From: Magnus Kulke <[email protected]>

Processor features are stored in a union containing two "banks":

union hv_partition_processor_features {
    uint64_t as_uint[2];
    struct {
        uint64_t sse3_support:1;
        ...
    }
}

get_proc_features() to retrieve the 2nd bank was passing a pointer that
steps over the whole union (+16B) instead of picking the 2nd bank _in_
the union. This manifests in mismatching feature bits for the 2nd bank
and possibly other side-effects caused by writing beyond the union.

We need to step over the first bank (+8B) by using as_uint64[0/1] to
correct this behaviour.

Resolves: Coverity CID 1660876
Fixes: 2f6da91e8a ("accel/mshv: store partition proc features")
Signed-off-by: Magnus Kulke <[email protected]>
Reviewed-by: Doru Blânzeanu <[email protected]>
Reviewed-by: Philippe Mathieu-Daudé <[email protected]>
Reviewed-by: Peter Maydell <[email protected]>
Message-ID: <[email protected]>
Signed-off-by: Philippe Mathieu-Daudé <[email protected]>
---
 accel/mshv/mshv-all.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/accel/mshv/mshv-all.c b/accel/mshv/mshv-all.c
index 1959baf6672..72721d0f0de 100644
--- a/accel/mshv/mshv-all.c
+++ b/accel/mshv/mshv-all.c
@@ -167,7 +167,7 @@ static int get_proc_features(int vm_fd,
 
     ret = get_partition_property(vm_fd,
                                  HV_PARTITION_PROPERTY_PROCESSOR_FEATURES0,
-                                 features[0].as_uint64);
+                                 &features->as_uint64[0]);
     if (ret < 0) {
         error_report("Failed to get processor features bank 0");
         return -1;
@@ -175,7 +175,7 @@ static int get_proc_features(int vm_fd,
 
     ret = get_partition_property(vm_fd,
                                  HV_PARTITION_PROPERTY_PROCESSOR_FEATURES1,
-                                 features[1].as_uint64);
+                                 &features->as_uint64[1]);
     if (ret < 0) {
         error_report("Failed to get processor features bank 1");
         return -1;
-- 
2.53.0


Reply via email to