Skip to content

virtio/console: validate guest control messages - #5

Closed
dills122 wants to merge 2 commits into
proof/upstream-main-07fd40dcf6dafrom
codex/virtio-console-control-validation-07fd40dc
Closed

dills122 wants to merge 2 commits into
proof/upstream-main-07fd40dcf6dafrom
codex/virtio-console-control-validation-07fd40dc

Conversation

@dills122

@dills122 dills122 commented Aug 5, 2026

Copy link
Copy Markdown
Collaborator

Summary

Harden virtio-console driver-to-device control handling. Reject unknown port IDs before port access, and validate the complete descriptor chain before processing a control message.

What Changed

  • Accept an exact 8-byte readable control message in one contiguous or multiple split descriptors.
  • Reject malformed, short, trailing, writable, mixed-direction, unsupported-flag, looped, oversized, and invalid-memory chains.
  • Complete every popped control chain exactly once with a used length of 0.
  • Add queue-path unit tests for valid messages, malformed chains, and unknown port IDs.

Validation

  • cargo fmt -- --check in the root, examples, and tests workspaces.
  • cargo test --locked -p krun-devices at each logical commit: 48/48 and 51/51 unit tests passed; doc-tests passed.
  • cargo test --locked -p krun-devices virtio::console::device::tests: 4/4 focused tests passed.
  • cargo clippy --locked -p krun-devices -- -D warnings.
  • python3 .github/scripts/check-ai-trailers.py proof/upstream-main-07fd40dcf6da.
  • Prior macOS arm64/HVF multiport-console guest regression passed twice against identical console, queue, and descriptor implementation bytes; it was not rerun for this proof rebase.

Official workspace/GPU clippy was not completed locally because the host lacks libclang.dylib and epoxy.pc. Changed-crate clippy passes.

Scope Notes

  • This draft targets an exact fork-local mirror of official libkrun/libkrun main at 07fd40dcf6da8e14dd47e16a535531f0383fe52c.
  • Human DCO review and Signed-off-by amendments remain required before any upstream submission.
  • No official upstream pull request or issue has been created.

Guest control messages currently index ports and derived queues without validating the supplied port ID. Reject unknown PORT_READY and PORT_OPEN IDs before any port or queue access so malformed guest input cannot panic the VMM or change console state.

Complete driver-to-device control chains with a used length of zero because the device does not write into them.

Assisted-by: Codex:gpt-5.6-sol
The control transmit path currently reads an object from the head address without validating descriptor direction, declared length, chained layout, or guest memory ranges. That can read outside the driver-declared buffer and leave unreadable elements stranded.

Validate the complete readable chain, accept scatter/gather layouts totaling exactly one control message, reject writable or malformed chains, and parse through the established descriptor Reader. Return every popped chain once with no device-written bytes.

Assisted-by: Codex:gpt-5.6-sol
@dills122 dills122 closed this Aug 6, 2026
@dills122
dills122 deleted the codex/virtio-console-control-validation-07fd40dc branch August 6, 2026 00:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant