On Mon, 13 Jul 2026 at 11:05, Thomas Huth <[email protected]> wrote:
>
> From: Thomas Huth <[email protected]>
>
> The FIXME macros in xhci_alloc_device_streams() can be triggered
> by a (malicious) guest. Since the macro also contains an abort()
> statement, this terminates QEMU. Turn the FIXME statements into
> a qemu_log_mask() instead to avoid that a guest can shoot itself
> this way.
>
> Reported-by: Feifan Qian <[email protected]>
> Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3784
> Reviewed-by: Philippe Mathieu-Daudé <[email protected]>
> Signed-off-by: Thomas Huth <[email protected]>
> ---
>  hw/usb/hcd-xhci.c | 6 ++++--
>  1 file changed, 4 insertions(+), 2 deletions(-)
>
> diff --git a/hw/usb/hcd-xhci.c b/hw/usb/hcd-xhci.c
> index 2cdab3ba0e4..f5bb7d25600 100644
> --- a/hw/usb/hcd-xhci.c
> +++ b/hw/usb/hcd-xhci.c
> @@ -965,11 +965,13 @@ static TRBCCode xhci_alloc_device_streams(XHCIState 
> *xhci, unsigned int slotid,
>           * together and make an usb_device_alloc_streams call per group.
>           */
>          if (epctxs[i]->nr_pstreams != req_nr_streams) {
> -            FIXME("guest streams config not identical for all eps");
> +            qemu_log_mask(LOG_UNIMP,
> +                          "guest streams config not identical for all 
> eps\n");
>              return CC_RESOURCE_ERROR;
>          }
>          if (eps[i]->max_streams != dev_max_streams) {
> -            FIXME("device streams config not identical for all eps");
> +            qemu_log_mask(LOG_UNIMP,
> +                          "device streams config not identical for all 
> eps\n");
>              return CC_RESOURCE_ERROR;
>          }
>      }


Reviewed-by: Peter Maydell <[email protected]>

thanks
-- PMM

Reply via email to