Some nits still remain:

On 2026/07/20 16:15, [email protected] wrote:
From: Haotian Jiang <[email protected]>

rutabaga_cmd_set_scanout() checks scanout_id < VIRTIO_GPU_MAX_SCANOUTS
(16), but does not check scanout_id < conf.max_outputs like the base
class (virtio-gpu.c) and virgl backend (virtio-gpu-virgl.c) do.

With the default max_outputs=1, virtio_gpu_base_device_realize only
initializes scanout[0].con. A guest submitting SET_SCANOUT with
scanout_id >= 1 takes the con=NULL path, and
qemu_console_set_surface(NULL, NULL) dereferences con->ds, crashing
QEMU.

scanout_id >= VIRTIO_GPU_MAX_SCANOUTS is already covered by an existing check. Crashing QEMU may be the most probable consequence, but it may turn out otherwise. I think just noting the out of bound access is sufficient and concise.


Replace VIRTIO_GPU_MAX_SCANOUTS with vb->conf.max_outputs in the
CHECK, since realization already ensures max_outputs <=
VIRTIO_GPU_MAX_SCANOUTS.

Fixes: 1dcc6adbc1 ("gfxstream + rutabaga: add initial support for gfxstream")

docs/devel/submitting-a-patch.rst says:

> If your patch fixes a commit that is already in the repository, please
> add an additional line with
> "Fixes: <at-least-12-digits-of-SHA-commit-id>
> ("Fixed commit subject")" below the patch description / before your
> "Signed-off-by:" line in the commit message.

This "Fixes:" tag only contains 10 digits.

Unfortunately, QEMU's documentation doesn't tell much about how to generate the Fixes: tag, but Linux's documentation has more details:
https://www.kernel.org/doc/html/v7.1/process/submitting-patches.html#describe-your-changes

Regards,
Akihiko Odaki

Reported-by: Haotian Jiang of Tencent Security (Yunding Lab) 
<[email protected]>
Signed-off-by: Haotian Jiang <[email protected]>
Cc: [email protected]
---
  hw/display/virtio-gpu-rutabaga.c | 2 +-
  1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/hw/display/virtio-gpu-rutabaga.c b/hw/display/virtio-gpu-rutabaga.c
index 6ff1263901..3f78899442 100644
--- a/hw/display/virtio-gpu-rutabaga.c
+++ b/hw/display/virtio-gpu-rutabaga.c
@@ -302,7 +302,7 @@ rutabaga_cmd_set_scanout(VirtIOGPU *g, struct 
virtio_gpu_ctrl_command *cmd)
      trace_virtio_gpu_cmd_set_scanout(ss.scanout_id, ss.resource_id,
                                       ss.r.width, ss.r.height, ss.r.x, ss.r.y);
- CHECK(ss.scanout_id < VIRTIO_GPU_MAX_SCANOUTS, cmd);
+    CHECK(ss.scanout_id < vb->conf.max_outputs, cmd);
      scanout = &vb->scanout[ss.scanout_id];
if (ss.resource_id == 0) {


Reply via email to