From nobody Wed Sep 30 15:54:09 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hw0363m4dz6tjtr for ; Wed, 30 Sep 2026 15:54:10 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hw0356Pkyz4ScV for ; Wed, 30 Sep 2026 15:54:09 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790783649; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=E0gKAmbBnQEN/4e109vrB8u7zSuHbois3+QQfovKI04=; b=dqBSCuN+8oVK77vcS8NpZijP/jr32fYP+oRM9NRsDc6cp36AAskY8rNWABahGKjkmkWZeG wx/BKzF1K4a6M4X7Fr6v47LZJSdhvJtO0MhxDc5VZ1FKwhEbSdUf44rzz5O10BMODzqQII YdHSsfIBSNutf8jpkLPtgTdEIE/PTibbAzwPQ7oGau6qKzInMmPpcfZF4Pf76IKd/Mw78y h4ZUO0aY7M2S9BSesnahjbeRctFOgMPNJ4+ha7ekvTV0LXymtsnuKVmPi/mu7t1rMUEJoX o3lOA9hGzFdVhTxc0U6cXfUiVNV9+BikS4Rfa8yN6e/80PnhvSDj1/jZR8io0A== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1790783649; b=fFlEPwXZtbMuNsuj+VWt6gJQLvpiOucEO7IztYx4XLNNGCCds+9H9B+3WpELETGJn6CQmF Lx+eU+0DlAW8tMWwyWU30yGKECFTRuWOgBTeFA8RBAZDHbn9fWZjzYf3zfs5ndBh8ep0SJ RbPYBRaJGQlpkaF2k0+zw2dxxhJi0qi9cCFVOaR1PS7tgc+SodlAxGTfDfR7QEVjOyBTd3 bVgLvqurYE4C+/OHKcaoCOAO60C5jO0PX3BUfh9kf1/cue1rnWY/N+vLeBlHQJQD9fQhVa kE4px2kukp2qGLHCy2J+t7iC6S1jF1y/YD8hUc8ZGDuWFr9bjGNcfMZL5E7EHA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790783649; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=E0gKAmbBnQEN/4e109vrB8u7zSuHbois3+QQfovKI04=; b=rJY4u69HU6I2xiT9/XxIeTGx19BfijE1kBUNbDFreZZs9EZLb9bvnYy1Ij//06aAe1LODD FyAOkGM4VCxXv6gBw617VsRl1ASOPdzSAC+/C8HgYnumkirfk9DYeSAJtxg6ci5088E+km 63NvN96ZqOC2l3kirk6pwVTxOz0xKhRbDz1xm0n7YVCSIPYMJprfSqC7H4nHgwxhCosIZa XqfhWcQi3oEzJPaOuHyRk4VhYY8SqlOhbKO0sUD5X6KxZ+ZzsaVIQFvu+s2CBk+0G99Kpg yYVYr/wEWqVRa/l1ubx+U1Q1vVOyzV4T6EhuhOXzc92PBfb0fQ14LjqBpajR6w== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hw0355TyDzrPw for ; Wed, 30 Sep 2026 15:54:09 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 32e26 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Wed, 30 Sep 2026 15:54:09 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org Cc: Hayzam Sherif From: Mark Johnston Subject: git: 4485bfaed214 - main - bhyve: Validate VirtIO queue guest addresses List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: markj X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 4485bfaed2145e88911bd3522d6fee5c0f8ceb39 Auto-Submitted: auto-generated Date: Wed, 30 Sep 2026 15:54:09 +0000 Message-Id: <6abd30a1.32e26.552e32aa@gitrepo.freebsd.org> The branch main has been updated by markj: URL: https://cgit.FreeBSD.org/src/commit/?id=4485bfaed2145e88911bd3522d6fee5c0f8ceb39 commit 4485bfaed2145e88911bd3522d6fee5c0f8ceb39 Author: Hayzam Sherif AuthorDate: 2026-09-30 14:17:24 +0000 Commit: Mark Johnston CommitDate: 2026-09-30 15:53:51 +0000 bhyve: Validate VirtIO queue guest addresses paddr_guest2host() returns NULL when a range does not fit within guest RAM. An unmappable queue address previously left the queue marked allocated with ring pointers computed from the failed mapping. Check the legacy virtqueue ring mapping before updating the queue state, and ignore an unmappable PFN write after printing a diagnostic. This leaves an unallocated queue unallocated and preserves an existing queue's PFN, ring pointers, flags, and indices. Also check the indirect descriptor table mapping before dereferencing it, returning an error if the table is unmappable, and ignore guest queue notifications for unallocated queues. Reviewed by: markj MFC after: 2 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D59904 --- usr.sbin/bhyve/virtio.c | 16 +++++++++++++++- 1 file changed, 15 insertions(+), 1 deletion(-) diff --git a/usr.sbin/bhyve/virtio.c b/usr.sbin/bhyve/virtio.c index a5ccbb9983a0..c0122238b457 100644 --- a/usr.sbin/bhyve/virtio.c +++ b/usr.sbin/bhyve/virtio.c @@ -182,10 +182,15 @@ vi_vq_init(struct virtio_softc *vs, uint32_t pfn) char *base; vq = &vs->vs_queues[vs->vs_curq]; - vq->vq_pfn = pfn; phys = (uint64_t)pfn << VRING_PFN; size = vring_size_aligned(vq->vq_qsize); base = paddr_guest2host(vs->vs_pi->pi_vmctx, phys, size); + if (base == NULL) { + EPRINTLN("%s: queue %u has invalid GPA %#jx/%#zx", + vs->vs_vc->vc_name, vq->vq_num, (uintmax_t)phys, size); + return; + } + vq->vq_pfn = pfn; /* First page(s) are descriptors... */ vq->vq_desc = (struct vring_desc *)base; @@ -349,6 +354,13 @@ vq_getchain(struct vqueue_info *vq, struct iovec *iov, int niov, } vindir = paddr_guest2host(ctx, vdir->addr, vdir->len); + if (vindir == NULL) { + EPRINTLN( + "%s: indirect table GPA %#jx/%#x is " + "unmappable", name, (uintmax_t)vdir->addr, + (u_int)vdir->len); + return (-1); + } /* * Indirects start at the 0th, then follow * their own embedded "next"s until those run @@ -780,6 +792,8 @@ bad: goto done; } vq = &vs->vs_queues[value]; + if (!vq_ring_ready(vq)) + goto done; if (vq->vq_notify) (*vq->vq_notify)(DEV_SOFTC(vs), vq); else if (vc->vc_qnotify)