); >> + qemu_log_mask(LOG_GUEST_ERROR, >> + "guest streams config not identical for all eps"); > > With trailing \n: D'oh! Thanks! I just noticed that I also forgot to add a "Reported-by" line to the description. I'll send a v2... > Reviewed-by: Philippe Mathieu-Daudé <[email protected]> Thanks! Thomas