On Thu, 9 Jul 2026 15:50:36 +0200
Christian Schoenebeck <[email protected]> wrote:

> Harden security by disabling hotpluggable property, to prevent
> issues like fixed in the previous commit.
> 
> Virtio-9p is a pass-through file-sharing device that provides a
> guest mount of a host filesystem tree. Unlike block or network
> devices, guest-triggered hotplug of the 9p device has no practical
> use case: the guest cannot recover from the device removal, and there
> is no protocol-level device-loss scenario as with block or ethernet
> devices.

hmh, I'm no maintainer of 9pfs, but to me it looks like any other
storage device.
One should be able to unmount/stop using it and unplug
(it doesn't really matter if unplug is triggered by guest or host side).

> Prevent guest-triggered hotplug by marking the device as
> non-hotpluggable. Device removal via QMP is not affected by this, as
> the QMP removal path is not reading the device's hotpluggable field
> at all.
> 
> Signed-off-by: Christian Schoenebeck <[email protected]>
> ---
>  hw/9pfs/virtio-9p-device.c | 1 +
>  1 file changed, 1 insertion(+)
> 
> diff --git a/hw/9pfs/virtio-9p-device.c b/hw/9pfs/virtio-9p-device.c
> index 1ec48fc9e0..ba43fd22d2 100644
> --- a/hw/9pfs/virtio-9p-device.c
> +++ b/hw/9pfs/virtio-9p-device.c
> @@ -273,6 +273,7 @@ static void virtio_9p_class_init(ObjectClass *klass, 
> const void *data)
>  
>      device_class_set_props(dc, virtio_9p_properties);
>      dc->vmsd = &vmstate_virtio_9p;
> +    dc->hotpluggable = false;
>      set_bit(DEVICE_CATEGORY_STORAGE, dc->categories);
>      vdc->realize = virtio_9p_device_realize;
>      vdc->unrealize = virtio_9p_device_unrealize;


Reply via email to