@samitouri / QOSamiQemu / commits / 2a886bda47

virtio-gpu: use computed rowstride instead of deriving it from hostmem

Since calc_image_hostmem() already computes the stride, return it and use it directly. This is both simpler and more correct. Signed-off-by: Marc-André Lureau <marcandre.lureau@redhat.com> Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp> Message-Id: <20260311-cve-v1-2-f72b4c7c1ab2@redhat.com>

Marc-André Lureau committed Mar 11, 2026 at 01:26 UTC 2a886bda476531566c673d93f28184bbf7bfd890
1 file changed +10 -7
hw/display/virtio-gpu.c
+10 -7
@@ -229,7 +229,7 @@ void virtio_gpu_get_edid(VirtIOGPU *g,
229
230 static bool calc_image_hostmem(pixman_format_code_t pformat,
231 uint32_t width, uint32_t height,
232 - uint32_t *hostmem)
232 + uint32_t *hostmem, uint32_t *rowstride_bytes)
233 {
234 uint64_t bpp = PIXMAN_FORMAT_BPP(pformat);
235 uint64_t stride = (((uint64_t)width * bpp + 0x1f) >> 5) * sizeof(uint32_t);
@@ -240,6 +240,7 @@ static bool calc_image_hostmem(pixman_format_code_t pformat,
240 }
241
242 *hostmem = size;
243 + *rowstride_bytes = stride;
244 return true;
245 }
246
@@ -250,7 +251,7 @@ static void virtio_gpu_resource_create_2d(VirtIOGPU *g,
251 pixman_format_code_t pformat;
252 struct virtio_gpu_simple_resource *res;
253 struct virtio_gpu_resource_create_2d c2d;
253 - uint32_t hostmem;
254 + uint32_t hostmem, rowstride_bytes;
255
256 VIRTIO_GPU_FILL_CMD(c2d);
257 virtio_gpu_bswap_32(&c2d, sizeof(c2d));
@@ -289,7 +290,8 @@ static void virtio_gpu_resource_create_2d(VirtIOGPU *g,
290 return;
291 }
292
292 - if (!calc_image_hostmem(pformat, c2d.width, c2d.height, &hostmem)) {
293 + if (!calc_image_hostmem(pformat, c2d.width, c2d.height,
294 + &hostmem, &rowstride_bytes)) {
295 qemu_log_mask(LOG_GUEST_ERROR, "%s: image dimensions overflow\n",
296 __func__);
297 goto end;
@@ -303,7 +305,7 @@ static void virtio_gpu_resource_create_2d(VirtIOGPU *g,
305 pformat,
306 c2d.width,
307 c2d.height,
306 - c2d.height ? res->hostmem / c2d.height : 0,
308 + rowstride_bytes,
309 &err)) {
310 warn_report_err(err);
311 goto end;
@@ -1302,7 +1304,7 @@ static int virtio_gpu_load(QEMUFile *f, void *opaque, size_t size,
1304 VirtIOGPU *g = opaque;
1305 Error *err = NULL;
1306 struct virtio_gpu_simple_resource *res;
1305 - uint32_t resource_id, pformat, hostmem;
1307 + uint32_t resource_id, pformat, hostmem, rowstride_bytes;
1308 int i, ret;
1309
1310 g->hostmem = 0;
@@ -1328,7 +1330,8 @@ static int virtio_gpu_load(QEMUFile *f, void *opaque, size_t size,
1330 return -EINVAL;
1331 }
1332
1331 - if (!calc_image_hostmem(pformat, res->width, res->height, &hostmem)) {
1333 + if (!calc_image_hostmem(pformat, res->width, res->height,
1334 + &hostmem, &rowstride_bytes)) {
1335 g_free(res);
1336 return -EINVAL;
1337 }
@@ -1339,7 +1342,7 @@ static int virtio_gpu_load(QEMUFile *f, void *opaque, size_t size,
1342 pformat,
1343 res->width,
1344 res->height,
1342 - res->height ? res->hostmem / res->height : 0,
1345 + rowstride_bytes,
1346 &err)) {
1347 warn_report_err(err);
1348 g_free(res);