Skip to content

virtio/console: validate control transmit messages - #3

Merged
dills122 merged 2 commits into
mainfrom
codex/upstream-console-control-validation
Aug 5, 2026
Merged

dills122 merged 2 commits into
mainfrom
codex/upstream-console-control-validation

Conversation

@dills122

@dills122 dills122 commented Aug 5, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • reject guest control messages that reference unknown console port IDs before port or queue access
  • validate complete control transmit descriptor chains and accept modern scatter/gather layouts totaling exactly one eight-byte message
  • return every popped control transmit chain once with used length zero
  • add queue-path regression coverage for valid, invalid, and malformed control inputs

Why

The control transmit path reads an eight-byte object from the head descriptor address without validating the guest-supplied port ID, descriptor direction, declared length, chained layout, or guest memory ranges. Unknown port IDs can reach unchecked port and queue indexing, while malformed or unreadable inputs can be processed outside their declared bounds or left uncompleted.

This change uses the established descriptor Reader, preserves valid control-event behavior, and treats malformed input as a local robustness failure without adding guest-visible side effects.

Validation

  • cargo fmt -- --check

  • cd examples && cargo fmt -- --check

  • cd tests && cargo fmt -- --check

  • xcrun clang-format -n -Werror over init/**/*.{c,h}

  • python3 .github/scripts/check-ai-trailers.py c652b56ca6fe28a038bf4be5beb39fa54b4247c0

  • cargo clippy --locked -- -D warnings on macOS arm64 with the fixed empty init fixture

  • cargo test on macOS arm64 with the fixed empty init fixture

  • focused krun-devices tests pass independently at each commit

  • fork CI passed AI trailers, formatting, Linux x86_64/aarch64 code quality, macOS code quality, Linux x86_64 units, Linux x86_64 examples, macOS cross-compilation, and Linux-to-FreeBSD cross-compilation

  • self-hosted Linux aarch64 unit/examples jobs remain queued because the fork has no matching runner available

  • the unrestricted integration workflow was intentionally canceled; only the fixed multiport-console guest case is authorized for this preparation

  • the fixed multiport-console integration case passed twice on macOS arm64/HVF, including one retained-artifact run: OK - 1/1 passed

  • the local runner used an explicit Xcode libclang loader path, the Makefile's aarch64 musl cross-linker flags, and a task-local dylib built from the official libkrunfw v5.5.0 prebuilt aarch64 source bundle

Review status

This fork-local PR is preparation-only. It is intentionally missing human Signed-off-by trailers until the human contributor reviews the changes and explicitly accepts DCO responsibility. It must not be submitted upstream before that review and separate authorization.

Shutdown/output handling, duplicate PORT_OPEN, PR libkrun#739 notification behavior, partial writes, and FD lifetime/flags are out of scope.

Guest control messages currently index ports and derived queues without validating the supplied port ID. Reject unknown PORT_READY and PORT_OPEN IDs before any port or queue access so malformed guest input cannot panic the VMM or change console state.

Complete driver-to-device control chains with a used length of zero because the device does not write into them.

Assisted-by: Codex:gpt-5.6-sol
The control transmit path currently reads an object from the head address without validating descriptor direction, declared length, chained layout, or guest memory ranges. That can read outside the driver-declared buffer and leave unreadable elements stranded.

Validate the complete readable chain, accept scatter/gather layouts totaling exactly one control message, reject writable or malformed chains, and parse through the established descriptor Reader. Return every popped chain once with no device-written bytes.

Assisted-by: Codex:gpt-5.6-sol
@dills122
dills122 marked this pull request as ready for review August 5, 2026 13:21
@dills122
dills122 merged commit 1622c9f into main Aug 5, 2026
11 of 14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant