All Virtuozzo development lists (kernel + QEMU)
 help / color / mirror / Atom feed
* [PATCH hci-8.1 0/6] io/channel-websock: fix an unauthenticated crash in the handshake #VSTOR-143316
@ 2026-08-31 14:06 Denis V. Lunev
  2026-08-31 14:06 ` [PATCH hci-8.1 1/6] io/channel-socket: do not treat a zero length write as an error #VSTOR-143316 Denis V. Lunev
                   ` (5 more replies)
  0 siblings, 6 replies; 7+ messages in thread
From: Denis V. Lunev @ 2026-08-31 14:06 UTC (permalink / raw)
  To: svt-core; +Cc: andrey.drobyshev, den

Backport of the upstream series fixing an unauthenticated crash in the
VNC websocket handshake. A client which can reach a websocket port
crashes QEMU before it has authenticated, by sending an HTTP greeting
whose request line holds no space:

  printf 'stats\r\nx\r\n\r\n' | nc $host $port

Three defects line up to produce it. The greeting is rejected without
queueing a response, so the handshake goes on to flush an empty buffer.
A zero length sendmsg() succeeds and returns 0, which
qio_channel_socket_writev() mistakes for failure and reports as
QIO_CHANNEL_ERR_BLOCK with errp left unset. The handshake treats every
negative return as fatal and hands that NULL Error to
error_get_pretty(). Patches 1 to 3 close the three links.

Patch 5 is the same NULL Error on the read side of the handshake, where
ERR_BLOCK is folded into -1. It is reachable for a wss:// client, whose
master channel is then a TLS channel: a wakeup carrying only part of a
record makes gnutls report EAGAIN.

The series applies to the branch unchanged, and the new unit test passes
on it.

Upstream posting, reviewed by the graphics maintainer:
https://lore.kernel.org/qemu-devel/20260831100151.914178-1-den@openvz.org/

Signed-off-by: Denis V. Lunev <den@openvz.org>

Denis V. Lunev (6):
  io/channel-socket: do not treat a zero length write as an error
    #VSTOR-143316
  io/channel-websock: send an HTTP 400 when the greeting has no space
    #VSTOR-143316
  io/channel-websock: handle a blocked write during the handshake
    #VSTOR-143316
  tests/unit: add websock handshake test #VSTOR-143316
  io/channel-websock: do not lose QIO_CHANNEL_ERR_BLOCK while reading
    #VSTOR-143316
  tests/unit: cover blocked IO during the websock handshake
    #VSTOR-143316

 io/channel-socket.c                  |   2 +-
 io/channel-websock.c                 |  10 +-
 tests/unit/meson.build               |   1 +
 tests/unit/test-io-channel-websock.c | 249 +++++++++++++++++++++++++++
 4 files changed, 260 insertions(+), 2 deletions(-)
 create mode 100644 tests/unit/test-io-channel-websock.c

-- 
2.53.0


^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2026-08-31 14:07 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-31 14:06 [PATCH hci-8.1 0/6] io/channel-websock: fix an unauthenticated crash in the handshake #VSTOR-143316 Denis V. Lunev
2026-08-31 14:06 ` [PATCH hci-8.1 1/6] io/channel-socket: do not treat a zero length write as an error #VSTOR-143316 Denis V. Lunev
2026-08-31 14:06 ` [PATCH hci-8.1 2/6] io/channel-websock: send an HTTP 400 when the greeting has no space #VSTOR-143316 Denis V. Lunev
2026-08-31 14:06 ` [PATCH hci-8.1 3/6] io/channel-websock: handle a blocked write during the handshake #VSTOR-143316 Denis V. Lunev
2026-08-31 14:06 ` [PATCH hci-8.1 4/6] tests/unit: add websock handshake test #VSTOR-143316 Denis V. Lunev
2026-08-31 14:06 ` [PATCH hci-8.1 5/6] io/channel-websock: do not lose QIO_CHANNEL_ERR_BLOCK while reading #VSTOR-143316 Denis V. Lunev
2026-08-31 14:06 ` [PATCH hci-8.1 6/6] tests/unit: cover blocked IO during the websock handshake #VSTOR-143316 Denis V. Lunev

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.