On 01/18/2018 06:51 PM, Claudio Imbrenda wrote: > Fix storage attribute migration so that it does not fail for guests > with more than a few GB of RAM. > With such guests, the index in the buffer would go out of bounds, > usually by large amounts, thus receiving -EFAULT from the kernel. > Migration itself would be successful, but storage attributes would then > not be migrated completely. > > This patch fixes the out of bounds access, and thus migration of all > storage attributes when the guest have large amounts of memory. > > Signed-off-by: Claudio Imbrenda <imbre...@linux.vnet.ibm.com> > Fixes: 903fd80b03243476 ("s390x/migration: Storage attributes device")
Cc: stable ? Reviewed-by: Christian Borntraeger <borntrae...@de.ibm.com> > --- > hw/s390x/s390-stattrib-kvm.c | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) > > diff --git a/hw/s390x/s390-stattrib-kvm.c b/hw/s390x/s390-stattrib-kvm.c > index 41770a7..480551c 100644 > --- a/hw/s390x/s390-stattrib-kvm.c > +++ b/hw/s390x/s390-stattrib-kvm.c > @@ -116,7 +116,7 @@ static void > kvm_s390_stattrib_synchronize(S390StAttribState *sa) > for (cx = 0; cx + len <= max; cx += len) { > clog.start_gfn = cx; > clog.count = len; > - clog.values = (uint64_t)(sas->incoming_buffer + cx * len); > + clog.values = (uint64_t)(sas->incoming_buffer + cx); > r = kvm_vm_ioctl(kvm_state, KVM_S390_SET_CMMA_BITS, &clog); > if (r) { > error_report("KVM_S390_SET_CMMA_BITS failed: %s", > strerror(-r)); > @@ -126,7 +126,7 @@ static void > kvm_s390_stattrib_synchronize(S390StAttribState *sa) > if (cx < max) { > clog.start_gfn = cx; > clog.count = max - cx; > - clog.values = (uint64_t)(sas->incoming_buffer + cx * len); > + clog.values = (uint64_t)(sas->incoming_buffer + cx); > r = kvm_vm_ioctl(kvm_state, KVM_S390_SET_CMMA_BITS, &clog); > if (r) { > error_report("KVM_S390_SET_CMMA_BITS failed: %s", > strerror(-r)); >