@samitouri / QOSamiQemu / commits / bf7f2ee96f

target/loongarch/kvm: fix uninitialized val and unchecked GET in cpucfg2 check

kvm_check_cpucfg2() discards the return value of KVM_GET_DEVICE_ATTR and uses the local val (the host cpucfg2 mask) without checking whether the read succeeded. val is also declared without an initializer, so on a GET failure env->cpucfg[2] &= val reads an uninitialized value. The &= mask is best-effort feature negotiation: if KVM_HAS_DEVICE_ATTR succeeds, a GET failure is most likely a copy_{from,to}_user issue, not a reason to fail the whole register sync. Check the GET return value, warn and skip the mask on failure (the guest keeps the cpucfg2 it already has), and initialize val to 0. Signed-off-by: Tao Cui <cuitao@kylinos.cn> Reviewed-by: Bibo Mao <maobibo@loongson.cn> Message-ID: <20260626052742.810726-2-cui.tao@linux.dev> Signed-off-by: Song Gao <gaosong@loongson.cn>

Tao Cui committed Jun 26, 2026 at 13:27 UTC bf7f2ee96faee0b6834f570129b97c8f15bd20ec
1 file changed +12 -3
target/loongarch/kvm/kvm.c
+12 -3
@@ -725,7 +725,7 @@ static int kvm_loongarch_get_cpucfg(CPUState *cs)
725 static int kvm_check_cpucfg2(CPUState *cs)
726 {
727 int ret;
728 - uint64_t val;
728 + uint64_t val = 0;
729 struct kvm_device_attr attr = {
730 .group = KVM_LOONGARCH_VCPU_CPUCFG,
731 .attr = 2,
@@ -736,8 +736,17 @@ static int kvm_check_cpucfg2(CPUState *cs)
736 ret = kvm_vcpu_ioctl(cs, KVM_HAS_DEVICE_ATTR, &attr);
737
738 if (!ret) {
739 - kvm_vcpu_ioctl(cs, KVM_GET_DEVICE_ATTR, &attr);
740 - env->cpucfg[2] &= val;
739 + /*
740 + * The &= mask is best-effort feature negotiation. If HAS succeeded,
741 + * a GET failure is most likely a copy_{from,to}_user issue; warn and
742 + * keep the cpucfg2 the guest already has rather than failing the sync.
743 + */
744 + int r = kvm_vcpu_ioctl(cs, KVM_GET_DEVICE_ATTR, &attr);
745 + if (r) {
746 + warn_report("CPUCFG2: KVM_GET_DEVICE_ATTR: %s", strerror(errno));
747 + } else {
748 + env->cpucfg[2] &= val;
749 + }
750
751 if (FIELD_EX32(env->cpucfg[2], CPUCFG2, FP)) {
752 /* The FP minimal version is 1. */