Linfeng Sun
0d195797a8
vdpa_sim_net: check TX pull result before RX copy
...
vringh_iov_pull_iotlb() returns a signed byte count. A failed TX pull is
currently added to the unsigned byte counter and then passed as a size_t
length to receive_filter() and vringh_iov_push_iotlb(). A negative error
can therefore become a large length in the RX path.
Handle non-positive pull results before every length use. Count the TX
error and complete the consumed TX descriptor with zero bytes.
I found this bug myself, though the patch was written with AI assistance.
Fixes: cfe2268929 ("vdpa_sim: filter destination mac address")
Assisted-by: OpenAI-Codex:GPT-5
Signed-off-by: Linfeng Sun <linfeng.sun.dev@gmail.com >
Signed-off-by: Michael S. Tsirkin <mst@redhat.com >
Message-ID: <20260901094842.25875-1-linfeng.sun.dev@gmail.com >
2026-09-07 18:54:03 -04:00
..
2026-09-05 20:45:18 -07:00
2026-09-04 21:37:00 -07:00
2026-08-25 09:38:50 -07:00
2026-09-03 16:10:44 +02:00
2026-08-24 08:15:59 -07:00
2026-09-05 20:45:18 -07:00
2026-09-05 20:45:18 -07:00
2026-08-31 14:05:27 -04:00
2026-08-25 09:38:50 -07:00
2026-09-07 18:54:02 -04:00
2026-09-04 21:37:00 -07:00
2026-08-26 16:47:40 -07:00
2026-08-25 09:38:50 -07:00
2026-09-04 21:37:00 -07:00
2026-09-01 17:28:56 +02:00
2026-09-04 21:37:00 -07:00
2026-08-20 18:17:08 -07:00
2026-09-04 21:37:00 -07:00
2026-08-12 17:08:05 -07:00
2026-09-04 21:37:00 -07:00
2026-09-05 20:45:18 -07:00
2026-08-18 10:42:41 -07:00
2026-09-04 21:37:00 -07:00
2026-08-22 08:41:28 -07:00
2026-09-04 21:37:00 -07:00
2026-09-04 21:37:00 -07:00
2026-08-14 19:21:17 -03:00
2026-08-25 09:38:50 -07:00
2026-09-04 21:37:00 -07:00
2026-09-05 20:45:18 -07:00
2026-09-04 21:37:00 -07:00
2026-08-21 12:01:23 -07:00
2026-09-04 21:37:00 -07:00
2026-09-04 21:37:00 -07:00
2026-09-04 21:37:00 -07:00
2026-09-04 21:37:00 -07:00
2026-09-04 21:37:00 -07:00
2026-08-07 21:22:50 +02:00
2026-09-04 21:37:00 -07:00
2026-09-04 21:37:00 -07:00
2026-09-04 21:37:00 -07:00
2026-08-19 09:55:37 +02:00
2026-09-04 21:37:00 -07:00
2026-08-25 09:38:50 -07:00
2026-09-06 10:35:24 -07:00
2026-08-27 11:05:51 -07:00
2026-09-04 21:37:00 -07:00
2026-09-04 21:37:00 -07:00
2026-09-04 21:37:00 -07:00
2026-08-23 09:11:21 -07:00
2026-09-04 21:37:00 -07:00
2026-09-01 09:38:51 +02:00
2026-08-21 11:58:08 -07:00
2026-09-04 21:37:00 -07:00
2026-09-04 21:37:00 -07:00
2026-08-18 10:42:41 -07:00
2026-08-20 13:43:24 -07:00
2026-09-04 21:37:00 -07:00
2026-09-05 20:45:18 -07:00
2026-08-25 09:38:50 -07:00
2026-08-27 12:53:43 -07:00
2026-09-04 21:37:00 -07:00
2026-08-18 11:43:05 +02:00
2026-09-04 21:37:00 -07:00
2026-08-20 14:53:54 -07:00
2026-08-26 11:14:30 -07:00
2026-08-24 08:46:03 -07:00
2026-09-04 21:37:00 -07:00
2026-09-04 21:37:00 -07:00
2026-08-07 20:01:31 +02:00
2026-09-04 21:37:00 -07:00
2026-08-26 14:13:26 -07:00
2026-09-04 21:37:00 -07:00
2026-08-19 10:42:18 -07:00
2026-08-31 20:10:39 -07:00
2026-08-27 12:21:56 -07:00
2026-08-18 11:57:17 -07:00
2026-08-26 11:14:30 -07:00
2026-08-28 09:53:43 -07:00
2026-09-04 21:37:00 -07:00
2026-09-05 20:45:18 -07:00
2026-09-04 21:37:00 -07:00
2026-08-24 12:16:16 -07:00
2026-09-04 21:37:00 -07:00
2026-09-06 09:49:06 -07:00
2026-09-01 22:08:31 -04:00
2026-09-04 21:37:00 -07:00
2026-08-27 10:45:08 -07:00
2026-09-04 21:37:00 -07:00
2026-09-04 21:37:00 -07:00
2026-09-05 20:45:18 -07:00
2026-09-06 08:50:20 -07:00
2026-09-07 18:54:03 -04:00
2026-08-20 18:17:08 -07:00
2026-09-07 18:54:02 -04:00
2026-08-27 11:16:39 -07:00
2026-08-18 11:57:17 -07:00
2026-09-07 18:54:03 -04:00
2026-08-27 10:45:08 -07:00
2026-09-04 21:37:00 -07:00