- hw/virtio/virtio-crypto: Protect from DMA re-entrancy bugs(CVE-2024-3446) - hw/char/virtio-serial-bus: Protect from DMA re-entrancy bugs(CVE-2024-3446) - hw/display/virtio-gpu: Protect from DMA re-entrancy bugs(CVE-2024-3446) - hw/virtio: Introduce virtio_bh_new_guarded() helper - hw: replace most qemu_bh_new calls with qemu_bh_new_guarded - checkpatch: add qemu_bh_new/aio_bh_new checks - async: avoid use-after-free on re-entrancy guard - async: Add an optional reentrancy guard to the BH API - hw/sd/sdhci: Do not update TRNMOD when Command Inhibit (DAT) is set(CVE-2024-3447) - rtl8139: Remove unused variable - tulip: Remove unused variable - virtio-mem: Fix the bitmap index of the section offset - virtio-mem: Fix the iterator variable in a vmem->rdl_list loop - system/memory: use ldn_he_p/stn_he_p - block: Fix crash when loading snapshot on inactive node - smmu: Clear SMMUPciBus pointer cache when system reset - block/mirror: Fix NULL s->job in active writes - amd_iommu: Fix APIC address check - virtio-crypto: fix NULL pointer dereference in virtio_crypto_free_reques - libqos/virtio.c: Correct 'flags' reading in qvirtqueue_kick cherry-pick from 66e411885a23c96ff73742d06b793fec3ceaebb7 - ivshmem-test.c: enable test_ivshmem_server for ppc64 arch - ivshmem.c: change endianness to LITTLE_ENDIAN - hw/ppc/mac.h: Remove MAX_CPUS macro - configure: remove dead variables - virtio-gpu: do not byteswap padding - hw/intc: clean-up error reporting for failed ITS cmd - qemu-iotests: Discard stderr when probing devices - linux-user: un-parent OBJECT(cpu) when closing thread - hw/net/rocker: Avoid undefined shifts with more than 31 ports - contrib/vhost-user-blk: Clean up deallocation of VuVirtqElement - scsi-disk: fix overflow when block size is not a multiple of BDRV_SECTOR_SIZE Signed-off-by: Jiabo Feng <fengjiabo1@huawei.com> (cherry picked from commit bf54b48c2963c869dfdc89977c57be4bd9e772aa)
215 lines
8.0 KiB
Diff
215 lines
8.0 KiB
Diff
From 2a9e9bb0201c513a085d51cb1d7b2cc83cad1d3b Mon Sep 17 00:00:00 2001
|
|
From: Alexander Bulekov <alxndr@bu.edu>
|
|
Date: Thu, 27 Apr 2023 17:10:07 -0400
|
|
Subject: [PATCH] async: Add an optional reentrancy guard to the BH API
|
|
|
|
Devices can pass their MemoryReentrancyGuard (from their DeviceState),
|
|
when creating new BHes. Then, the async API will toggle the guard
|
|
before/after calling the BH call-back. This prevents bh->mmio reentrancy
|
|
issues.
|
|
|
|
Signed-off-by: Alexander Bulekov <alxndr@bu.edu>
|
|
Reviewed-by: Darren Kenny <darren.kenny@oracle.com>
|
|
Message-Id: <20230427211013.2994127-3-alxndr@bu.edu>
|
|
[thuth: Fix "line over 90 characters" checkpatch.pl error]
|
|
Signed-off-by: Thomas Huth <thuth@redhat.com>
|
|
Signed-off-by: liuxiangdong <liuxiangdong5@huawei.com>
|
|
---
|
|
docs/devel/multiple-iothreads.txt | 7 +++++++
|
|
include/block/aio.h | 18 ++++++++++++++++--
|
|
include/qemu/main-loop.h | 7 +++++--
|
|
tests/unit/ptimer-test-stubs.c | 3 ++-
|
|
util/async.c | 18 +++++++++++++++++-
|
|
util/main-loop.c | 6 ++++--
|
|
util/trace-events | 1 +
|
|
7 files changed, 52 insertions(+), 8 deletions(-)
|
|
|
|
diff --git a/docs/devel/multiple-iothreads.txt b/docs/devel/multiple-iothreads.txt
|
|
index aeb997bed5..a11576bc74 100644
|
|
--- a/docs/devel/multiple-iothreads.txt
|
|
+++ b/docs/devel/multiple-iothreads.txt
|
|
@@ -61,6 +61,7 @@ There are several old APIs that use the main loop AioContext:
|
|
* LEGACY qemu_aio_set_event_notifier() - monitor an event notifier
|
|
* LEGACY timer_new_ms() - create a timer
|
|
* LEGACY qemu_bh_new() - create a BH
|
|
+ * LEGACY qemu_bh_new_guarded() - create a BH with a device re-entrancy guard
|
|
* LEGACY qemu_aio_wait() - run an event loop iteration
|
|
|
|
Since they implicitly work on the main loop they cannot be used in code that
|
|
@@ -72,8 +73,14 @@ Instead, use the AioContext functions directly (see include/block/aio.h):
|
|
* aio_set_event_notifier() - monitor an event notifier
|
|
* aio_timer_new() - create a timer
|
|
* aio_bh_new() - create a BH
|
|
+ * aio_bh_new_guarded() - create a BH with a device re-entrancy guard
|
|
* aio_poll() - run an event loop iteration
|
|
|
|
+The qemu_bh_new_guarded/aio_bh_new_guarded APIs accept a "MemReentrancyGuard"
|
|
+argument, which is used to check for and prevent re-entrancy problems. For
|
|
+BHs associated with devices, the reentrancy-guard is contained in the
|
|
+corresponding DeviceState and named "mem_reentrancy_guard".
|
|
+
|
|
The AioContext can be obtained from the IOThread using
|
|
iothread_get_aio_context() or for the main loop using qemu_get_aio_context().
|
|
Code that takes an AioContext argument works both in IOThreads or the main
|
|
diff --git a/include/block/aio.h b/include/block/aio.h
|
|
index 47fbe9d81f..c7da152985 100644
|
|
--- a/include/block/aio.h
|
|
+++ b/include/block/aio.h
|
|
@@ -22,6 +22,8 @@
|
|
#include "qemu/event_notifier.h"
|
|
#include "qemu/thread.h"
|
|
#include "qemu/timer.h"
|
|
+#include "hw/qdev-core.h"
|
|
+
|
|
|
|
typedef struct BlockAIOCB BlockAIOCB;
|
|
typedef void BlockCompletionFunc(void *opaque, int ret);
|
|
@@ -321,9 +323,11 @@ void aio_bh_schedule_oneshot_full(AioContext *ctx, QEMUBHFunc *cb, void *opaque,
|
|
* is opaque and must be allocated prior to its use.
|
|
*
|
|
* @name: A human-readable identifier for debugging purposes.
|
|
+ * @reentrancy_guard: A guard set when entering a cb to prevent
|
|
+ * device-reentrancy issues
|
|
*/
|
|
QEMUBH *aio_bh_new_full(AioContext *ctx, QEMUBHFunc *cb, void *opaque,
|
|
- const char *name);
|
|
+ const char *name, MemReentrancyGuard *reentrancy_guard);
|
|
|
|
/**
|
|
* aio_bh_new: Allocate a new bottom half structure
|
|
@@ -332,7 +336,17 @@ QEMUBH *aio_bh_new_full(AioContext *ctx, QEMUBHFunc *cb, void *opaque,
|
|
* string.
|
|
*/
|
|
#define aio_bh_new(ctx, cb, opaque) \
|
|
- aio_bh_new_full((ctx), (cb), (opaque), (stringify(cb)))
|
|
+ aio_bh_new_full((ctx), (cb), (opaque), (stringify(cb)), NULL)
|
|
+
|
|
+/**
|
|
+ * aio_bh_new_guarded: Allocate a new bottom half structure with a
|
|
+ * reentrancy_guard
|
|
+ *
|
|
+ * A convenience wrapper for aio_bh_new_full() that uses the cb as the name
|
|
+ * string.
|
|
+ */
|
|
+#define aio_bh_new_guarded(ctx, cb, opaque, guard) \
|
|
+ aio_bh_new_full((ctx), (cb), (opaque), (stringify(cb)), guard)
|
|
|
|
/**
|
|
* aio_notify: Force processing of pending events.
|
|
diff --git a/include/qemu/main-loop.h b/include/qemu/main-loop.h
|
|
index 8dbc6fcb89..85dd5ada9e 100644
|
|
--- a/include/qemu/main-loop.h
|
|
+++ b/include/qemu/main-loop.h
|
|
@@ -294,9 +294,12 @@ void qemu_cond_timedwait_iothread(QemuCond *cond, int ms);
|
|
|
|
void qemu_fd_register(int fd);
|
|
|
|
+#define qemu_bh_new_guarded(cb, opaque, guard) \
|
|
+ qemu_bh_new_full((cb), (opaque), (stringify(cb)), guard)
|
|
#define qemu_bh_new(cb, opaque) \
|
|
- qemu_bh_new_full((cb), (opaque), (stringify(cb)))
|
|
-QEMUBH *qemu_bh_new_full(QEMUBHFunc *cb, void *opaque, const char *name);
|
|
+ qemu_bh_new_full((cb), (opaque), (stringify(cb)), NULL)
|
|
+QEMUBH *qemu_bh_new_full(QEMUBHFunc *cb, void *opaque, const char *name,
|
|
+ MemReentrancyGuard *reentrancy_guard);
|
|
void qemu_bh_schedule_idle(QEMUBH *bh);
|
|
|
|
enum {
|
|
diff --git a/tests/unit/ptimer-test-stubs.c b/tests/unit/ptimer-test-stubs.c
|
|
index 2a3ef58799..a7a2d08e7e 100644
|
|
--- a/tests/unit/ptimer-test-stubs.c
|
|
+++ b/tests/unit/ptimer-test-stubs.c
|
|
@@ -108,7 +108,8 @@ int64_t qemu_clock_deadline_ns_all(QEMUClockType type, int attr_mask)
|
|
return deadline;
|
|
}
|
|
|
|
-QEMUBH *qemu_bh_new_full(QEMUBHFunc *cb, void *opaque, const char *name)
|
|
+QEMUBH *qemu_bh_new_full(QEMUBHFunc *cb, void *opaque, const char *name,
|
|
+ MemReentrancyGuard *reentrancy_guard)
|
|
{
|
|
QEMUBH *bh = g_new(QEMUBH, 1);
|
|
|
|
diff --git a/util/async.c b/util/async.c
|
|
index 6f6717a34b..3eb6b50163 100644
|
|
--- a/util/async.c
|
|
+++ b/util/async.c
|
|
@@ -62,6 +62,7 @@ struct QEMUBH {
|
|
void *opaque;
|
|
QSLIST_ENTRY(QEMUBH) next;
|
|
unsigned flags;
|
|
+ MemReentrancyGuard *reentrancy_guard;
|
|
};
|
|
|
|
/* Called concurrently from any thread */
|
|
@@ -123,7 +124,7 @@ void aio_bh_schedule_oneshot_full(AioContext *ctx, QEMUBHFunc *cb,
|
|
}
|
|
|
|
QEMUBH *aio_bh_new_full(AioContext *ctx, QEMUBHFunc *cb, void *opaque,
|
|
- const char *name)
|
|
+ const char *name, MemReentrancyGuard *reentrancy_guard)
|
|
{
|
|
QEMUBH *bh;
|
|
bh = g_new(QEMUBH, 1);
|
|
@@ -132,13 +133,28 @@ QEMUBH *aio_bh_new_full(AioContext *ctx, QEMUBHFunc *cb, void *opaque,
|
|
.cb = cb,
|
|
.opaque = opaque,
|
|
.name = name,
|
|
+ .reentrancy_guard = reentrancy_guard,
|
|
};
|
|
return bh;
|
|
}
|
|
|
|
void aio_bh_call(QEMUBH *bh)
|
|
{
|
|
+ bool last_engaged_in_io = false;
|
|
+
|
|
+ if (bh->reentrancy_guard) {
|
|
+ last_engaged_in_io = bh->reentrancy_guard->engaged_in_io;
|
|
+ if (bh->reentrancy_guard->engaged_in_io) {
|
|
+ trace_reentrant_aio(bh->ctx, bh->name);
|
|
+ }
|
|
+ bh->reentrancy_guard->engaged_in_io = true;
|
|
+ }
|
|
+
|
|
bh->cb(bh->opaque);
|
|
+
|
|
+ if (bh->reentrancy_guard) {
|
|
+ bh->reentrancy_guard->engaged_in_io = last_engaged_in_io;
|
|
+ }
|
|
}
|
|
|
|
/* Multiple occurrences of aio_bh_poll cannot be called concurrently. */
|
|
diff --git a/util/main-loop.c b/util/main-loop.c
|
|
index 06b18b195c..1eacf04691 100644
|
|
--- a/util/main-loop.c
|
|
+++ b/util/main-loop.c
|
|
@@ -544,9 +544,11 @@ void main_loop_wait(int nonblocking)
|
|
|
|
/* Functions to operate on the main QEMU AioContext. */
|
|
|
|
-QEMUBH *qemu_bh_new_full(QEMUBHFunc *cb, void *opaque, const char *name)
|
|
+QEMUBH *qemu_bh_new_full(QEMUBHFunc *cb, void *opaque, const char *name,
|
|
+ MemReentrancyGuard *reentrancy_guard)
|
|
{
|
|
- return aio_bh_new_full(qemu_aio_context, cb, opaque, name);
|
|
+ return aio_bh_new_full(qemu_aio_context, cb, opaque, name,
|
|
+ reentrancy_guard);
|
|
}
|
|
|
|
/*
|
|
diff --git a/util/trace-events b/util/trace-events
|
|
index c8f53d7d9f..dc3b1eb3bf 100644
|
|
--- a/util/trace-events
|
|
+++ b/util/trace-events
|
|
@@ -11,6 +11,7 @@ poll_remove(void *ctx, void *node, int fd) "ctx %p node %p fd %d"
|
|
# async.c
|
|
aio_co_schedule(void *ctx, void *co) "ctx %p co %p"
|
|
aio_co_schedule_bh_cb(void *ctx, void *co) "ctx %p co %p"
|
|
+reentrant_aio(void *ctx, const char *name) "ctx %p name %s"
|
|
|
|
# thread-pool.c
|
|
thread_pool_submit(void *pool, void *req, void *opaque) "pool %p req %p opaque %p"
|
|
--
|
|
2.27.0
|
|
|