Go to file
Prasad J Pandit abd7f08b23 display: virtio-gpu-3d: check virgl capabilities max_size
Virtio GPU device while processing 'VIRTIO_GPU_CMD_GET_CAPSET'
command, retrieves the maximum capabilities size to fill in the
response object. It continues to fill in capabilities even if
retrieved 'max_size' is zero(0), thus resulting in OOB access.
Add check to avoid it.

Reported-by: Zhenhao Hong <zhenhaohong@gmail.com>
Signed-off-by: Prasad J Pandit <pjp@fedoraproject.org>
Message-id: 20161214070156.23368-1-ppandit@redhat.com
Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
2016-12-20 14:18:39 +01:00
audio trace-events: fix first line comment in trace-events 2016-08-12 10:36:01 +01:00
backends cryptodev: introduce an unified wrapper for crypto operation 2016-11-01 19:21:08 +02:00
block Block layer patches for 2.8.0-rc3 2016-12-06 17:35:29 +00:00
bsd-user translate-all: add DEBUG_LOCKING asserts 2016-10-31 10:24:45 +01:00
contrib Clean up ill-advised or unusual header guards 2016-07-12 16:20:46 +02:00
crypto crypto: fix initialization of gcrypt threading 2016-10-20 12:19:35 +01:00
default-configs pc: memhp: move nvdimm hotplug out of memory hotplug 2016-11-15 17:20:37 +02:00
disas target-ppc: add vrldnm and vrlwnm instructions 2016-11-15 10:05:50 +11:00
docs spec/vhost-user: fix the VHOST_USER prefix 2016-11-30 04:20:57 +02:00
dtc@65cc4d2748 dtc: Update dtc / libfdt submodule to version 1.4.0 2015-06-03 23:56:49 +02:00
fpu fpu: add mechanism to check for invalid long double formats 2016-09-15 12:43:18 +01:00
fsdev 9pfs: add cleanup operation in FileOperations 2016-11-23 13:53:34 +01:00
gdb-xml target-ppc: gdbstub: Add VSX support 2016-01-30 23:37:38 +11:00
hw display: virtio-gpu-3d: check virgl capabilities max_size 2016-12-20 14:18:39 +01:00
include virtio-pci: Fix cross-version migration with older machines 2016-12-15 07:35:19 +00:00
io io: add ability to set a name for IO channels 2016-10-27 09:13:10 +02:00
libdecnumber libdecnumber: Clean up includes 2016-02-16 14:29:27 +00:00
linux-headers linux-headers: update 2016-09-05 15:15:16 +02:00
linux-user linux-user/elfload: ensure mmap_lock() held while setting up 2016-10-31 10:51:16 +01:00
migration migration: Fix return code of ram_save_iterate() 2016-11-14 19:35:41 +01:00
nbd nbd: Don't inf-loop on early EOF 2016-11-10 16:01:30 +01:00
net net: fix sending of data with -net socket, listen backend 2016-11-15 15:36:21 +08:00
pc-bios Update OpenBIOS images to ef8a14e built from submodule. 2016-11-24 21:26:00 +00:00
pixman@87eea99e44 pixman: update internal copy to pixman-0.32.6 2014-09-15 08:14:19 +02:00
po po: add missing translations in de, fr, it, zh 2016-12-14 18:47:19 +00:00
qapi qapi: Document introduction of gluster's 'debug' option 2016-12-06 20:22:03 +00:00
qga qapi: add missing colon-ending for section name 2016-12-05 17:41:38 +01:00
qobject qdict: implement a qdict_crumple method for un-flattening a dict 2016-10-25 17:56:14 +02:00
qom qapi: rename QmpOutputVisitor to QObjectOutputVisitor 2016-10-25 16:25:54 +02:00
replay replay: allow replay stopping and restarting 2016-09-27 11:57:30 +02:00
roms Update OpenBIOS images to ef8a14e built from submodule. 2016-11-24 21:26:00 +00:00
scripts trace: fix generated code build break 2016-11-18 11:09:58 +00:00
slirp slirp: Fix access to freed memory 2016-11-14 17:36:33 +01:00
stubs tests: send error_report to test log 2016-11-01 16:06:57 +01:00
target-alpha target-alpha: Log cpuid with -d int 2016-11-17 15:56:31 +01:00
target-arm target-arm/translate-a64: fix gen_load_exclusive 2016-12-05 17:52:01 +00:00
target-cris log: Add locking to large logging blocks 2016-11-01 10:29:03 -06:00
target-i386 target-i386: Remove unused local_err variable 2016-11-25 15:12:23 -02:00
target-lm32 log: Add locking to large logging blocks 2016-11-01 10:29:03 -06:00
target-m68k target-m68k: fix muluw/mulsw 2016-11-24 16:24:27 +01:00
target-microblaze target-microblaze: Cleanup dec_mul 2016-11-01 10:30:45 -06:00
target-mips target-mips: fix bad shifts in {dextp|dextpdp} 2016-12-04 00:57:06 +00:00
target-moxie exec: move cpu_exec_init() calls to realize functions 2016-10-24 17:29:16 -02:00
target-openrisc log: Add locking to large logging blocks 2016-11-01 10:29:03 -06:00
target-ppc target-ppc: Allow eventual removal of old migration mistakes 2016-11-23 12:00:48 +11:00
target-s390x s390x/kvm: fix run_on_cpu sigp conversions 2016-11-07 11:25:02 +00:00
target-sh4 log: Add locking to large logging blocks 2016-11-01 10:29:03 -06:00
target-sparc log: Add locking to large logging blocks 2016-11-01 10:29:03 -06:00
target-tilegx log: Add locking to large logging blocks 2016-11-01 10:29:03 -06:00
target-tricore log: Add locking to large logging blocks 2016-11-01 10:29:03 -06:00
target-unicore32 log: Add locking to large logging blocks 2016-11-01 10:29:03 -06:00
target-xtensa log: Add locking to large logging blocks 2016-11-01 10:29:03 -06:00
tcg tcg: correct 32-bit tcg_gen_ld8s_i64 sign-extension 2016-11-01 10:30:45 -06:00
tests tests/.gitignore: Ignore test-char 2016-12-06 20:05:49 +00:00
trace trace: pass trace-events to tracetool as a positional param 2016-10-12 09:54:53 +02:00
ui ui/gtk: fix "Copy" menu item segfault 2016-12-14 18:46:21 +00:00
util hbitmap: Fix shifts of constants by granularity 2016-11-29 17:46:36 +08:00
.dir-locals.el Add .dir-locals.el file to configure emacs coding style 2015-10-08 19:46:01 +03:00
.exrc qemu: add .exrc 2012-09-07 09:02:44 +03:00
.gitignore trivial patches for 2016-10-08 2016-10-10 13:01:43 +01:00
.gitmodules ppc: add skiboot firmware for the pnv platform 2016-10-28 09:36:58 +11:00
.mailmap Update mailmap 2013-09-05 09:40:31 -05:00
.travis.yml .travis.yml: add gcc sanitizer build 2016-10-04 10:00:26 +02:00
accel.c clean-up: removed duplicate #includes 2016-10-28 18:17:24 +03:00
aio-posix.c aio-posix: simplify aio_epoll_update 2016-11-08 17:09:14 +00:00
aio-win32.c aio-posix: remove useless parameter 2016-07-18 15:10:52 +01:00
arch_init.c util: Add UUID API 2016-09-23 11:42:52 +08:00
async.c aio: convert from RFifoLock to QemuRecMutex 2016-10-28 21:50:18 +08:00
atomic_template.h tcg: Add atomic128 helpers 2016-10-26 08:29:01 -07:00
balloon.c all: Clean up includes 2016-02-04 17:41:30 +00:00
block.c block: Emit modules in bdrv_iterate_format() 2016-11-11 15:56:22 +01:00
blockdev-nbd.c nbd: set name for all I/O channels created 2016-10-27 09:13:10 +02:00
blockdev.c blockjob: refactor backup_start as backup_job_create 2016-11-14 22:47:34 -05:00
blockjob.c blockjob: add block_job_start 2016-11-14 22:47:34 -05:00
bootdevice.c error: Remove NULL checks on error_propagate() calls 2016-06-20 16:38:13 +02:00
bt-host.c all: Clean up includes 2016-02-04 17:41:30 +00:00
bt-vhci.c all: Clean up includes 2016-02-04 17:41:30 +00:00
Changelog Use qemu-project.org domain name 2013-10-11 09:34:56 -07:00
CODING_STYLE CODING_STYLE: Fix a typo ("have" vs. "has") 2016-10-08 11:25:29 +03:00
configure rules.mak: Also try -r to build modules 2016-11-29 16:21:05 +00:00
COPYING
COPYING.LIB
cpu-exec-common.c tcg: Add EXCP_ATOMIC 2016-10-26 08:29:00 -07:00
cpu-exec.c log: Add locking to large logging blocks 2016-11-01 10:29:03 -06:00
cpus-common.c *_run_on_cpu: introduce run_on_cpu_data type 2016-10-31 15:00:25 +01:00
cpus.c *_run_on_cpu: introduce run_on_cpu_data type 2016-10-31 15:00:25 +01:00
cputlb.c clean-up: removed duplicate #includes 2016-10-28 18:17:24 +03:00
device_tree.c qemu-common: stop including qemu/bswap.h from qemu-common.h 2016-05-19 16:42:28 +02:00
device-hotplug.c blockdev: Split monitor reference from BB creation 2016-03-17 15:47:56 +01:00
disas.c Remove remainders of HPPA backend 2016-09-15 15:32:22 +03:00
dma-helpers.c dma-helpers: explicitly pass alignment into DMA helpers 2016-10-27 16:29:13 -04:00
dump.c error: Remove NULL checks on error_propagate() calls 2016-06-20 16:38:13 +02:00
exec.c exec.c: Fix breakpoint invalidation race 2016-12-06 20:21:46 +00:00
gdbstub.c clean-up: removed duplicate #includes 2016-10-28 18:17:24 +03:00
HACKING Disable warn about left shifts of negative values 2016-08-09 22:57:36 +02:00
hmp-commands-info.hx intc: make HMP 'info irq' and 'info pic' commands available on all targets 2016-10-04 10:00:25 +02:00
hmp-commands.hx COLO: Add 'x-colo-lost-heartbeat' command to trigger failover 2016-10-30 15:17:39 +05:30
hmp.c migration/next for 20161114 2016-11-15 11:49:46 +00:00
hmp.h COLO: Add 'x-colo-lost-heartbeat' command to trigger failover 2016-10-30 15:17:39 +05:30
iohandler.c iohandler: Introduce iohandler_get_aio_context 2016-04-22 16:43:42 +02:00
ioport.c hw: remove pio_addr_t 2016-05-19 16:42:30 +02:00
iothread.c iothread: release AioContext around aio_poll 2016-10-28 21:50:18 +08:00
kvm-all.c *_run_on_cpu: introduce run_on_cpu_data type 2016-10-31 15:00:25 +01:00
kvm-stub.c kvm-all: Pass requester ID to MSI routing functions 2016-10-04 13:28:09 +01:00
LICENSE vfio: move hw/misc/vfio.c to hw/vfio/pci.c Move vfio.h into include/hw/vfio 2014-12-19 15:24:06 -07:00
main-loop.c main-loop: Suppress I/O thread warning under qtest 2016-11-02 09:28:57 +01:00
MAINTAINERS MAINTAINERS: Remove obsolete stable branches 2016-11-10 15:29:59 +00:00
Makefile trivial patches for 2016-10-28 2016-10-31 11:58:30 +00:00
Makefile.objs tcg: Add atomic helpers 2016-10-26 08:29:01 -07:00
Makefile.target tcg: Add atomic helpers 2016-10-26 08:29:01 -07:00
memory_mapping.c memory: Replace skip_dump flag with "ram_device" 2016-10-31 09:53:03 -06:00
memory.c memory: Don't use memcpy for ram_device regions 2016-10-31 09:53:03 -06:00
module-common.c all: Clean up includes 2016-02-04 17:41:30 +00:00
monitor.c qemu-error: remove dependency of stubs on monitor 2016-11-01 16:06:57 +01:00
numa.c numa: reduce code duplication by adding helper numa_get_node_for_cpu() 2016-10-10 01:16:57 +03:00
os-posix.c use g_path_get_dirname instead of dirname 2016-07-17 09:59:21 +02:00
os-win32.c all: Clean up includes 2016-02-04 17:41:30 +00:00
page_cache.c coccinelle: Remove unnecessary variables for function return value 2016-06-20 16:38:13 +02:00
qapi-schema.json qapi: add missing colon-ending for section name 2016-12-05 17:41:38 +01:00
qdev-monitor.c qdev: add function qdev_set_id() 2016-11-22 10:29:37 -08:00
qdict-test-data.txt
qemu-bridge-helper.c all: Remove unnecessary glib.h includes 2016-06-07 18:19:24 +03:00
qemu-char.c qemu-char: do not forward events through the mux until QEMU has started 2016-11-02 09:28:56 +01:00
qemu-doc.texi qemu-doc: update gluster protocol usage guide 2016-12-05 16:30:29 -05:00
qemu-ga.texi qemu-ga: Remove stray 'q' in documentation 2016-10-28 18:17:23 +03:00
qemu-img-cmds.hx qemu-img: add skip option to dd 2016-09-20 22:10:57 +02:00
qemu-img.c Replication/Blockjobs: Create replication jobs as internal 2016-11-01 07:55:57 -04:00
qemu-img.texi qemu-img: add skip option to dd 2016-09-20 22:10:57 +02:00
qemu-io-cmds.c trivial patches for 2016-10-28 2016-10-31 11:58:30 +00:00
qemu-io.c trace: provide mechanism for registering trace events 2016-10-12 09:52:50 +02:00
qemu-nbd.c nbd: Add qemu-nbd -D for human-readable description 2016-11-02 09:28:55 +01:00
qemu-nbd.texi nbd: Add qemu-nbd -D for human-readable description 2016-11-02 09:28:55 +01:00
qemu-option-trace.texi doc: move text describing --trace to specific .texi file 2016-06-28 21:14:12 +01:00
qemu-options-wrapper.h vl.c: In qemu -h output, only print options for the arch we are running as 2011-12-19 10:27:33 -06:00
qemu-options.h Clean up ill-advised or unusual header guards 2016-07-12 16:20:46 +02:00
qemu-options.hx qemu-doc: update gluster protocol usage guide 2016-12-05 16:30:29 -05:00
qemu-seccomp.c seccomp: adding getrusage to the whitelist 2016-09-21 11:26:02 +02:00
qemu-tech.texi qemu-doc: merge qemu-tech and qemu-doc 2016-10-07 10:05:54 +02:00
qemu-timer.c timer: set vm_clock disabled default 2016-08-09 22:57:36 +02:00
qemu.nsi qemu-doc: merge qemu-tech and qemu-doc 2016-10-07 10:05:54 +02:00
qemu.sasl sasl: Avoid 'Could not find keytab file' in syslog 2014-03-15 13:54:18 +04:00
qmp.c clean-up: removed duplicate #includes 2016-10-28 18:17:24 +03:00
qtest.c char: remove explicit_fe_open, use a set_handlers argument 2016-10-24 15:46:10 +02:00
README qemu-doc: drop installation and compilation notes 2016-10-07 10:05:15 +02:00
replication.c replication: Introduce new APIs to do replication operation 2016-09-13 11:00:56 +01:00
replication.h replication: Introduce new APIs to do replication operation 2016-09-13 11:00:56 +01:00
rules.mak rules.mak: Also try -r to build modules 2016-11-29 16:21:05 +00:00
softmmu_template.h cputlb: Tidy some macros 2016-10-26 08:29:00 -07:00
spice-qemu-char.c char: remove explicit_be_open from CharDriverState 2016-10-24 15:46:11 +02:00
tcg-runtime.c tcg: Add CONFIG_ATOMIC64 2016-10-26 08:29:01 -07:00
tci.c tcg/tci: Add support for fence 2016-09-16 08:12:12 -07:00
thread-pool.c coroutine: move entry argument to qemu_coroutine_create 2016-07-13 13:26:02 +02:00
thunk.c thunk: Rename args and fields in host-target bitmask conversion code 2016-06-07 18:19:24 +03:00
tpm.c qapi: Don't special-case simple union wrappers 2016-03-18 10:29:26 +01:00
trace-events memory: Don't use memcpy for ram_device regions 2016-10-31 09:53:03 -06:00
translate-all.c log: Add locking to large logging blocks 2016-11-01 10:29:03 -06:00
translate-all.h trace: Add per-vCPU tracing states for events with the 'vcpu' property 2016-07-18 18:23:12 +01:00
translate-common.c include: move CPU-related definitions out of qemu-common.h 2016-05-19 13:08:04 +02:00
user-exec.c tcg: Merge GETPC and GETRA 2016-09-16 08:12:11 -07:00
VERSION Update version for v2.8.0-rc4 release 2016-12-15 07:36:03 +00:00
version.rc Use qemu-project.org domain name 2013-10-11 09:34:56 -07:00
vl.c vl.c: move pidfile creation up the line 2016-11-09 14:08:17 +01:00
xen-common-stub.c xen: Clean up includes 2016-01-29 15:07:23 +00:00
xen-common.c xen: Fix xenpv machine initialisation 2016-11-08 11:17:30 -08:00
xen-hvm-stub.c fix MSI injection on Xen 2016-02-06 20:44:10 +02:00
xen-hvm.c xen: ignore direction in bufioreq handling 2016-11-28 11:26:29 -08:00
xen-mapcache.c os-posix: include sys/mman.h 2016-06-16 18:39:03 +02:00

         QEMU README
         ===========

QEMU is a generic and open source machine & userspace emulator and
virtualizer.

QEMU is capable of emulating a complete machine in software without any
need for hardware virtualization support. By using dynamic translation,
it achieves very good performance. QEMU can also integrate with the Xen
and KVM hypervisors to provide emulated hardware while allowing the
hypervisor to manage the CPU. With hypervisor support, QEMU can achieve
near native performance for CPUs. When QEMU emulates CPUs directly it is
capable of running operating systems made for one machine (e.g. an ARMv7
board) on a different machine (e.g. an x86_64 PC board).

QEMU is also capable of providing userspace API virtualization for Linux
and BSD kernel interfaces. This allows binaries compiled against one
architecture ABI (e.g. the Linux PPC64 ABI) to be run on a host using a
different architecture ABI (e.g. the Linux x86_64 ABI). This does not
involve any hardware emulation, simply CPU and syscall emulation.

QEMU aims to fit into a variety of use cases. It can be invoked directly
by users wishing to have full control over its behaviour and settings.
It also aims to facilitate integration into higher level management
layers, by providing a stable command line interface and monitor API.
It is commonly invoked indirectly via the libvirt library when using
open source applications such as oVirt, OpenStack and virt-manager.

QEMU as a whole is released under the GNU General Public License,
version 2. For full licensing details, consult the LICENSE file.


Building
========

QEMU is multi-platform software intended to be buildable on all modern
Linux platforms, OS-X, Win32 (via the Mingw64 toolchain) and a variety
of other UNIX targets. The simple steps to build QEMU are:

  mkdir build
  cd build
  ../configure
  make

Additional information can also be found online via the QEMU website:

  http://qemu-project.org/Hosts/Linux
  http://qemu-project.org/Hosts/W32


Submitting patches
==================

The QEMU source code is maintained under the GIT version control system.

   git clone git://git.qemu-project.org/qemu.git

When submitting patches, the preferred approach is to use 'git
format-patch' and/or 'git send-email' to format & send the mail to the
qemu-devel@nongnu.org mailing list. All patches submitted must contain
a 'Signed-off-by' line from the author. Patches should follow the
guidelines set out in the HACKING and CODING_STYLE files.

Additional information on submitting patches can be found online via
the QEMU website

  http://qemu-project.org/Contribute/SubmitAPatch
  http://qemu-project.org/Contribute/TrivialPatches


Bug reporting
=============

The QEMU project uses Launchpad as its primary upstream bug tracker. Bugs
found when running code built from QEMU git or upstream released sources
should be reported via:

  https://bugs.launchpad.net/qemu/

If using QEMU via an operating system vendor pre-built binary package, it
is preferable to report bugs to the vendor's own bug tracker first. If
the bug is also known to affect latest upstream code, it can also be
reported via launchpad.

For additional information on bug reporting consult:

  http://qemu-project.org/Contribute/ReportABug


Contact
=======

The QEMU community can be contacted in a number of ways, with the two
main methods being email and IRC

 - qemu-devel@nongnu.org
   http://lists.nongnu.org/mailman/listinfo/qemu-devel
 - #qemu on irc.oftc.net

Information on additional methods of contacting the community can be
found online via the QEMU website:

  http://qemu-project.org/Contribute/StartHere

-- End