FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

[drivers][virtio] Reject invalid input offsets without overflow by manyangshen · Pull Request #11826 · RT-Thread/rt-thread · GitHub

[drivers][virtio] Reject invalid input offsets without overflow - #11826

Open
manyangshen wants to merge 2 commits into
RT-Thread:masterfrom
manyangshen:fix/virtio-input-offset-validation
Open

manyangshen wants to merge 2 commits into
RT-Thread:masterfrom
manyangshen:fix/virtio-input-offset-validation

Conversation

manyangshen commented Sep 22, 2026
edited
Loading

Copy link
Copy Markdown

拉取/合并请求描述:(PR description)

Legacy virtio-input read/write check pos + size before indexing the event array. Mixing a signed offset with an unsigned length allows a negative offset or an overflowing length to pass that check.

Reject negative and out-of-range offsets first, then compare the length with the remaining queue range using subtraction. Keep the existing strict range convention and return values; this change does not redefine the API's event-index/byte-count units.

Fixes #10379.
Fixes #10380.

Validation

GCC 16.1 tests compile the complete read/write bodies against repository virtio headers. Negative offsets, overflowing lengths, null buffers and boundary cases pass. Exhaustive small nonnegative inputs confirm that request acceptance is unchanged. A copy adapter detects invalid copies without executing them; the original code fails the regression cases.

Changed-line clang-format and git diff --check pass. No target BSP, QEMU or actual ISR/mutex scheduling test was run.

当前拉取/合并请求的状态 Intent for your PR

必须选择一项 Choose one (Mandatory):

  • 本拉取/合并请求是一个草稿版本 This PR is for a code-review and is intended to get feedback
  • 本拉取/合并请求是一个成熟版本 This PR is mature, and ready to be integrated into the repo

代码质量 Code Quality:

我在这个拉取/合并请求中已经考虑了 As part of this pull request, I've considered the following:

  • 已经仔细查看过代码改动的对比 Already check the difference between PR and old code
  • 代码风格正确,包括缩进空格,命名及其他风格 Style guide is adhered to, including spacing, naming and other styles
  • 没有垃圾代码,代码尽量精简,不包含#if 0代码,不包含已经被注释了的代码 All redundant code is removed and cleaned up
  • 所有变更均有原因及合理的,并且不会影响到其他软件组件代码或BSP All modifications are justified and not affect other components or BSP
  • 对难懂代码均提供对应的注释 I've commented appropriately where code is tricky
  • 代码是高质量的 Code in this PR is of high quality
  • 已经使用clang-format 源码格式化工具确保格式符合RT-Thread代码规范 This PR has been formatted with clang-format and complies with RT-Thread code specification
  • 如果是新增bsp, 已经添加ci检查到.github/ALL_BSP_COMPILE.json 详细请参考链接BSP自查

CLAassistant commented Sep 22, 2026
edited
Loading

Copy link
Copy Markdown


All committers have signed the CLA.

Copy link
Copy Markdown

👋 感谢您对 RT-Thread 的贡献!Thank you for your contribution to RT-Thread!

为确保代码符合 RT-Thread 的编码规范,请在你的仓库中执行以下步骤运行代码格式化工作流(如果格式化CI运行失败)。
To ensure your code complies with RT-Thread's coding style, please run the code formatting workflow by following the steps below (If the formatting of CI fails to run).


🛠 操作步骤 | Steps

  1. 前往 Actions 页面 | Go to the Actions page
    点击进入工作流 → | Click to open workflow →

  2. 点击 Run workflow | Click Run workflow

  • Use workflow from 保持默认分支(通常为 master)
    Keep the default branch (usually master) in Use workflow from
  • 在 branch 输入框填写 PR 分支 fix/virtio-input-offset-validation
    Enter PR branch fix/virtio-input-offset-validation in the branch field
  • 设置需排除的文件/目录(目录请以"/"结尾)
    Set files/directories to exclude (directories should end with "/")
  1. 等待工作流完成 | Wait for the workflow to complete
    格式化后的代码将作为独立提交推送至你的分支。
    The formatting changes will be pushed to your branch as a separate commit.

完成后,提交将自动更新至 fix/virtio-input-offset-validation 分支,关联的 Pull Request 也会同步更新。
Once completed, commits will be pushed to the fix/virtio-input-offset-validation branch automatically, and the related Pull Request will be updated.

如有问题欢迎联系我们,再次感谢您的贡献!💐
If you have any questions, feel free to reach out. Thanks again for your contribution!

github-actions Bot commented Sep 22, 2026
edited
Loading

Copy link
Copy Markdown

📌 Code Review Assignment

🏷️ Tag: components

Reviewers: @Maihuanyi

Changed Files (Click to expand)
  • components/legacy/virtio/virtio_input.c

📊 Current Review Status (Last Updated: 2026-09-23 09:31 CST)


📝 Review Instructions

  1. 维护者可以通过单击此处来刷新审查状态: 🔄 刷新状态
    Maintainers can refresh the review status by clicking here: 🔄 Refresh Status

  2. 确认审核通过后评论 LGTM/lgtm
    Comment LGTM/lgtm after confirming approval

  3. PR合并前需至少一位维护者确认
    PR must be confirmed by at least one maintainer before merging

ℹ️ 刷新CI状态操作需要具备仓库写入权限。
ℹ️ Refresh CI status operation requires repository Write permission.

manyangshen force-pushed the fix/virtio-input-offset-validation branch from 6bc961c to 0b941b9 Compare September 22, 2026 10:48
Reject negative event offsets and compare against the remaining queue range using subtraction. Preserve the existing strict range convention and read/write return behavior for valid requests.

Fixes RT-Thread#10379 and RT-Thread#10380
Name the queue bound and validate the offset before subtracting it. This keeps the accepted request range unchanged while following the order in which a reader checks an indexed copy.
manyangshen force-pushed the fix/virtio-input-offset-validation branch from 0b941b9 to 252fe1e Compare September 23, 2026 01:30
manyangshen marked this pull request as ready for review September 23, 2026 01:39

This branch has not been deployed

No deployments
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters. Learn more about bidirectional Unicode characters
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] Out of bounds read in virtio_input driver [Bug] Out of bounds write in virtio_input driver

2 participants


Back | FazBrowse Home | New Git URL