From nobody Tue May 13 18:38:30 2025 Delivered-To: importer2@patchew.org Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer2=patchew.org@nongnu.org; dmarc=pass(p=reject dis=none) header.from=linux.ibm.com ARC-Seal: i=1; a=rsa-sha256; t=1677189578; cv=none; d=zohomail.com; s=zohoarc; b=BLoXDtKNDKCwi9hI2wozJg+qkirio2HKPCdGewSHSv75t8ltqisZeBz3Hc3f2URzNMoZMkc2veidQtnc2jQ/rvO3Cy1Vll7+/uLN9eL8GXw6Evsb1pawb+Lx/7UjqoHM7VjnSwfgO92SiefePtHnnctlqVDWa9EG7Y0XIUoKCsM= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1677189578; h=Content-Transfer-Encoding:Cc:Date:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:To; bh=G/ynAq+gVEDic/LEXIjGQywDL7mnx0doz9rgeqWvxmQ=; b=VqNry31r0OT+cjMaDgSfEc5t2G9QgzssxuU6ARw0pZkP2gbQiCIS9+IcwK1iioum+BV89IyNF6nPmUt+TW//cAZFJoxrFVU8oCxXZ1G7qO7IWtExgVLTQq9W+ycWmPN7ynECIYOag6ODlLjvChrez1qceDzMbcEbADMROV7Ppsk= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer2=patchew.org@nongnu.org; dmarc=pass header.from= (p=reject dis=none) Return-Path: Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mx.zohomail.com with SMTPS id 1677189578849676.5860494737178; Thu, 23 Feb 2023 13:59:38 -0800 (PST) Received: from localhost ([::1] helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1pVJc7-00075V-Q9; Thu, 23 Feb 2023 16:58:55 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1pVJc4-00072b-J5 for qemu-devel@nongnu.org; Thu, 23 Feb 2023 16:58:52 -0500 Received: from mx0b-001b2d01.pphosted.com ([148.163.158.5] helo=mx0a-001b2d01.pphosted.com) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1pVJc1-0002Fm-0o for qemu-devel@nongnu.org; Thu, 23 Feb 2023 16:58:52 -0500 Received: from pps.filterd (m0098420.ppops.net [127.0.0.1]) by mx0b-001b2d01.pphosted.com (8.17.1.19/8.17.1.19) with ESMTP id 31NKL88D026136; Thu, 23 Feb 2023 21:58:45 GMT Received: from ppma04ams.nl.ibm.com (63.31.33a9.ip4.static.sl-reverse.com [169.51.49.99]) by mx0b-001b2d01.pphosted.com (PPS) with ESMTPS id 3nxf3m29kc-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 23 Feb 2023 21:58:45 +0000 Received: from pps.filterd (ppma04ams.nl.ibm.com [127.0.0.1]) by ppma04ams.nl.ibm.com (8.17.1.19/8.17.1.19) with ESMTP id 31N7VYIZ007325; Thu, 23 Feb 2023 21:58:43 GMT Received: from smtprelay07.fra02v.mail.ibm.com ([9.218.2.229]) by ppma04ams.nl.ibm.com (PPS) with ESMTPS id 3ntpa6f6ne-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Thu, 23 Feb 2023 21:58:43 +0000 Received: from smtpav05.fra02v.mail.ibm.com (smtpav05.fra02v.mail.ibm.com [10.20.54.104]) by smtprelay07.fra02v.mail.ibm.com (8.14.9/8.14.9/NCO v10.0) with ESMTP id 31NLwdxA48824748 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Thu, 23 Feb 2023 21:58:40 GMT Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id D625320043; Thu, 23 Feb 2023 21:58:39 +0000 (GMT) Received: from smtpav05.fra02v.mail.ibm.com (unknown [127.0.0.1]) by IMSVA (Postfix) with ESMTP id 7AC7820040; Thu, 23 Feb 2023 21:58:39 +0000 (GMT) Received: from heavy.boeblingen.de.ibm.com (unknown [9.179.17.238]) by smtpav05.fra02v.mail.ibm.com (Postfix) with ESMTP; Thu, 23 Feb 2023 21:58:39 +0000 (GMT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ibm.com; h=from : to : cc : subject : date : message-id : in-reply-to : references : mime-version : content-transfer-encoding; s=pp1; bh=G/ynAq+gVEDic/LEXIjGQywDL7mnx0doz9rgeqWvxmQ=; b=UGjhQOXwML7hv/MPlqnMN6sjhNd3/CI8NpHJKBe/WasDENsbfzPRyx4O89dbe6Kmu/K2 Jf/IBYQ3s9BgwWWjdNxBILiy1i5L72U74Fa3QGgcSaIoiCHs1CdR5mk0uYWR1kUS/WM7 oib3jMtJgY/pUtFov5fnV5iQA1I4y1jN+DACO+Pey/6hbgpVeHmg/4BMLxjnN3IGqr1R 86yiGpobI06ZTwfml9j20NfDJOZP1lP5Z6F6lR02aztrFzDuSX/e6rHLLm3ynhX7PC27 cSrH3Xzbzo460UOSGuqczk8E3c7rKpO3kMm4aABFQtTSfnH6L0s+9sW4g9K/MeFR85si Jg== From: Ilya Leoshkevich To: =?UTF-8?q?Alex=20Benn=C3=A9e?= , Laurent Vivier Cc: qemu-devel@nongnu.org, Christian Borntraeger , Ilya Leoshkevich , Richard Henderson Subject: [PATCH 1/2] linux-user: Fix unaligned memory access in prlimit64 syscall Date: Thu, 23 Feb 2023 22:58:33 +0100 Message-Id: <20230223215834.166055-2-iii@linux.ibm.com> X-Mailer: git-send-email 2.39.1 In-Reply-To: <20230223215834.166055-1-iii@linux.ibm.com> References: <20230223215834.166055-1-iii@linux.ibm.com> MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-TM-AS-GCONF: 00 X-Proofpoint-GUID: x-AxAy72TBbyiLoB6Qb7itrY4_9wnZrs X-Proofpoint-ORIG-GUID: x-AxAy72TBbyiLoB6Qb7itrY4_9wnZrs X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.219,Aquarius:18.0.930,Hydra:6.0.562,FMLib:17.11.170.22 definitions=2023-02-23_13,2023-02-23_01,2023-02-09_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 malwarescore=0 phishscore=0 adultscore=0 lowpriorityscore=0 mlxlogscore=999 suspectscore=0 clxscore=1015 impostorscore=0 bulkscore=0 spamscore=0 priorityscore=1501 mlxscore=0 classifier=spam adjust=0 reason=mlx scancount=1 engine=8.12.0-2212070000 definitions=main-2302230177 Received-SPF: pass (zohomail.com: domain of gnu.org designates 209.51.188.17 as permitted sender) client-ip=209.51.188.17; envelope-from=qemu-devel-bounces+importer2=patchew.org@nongnu.org; helo=lists.gnu.org; Received-SPF: pass client-ip=148.163.158.5; envelope-from=iii@linux.ibm.com; helo=mx0a-001b2d01.pphosted.com X-Spam_score_int: -19 X-Spam_score: -2.0 X-Spam_bar: -- X-Spam_report: (-2.0 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: qemu-devel-bounces+importer2=patchew.org@nongnu.org Sender: qemu-devel-bounces+importer2=patchew.org@nongnu.org X-ZohoMail-DKIM: pass (identity @ibm.com) X-ZM-MESSAGEID: 1677189579364100001 Content-Type: text/plain; charset="utf-8" 32-bit guests may enforce only 4-byte alignment for target_rlimit64, whereas 64-bit hosts normally require the 8-byte one. Therefore accessing this struct directly is UB. Fix by adding a local copy. Fixes: 163a05a8398b ("linux-user: Implement prlimit64 syscall") Reported-by: Richard Henderson Signed-off-by: Ilya Leoshkevich --- linux-user/syscall.c | 12 +++++++----- 1 file changed, 7 insertions(+), 5 deletions(-) diff --git a/linux-user/syscall.c b/linux-user/syscall.c index a6c426d73cf..8ae7696d8f1 100644 --- a/linux-user/syscall.c +++ b/linux-user/syscall.c @@ -12876,7 +12876,7 @@ static abi_long do_syscall1(CPUArchState *cpu_env, = int num, abi_long arg1, case TARGET_NR_prlimit64: { /* args: pid, resource number, ptr to new rlimit, ptr to old rlimi= t */ - struct target_rlimit64 *target_rnew, *target_rold; + struct target_rlimit64 *target_rnew, *target_rold, tmp; struct host_rlimit64 rnew, rold, *rnewp =3D 0; int resource =3D target_to_host_resource(arg2); =20 @@ -12886,8 +12886,9 @@ static abi_long do_syscall1(CPUArchState *cpu_env, = int num, abi_long arg1, if (!lock_user_struct(VERIFY_READ, target_rnew, arg3, 1)) { return -TARGET_EFAULT; } - rnew.rlim_cur =3D tswap64(target_rnew->rlim_cur); - rnew.rlim_max =3D tswap64(target_rnew->rlim_max); + memcpy(&tmp, target_rnew, sizeof(tmp)); + rnew.rlim_cur =3D tswap64(tmp.rlim_cur); + rnew.rlim_max =3D tswap64(tmp.rlim_max); unlock_user_struct(target_rnew, arg3, 0); rnewp =3D &rnew; } @@ -12897,8 +12898,9 @@ static abi_long do_syscall1(CPUArchState *cpu_env, = int num, abi_long arg1, if (!lock_user_struct(VERIFY_WRITE, target_rold, arg4, 1)) { return -TARGET_EFAULT; } - target_rold->rlim_cur =3D tswap64(rold.rlim_cur); - target_rold->rlim_max =3D tswap64(rold.rlim_max); + tmp.rlim_cur =3D tswap64(rold.rlim_cur); + tmp.rlim_max =3D tswap64(rold.rlim_max); + memcpy(target_rold, &tmp, sizeof(*target_rold)); unlock_user_struct(target_rold, arg4, 1); } return ret; --=20 2.39.1