From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from DUZPR83CU001.outbound.protection.outlook.com (mail-northeuropeazon11022073.outbound.protection.outlook.com [52.101.66.73]) by lore.virtuozzo.com (Postfix) with ESMTPS id 4BBCA80266 for ; Fri, 4 Sep 2026 09:33:52 +0000 (UTC) ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=NOZ5SStuE4E4ttucPu+qYsMCTrUoTYllu0VKw7mCvz7VnyWxbgHpAOaMoUkKHckH53c0j6OQk71yzjS9H1x7yNReVFUbqMquVYkd2pghuR9QskwDAuGQlCyN1km3W048blp49lwmn6DwWykGiVxBoW3/lXnzIdiWfJKwAZ92eUnGXs2Eag7bxevaM94AomZtqg8+1ajNeiMgMMqQdaC6VCO0t0FpZLSOyupQuCQCvVqQ8DZhb6hl78tpE1E3Kaugac3nFimCvP0Y6oz61ASsMCFqsYuoP245lCiShpTo3zhPIpBEd4U5ToxigGotteM5FtgTleBeUqbIWyVvA6pF/w== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=ahXtf9RVz1HTWJ2z6fm/jD66GjUgvsUTADpSUKiiYfM=; b=Mnb4glhf3wHLV3l+5ZUFv7T3L+RA4T13eSfRaZwYyHnMof6QFP9VKYojExwZZONYFwH1yZf0M85VgTSF/3QfoO74VlEQcxa6GIZMDBG+KJa+eWo0bHzS+Ky0XHEDE/QG/j+7A3MdTS2aNwriW7AbEDavaVY0j76hbRXNZsfsx2zD2E5jbLHtPEShEPjSpexiLbgdJj2ePPydZaGyb73wODZNXQt1/WTteoyaFbNG+bJHtMK94em5cG0yMsSlzcdx24vwuig7RJDmxO/j1AKlMOm2hpMoBrJ+lw9uVvUtsr8gRr5oMmDTuah+Oxngt4LTYbiZN2CVZG4n8qr5Vs/qDA== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=virtuozzo.com; dmarc=pass action=none header.from=virtuozzo.com; dkim=pass header.d=virtuozzo.com; arc=none DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=virtuozzo.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=ahXtf9RVz1HTWJ2z6fm/jD66GjUgvsUTADpSUKiiYfM=; b=Dh6C7PLgFNKO7BWX+88nBURPYyi2hKMX5OL+b7zIMe4umm3kk/CH13aizhX7NxVnwVZkyv/gEB30Qr7LWpuMblGxxMD8+Ij+W/gvo6EZcaOOSgSc/fVc7TJwiDnVZ7vGaM0AEHAwZP5Y1cwNA53Pwc4JxSiFVKmoOXdH1chCrmVvtONOIUe6MuRHq+5nbumF0BfDdAjnB6Ha/Jb0Sdm9lhAA4CBYh2MYbkjEaA/VVvFaAtq/9MMGJeEDn5CdTd37pWkgZ1DMWKbP7MAs1+DtM7oIbsmemf+5dvQlmNklJSfanerXDUG96I858Ji9wkb6OX3dYGp6DOuLSUVXxOtMWw== Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=virtuozzo.com; Received: from VI0PR08MB10656.eurprd08.prod.outlook.com (2603:10a6:800:20a::12) by AS2PR08MB9414.eurprd08.prod.outlook.com (2603:10a6:20b:596::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.21.382.10; Fri, 4 Sep 2026 09:33:48 +0000 Received: from VI0PR08MB10656.eurprd08.prod.outlook.com ([fe80::4e37:b189:ddcd:3dd8]) by VI0PR08MB10656.eurprd08.prod.outlook.com ([fe80::4e37:b189:ddcd:3dd8%7]) with mapi id 15.21.0382.007; Fri, 4 Sep 2026 09:33:48 +0000 Message-ID: <32a755dd-08dc-4040-b41b-dc1bf0f83823@virtuozzo.com> Date: Fri, 4 Sep 2026 12:33:47 +0300 User-Agent: Mozilla Thunderbird Subject: Re: [QEMU HCI-8.0 PATCH 0/7] qxl cursor use-after-free plus stability backports #VSTOR-144000 To: "Denis V. Lunev" , svt-core@virtuozzo.com References: <20260903202549.2754937-1-den@openvz.org> Content-Language: en-US From: Andrey Drobyshev In-Reply-To: <20260903202549.2754937-1-den@openvz.org> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-ClientProxiedBy: FR4P281CA0211.DEUP281.PROD.OUTLOOK.COM (2603:10a6:d10:e4::7) To VI0PR08MB10656.eurprd08.prod.outlook.com (2603:10a6:800:20a::12) MIME-Version: 1.0 X-MS-PublicTrafficType: Email X-MS-TrafficTypeDiagnostic: VI0PR08MB10656:EE_|AS2PR08MB9414:EE_ X-MS-Office365-Filtering-Correlation-Id: 4e6ee870-f454-471c-711d-08df0a679f56 X-LD-Processed: 0bc7f26d-0264-416e-a6fc-8352af79c58f,ExtAddr List-Id: svt-core@virtuozzo.com X-MS-Exchange-SenderADCheck: 1 X-MS-Exchange-AntiSpam-Relay: 0 X-Microsoft-Antispam: BCL:0;ARA:13230040|23010399003|366016|376014|1800799024|56012099006|10067099003|22082099003|5023799004|5113699003|3023799007|18002099003; X-Microsoft-Antispam-Message-Info: 8NZZsisWIf8FNuKFeu/VN6aIszXeZPcPeGWC3XvPJBzSw1TiWcbb4MNTyXa/GzCTfaUJMIHuzgITwGFH+IOha9p2d5lbEybhWCvGyOYKn/EMaiR8jU3OBSeqC25vRVSn0BotK4MTFHdGPhfIqE1dYR9E4O7/MMNrK2Ix35UML5LZRdjRoGRtdihbmYNe93G+FbaZFeujAkrNyxZBaJFbgpASJS1GV8xPUsTd+f7AgpKygolRIFldUS7WJ2DHv1JLbBzk1hCrTOXydJRe5c0F+B7l7wR3rAPAFRYzqtBZorbAqJwCQUQrSppynwoF/zx24fUyyhxvqhtswnck/m2FB1rAN89UefqJ+sKz++NAl82V0rwNurrGxYofiQ58DxxoI6473abumytFlGTKYd41BBjVypmYb6dy95pBQnIR4IIcHzECMyZTNJTUdRLf0G/UNYDDucY674t0KGEVWFvivb6I5Y2srXi1Ahi1OJj6Uw7Avy8vMqaKooaIen4mSYl2QY+1JkxCb2npHYJ4bSsealJHyj8rmp1t6UNE9rORRAQVYW5fFv9hkNcmDTVbs6cWDdlLSViRPCqhO3upOhHBx9i/mDt0Un24Wxx56kwWU/Y8IFDXRKV666VW36h3HXIk+TKqzAXAAEB6fOGUyu2tw/Vy7XmpL3x8YX3GoufTgUQ= X-Forefront-Antispam-Report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:VI0PR08MB10656.eurprd08.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(23010399003)(366016)(376014)(1800799024)(56012099006)(10067099003)(22082099003)(5023799004)(5113699003)(3023799007)(18002099003);DIR:OUT;SFP:1102; X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1 X-MS-Exchange-AntiSpam-MessageData-0: =?utf-8?B?ZzNQUFJGYVBGZU94MzZKdDAvVFNNQ2owWUFNVkVuQjBlN2JCNWpJSDVtV2hp?= =?utf-8?B?TkRJT1RQdXhQb2pWUGxlaStSakxJdkNmNkZiL2RZSHFVZllKT3MxUW1ES1Jr?= =?utf-8?B?clVWTWxDK3RDYmtVREVQbVh1a0dOWUIyeFZZYjJkWklBTTB5aEUrUGhuSnFE?= =?utf-8?B?MGFrQmN1NWFtRGt4TTl5SXRDVEs0eFlWN0ZyU2FRTTEvSHk5YkEyKzVVdWM5?= =?utf-8?B?dDFNbGJKL3FsS0FiY3AvVlM2WUVZT254WmlyOWZOMEswTzVSMk95OUxIdkhX?= =?utf-8?B?WlNXVS9OZUIraDhSYllPWDFpU1UveG0yQkR6aGR0QW5XMDdsT1lBdk4wSHU1?= =?utf-8?B?cDVjd3N5cFc5cURldDBFYmg4TnlFaGFXSUt4ZmJLY2dFVDFNajU1cDJQVmFD?= =?utf-8?B?anhIYVZtMlJKM20vemMrRkI5WEdINzRwZXlyK0tSUFRNUElUdFBRK1lYU3Q4?= =?utf-8?B?aHRHZHF4MnljdGRNK0hENW1iVFRadHpneE1hN1ZDTFQwd3Q2MVh4RS9jUVpQ?= =?utf-8?B?NDFsNmVBY2c3eGJlWHFUcW9ta0t6K2MvbmNTYWZyeVo3VjY1ZnNrd3lOL1ZH?= =?utf-8?B?N3BGR2M2ZThIK3o0aXFMbmxOVzJMK2NXcmFlZUVYWXBKbUJ2MFBxTkxOOTlm?= =?utf-8?B?S04yQVJNL1NzUnk1R3lUenV0VDVjYXJsT3ZJODJUdkxLOHk0NGR2cEIxQk9h?= =?utf-8?B?TnFBWkZ1a3U1MG1xZndkZkt5RTdsOUhLMnY0YUdSeEJIV3JXSStsbXlWcG9T?= =?utf-8?B?TGE5dU8yZXFNa1FPalBxYVQyK2hBaEwwWTFsdUsrT1NSZjd0OEYra05lMldM?= =?utf-8?B?WDBpRXo1OFluU01XditzY1JXZ1lVUkRyTnF3S2hTUlJnWCtqWHNObXpSTk9R?= =?utf-8?B?ZjhVblhJQW9QeU1CNGhDbENWWUtVc2VTT21Wc0xwaUZJR1o0dVRzcy93SmdF?= =?utf-8?B?MjQ4YUtPK2QwQ0xtZGRWSHFnaVF2cVd0NTREQlFHRk9KKzk0Q2JkbG04NWkr?= =?utf-8?B?WDcrM1JUU2dFYVNvbUExQTBIWU8zbVdseTFLVlE3UGh6bHR4RVhwR0ZXYjhR?= =?utf-8?B?NEh4YnFyWlNEOXFaM0RTSyt0ZXk1VldIT2RIOVBlZnlGTzZoWGNtQkZYbHBR?= =?utf-8?B?b0hGWm1hWGN5LzFwUzZwbmNMeGwvbEVKUE1rcG41VmN4VTVtVFowclZaTG1t?= =?utf-8?B?ZkxDQkFseDllWnF5WEpqODJjWW5DNXFKTjE3UFA2a3doUG1HODZoQ3VKSHBW?= =?utf-8?B?K1g2T05BbXp6cTNHWEVXNURlMFhpUUd2Y2cwZ3NCUmlNSkhyd25kS05tUmpH?= =?utf-8?B?WkxXL044STRBak1MdzBRbFpvVDVTelJlWlR3Wkg5K2RKaGYxWTJjRGRNdzdT?= =?utf-8?B?aXBpdGRZclFtaUhJUnNQZGJzMUVYeGhMZTk1OG1xcm91Mlp1bkg4YUtDR0Vk?= =?utf-8?B?cHpmdzdabWxlN3cyN2ppUjRSdEF1amEwZkh2TURFaFRtTVZrdlNMVUFFUDdF?= =?utf-8?B?VlYvMG0vOEFjNXBUU0xQS2Z2OVljUDJMdG9FZW9rcnpRRTVxVGNyRzBjR040?= =?utf-8?B?MWFtM2ZrY2F5dzcxQXBtVUxnSzh3OTBqeGRQVy96WU9ZZ0doVXJTdlNGOXQ0?= =?utf-8?B?cm5LYnpLZzMybkRNOWpPR2dIV3E0R2dFUkttRkxLY0d5eVpjTEtTb3h2Tko4?= =?utf-8?B?b1BINk1EUXUzYmhSQVVhaFJmbkhVSXlFd3FZOFJnLzB5am5QLzhSUEZhNXJ4?= =?utf-8?B?eHdIVmFMWkpSVHpTSTFhaThFcGU5c3YzYm0wa0lubm9CN1F5VWNVTGZxdVgx?= =?utf-8?B?YVBiblVqQ0pNQXhhY0hqQ1FpWUVPQjV6d3N0VjBWU2haZVR1bnlLTm5oc20v?= =?utf-8?B?bWN2RTBvM3lFblRUTlZUWnBFaHhnODVVODJvL3hNb2MwczM1cmo3dnBNQ1dn?= =?utf-8?B?b0dUVlVKeC9jaitabXlxNDlNSGZIM2hJYWp0ZThDZEVEaGsrT3luSkRIV0Jo?= =?utf-8?B?YVRyWmhXM0dIV3JUR1FFdmlGa2I2b09rS2hudkdKcDFyeU5pV1RDblducHFH?= =?utf-8?B?Y2V6YWRzeG5OZTFWa1RTOFJpRWFtaGNIVGd6QUJmeVF6Y0NyTFJMeUpTTUJ1?= =?utf-8?B?MFVHcW1qME1SSjZkRW1Gc2tOUlJBQWw1MEh1N3YrRzFhRlJkR1ZJdHRCcVJt?= =?utf-8?B?TUt4bTBGY2dIU0N4dTJ4NG5KMGIxUFNTOTlXWjNnNFlSTlBSclQwRzd3TG5H?= =?utf-8?B?OTFHdzZ4QkgyUjNrVlUvaXJnUnBJT1JvNWxnY0xTRmhpa3FHMFpGNU1yb0pk?= =?utf-8?B?Sisxemd0RkRvT1QvTzJUTFZ0eVRWeU5YcUsrQS90Ukd1eXZQYklVRVVLLzBU?= =?utf-8?Q?WTKO6DToFbxz8GHw=3D?= X-Auto-Response-Suppress: DR, OOF, AutoReply X-OriginatorOrg: virtuozzo.com X-MS-Exchange-CrossTenant-Network-Message-Id: 4e6ee870-f454-471c-711d-08df0a679f56 X-MS-Exchange-CrossTenant-AuthSource: VI0PR08MB10656.eurprd08.prod.outlook.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-OriginalArrivalTime: 04 Sep 2026 09:33:48.3044 (UTC) X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted X-MS-Exchange-CrossTenant-Id: 0bc7f26d-0264-416e-a6fc-8352af79c58f X-MS-Exchange-CrossTenant-MailboxType: HOSTED X-MS-Exchange-CrossTenant-UserPrincipalName: fG9VSIhHSZflc6HYlMHsRgPvai3TzLD1hFDJBbVJTAI7AnLgxfRnn9/CE4DkL3lCq9EBiuFfzLAs0/9qt3+TpNL7xELFPVWCqvd6CWanVfY= X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS2PR08MB9414 Ack Applied to hci-8.0 On 9/3/26 11:25 PM, Denis V. Lunev wrote: > A guest with a qxl display can make QEMU drop more references to a > QEMUCursor than were taken. The cursor is freed while another owner > still points at it, and that owner's later cursor_unref() decrements > four bytes of a chunk the allocator has handed out again. Nothing > aborts and nothing is logged; QEMU dies later in an unrelated > allocation, in another thread. > > Two defects get there, and neither fix is sufficient alone: > > - qxl_spice_reset_cursor() replaces qxl->ssd.cursor with no lock held, > while every other writer of that field takes ssd.lock. It runs on a > vCPU thread from QXL_IO_DESTROY_PRIMARY and, unlike qxl_hard_reset(), > leaves the SPICE display worker running. > > - QEMUCursor.refcount is a plain int, taken and dropped from the main > loop, the SPICE worker, ui/cocoa.m and ui/dbus-listener.c, with no > lock common to all of them, so an increment can be lost. > > A qxl device starts a spice-server instance for local rendering even > with no -spice, so this is not limited to SPICE console setups. > > Patch 2 also asserts that the refcount was positive. Only qxl was > exercised here, so if another display backend drops a reference it > never took, that assert turns a silent leak into an abort. > > Reproducer: a libdrm program in the guest queues cursor SET commands, > then disables the CRTC so the driver issues QXL_IO_DESTROY_PRIMARY. > Unpatched QEMU dies within seconds; with the series it does not. > > Patches 1 and 2 were posted upstream and carry Marc-Andre's > Reviewed-by, but are not merged yet, so they have no cherry-pick line: > > https://lore.kernel.org/qemu-devel/20260903192647.2677279-1-den@openvz.org/ > > Patches 3 to 7 are definitive stability fixes, cherry-picked from > mainstream. All five are already reviewed and merged upstream, and none > of them was present on our branch. They are unrelated to the crash > above but sit in the same device, so they are worth taking in one go: > > 3/7 mono cursor validation reading past a cursor chunk > 4/7 TOCTOU in cursor chunk data_size handling > 5/7 monitors_config heads[] validation in phys2virt > 6/7 vm_change_state handler and BHs left registered on unrealize > 7/7 primary surface stride not validated against width > > Two of those carry CVE references in their upstream messages, 7/7 > CVE-2026-16271 and 6/7 CVE-2026-63322. > > None of these seven touches qxl_post_load(), so none of them addresses > the migration failure tracked separately in VSTOR-113533. > > Denis V. Lunev (2): > hw/display/qxl: hold ssd.lock while replacing ssd.cursor #VSTOR-144000 > ui/cursor: make the cursor refcount atomic #VSTOR-144000 > > Haotian Jiang (1): > hw/display/qxl: unregister vm_change_state handler and BHs > #VSTOR-144000 > > Marc-André Lureau (3): > hw/display/qxl: fix TOCTOU in cursor chunk data_size handling > #VSTOR-144000 > hw/display/qxl: validate monitors_config heads[] in phys2virt > #VSTOR-144000 > hw/display/qxl: validate primary surface stride against width > #VSTOR-144000 > > Thomas Huth (1): > hw/display/qxl: Fix mono cursor validation that can read past a cursor > chunk #VSTOR-144000 > > hw/display/qxl-render.c | 98 +++++++++++++++++++++++++---------------- > hw/display/qxl.c | 79 ++++++++++++++++++++++++++++++++- > hw/display/qxl.h | 3 ++ > include/ui/console.h | 9 ++++ > ui/cursor.c | 17 ++++--- > 5 files changed, 160 insertions(+), 46 deletions(-) >