From: Laurent Vivier <[email protected]>

rx_desc_len is migrated as a raw uint8_t from the stream but is a
derived value. Currently igb_rx_use_legacy_descriptor() is a stub
that always returns false, so rx_desc_len is always set to
sizeof(union e1000_adv_rx_desc). Recalculate it in post_load to
prevent a crafted migration stream from setting an invalid value.

Cc: [email protected]
Signed-off-by: Laurent Vivier <[email protected]>
Reviewed-by: Akihiko Odaki <[email protected]>
Message-ID: <[email protected]>
Reviewed-by: Philippe Mathieu-Daudé <[email protected]>
Signed-off-by: Philippe Mathieu-Daudé <[email protected]>
(cherry picked from commit 1e5efe6d93701d6b2b05b62822c02eee935490b5)
Signed-off-by: Michael Tokarev <[email protected]>

diff --git a/hw/net/igb_core.c b/hw/net/igb_core.c
index 39e3ce1c8fe..f362e201b14 100644
--- a/hw/net/igb_core.c
+++ b/hw/net/igb_core.c
@@ -4547,5 +4547,7 @@ igb_core_post_load(IGBCore *core)
     igb_intrmgr_resume(core);
     igb_autoneg_resume(core);
 
+    igb_calc_rxdesclen(core);
+
     return 0;
 }
-- 
2.47.3


Reply via email to