Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [High] virtio-gpu: guest-only blob flags leaked to host breaking wire ABI
--

commit ce150cb1a68528e491d40b28c03376311a653c0c
Author: Honglei Huang <[email protected]>

drm/virtgpu api: add blob userptr resource

This commit adds DRM ioctl flags and a userptr field to allow userspace
to request a blob backed by an existing process mapping. It introduces
guest-only flags VIRTGPU_BLOB_FLAG_USE_USERPTR and
VIRTGPU_BLOB_FLAG_USERPTR_RDONLY for guest pin behavior.

> diff --git a/include/uapi/drm/virtgpu_drm.h b/include/uapi/drm/virtgpu_drm.h
> index 95587e12aed57..6171b4e2300b1 100644
> --- a/include/uapi/drm/virtgpu_drm.h
> +++ b/include/uapi/drm/virtgpu_drm.h
> @@ -186,6 +186,9 @@ struct drm_virtgpu_resource_create_blob {
>  #define VIRTGPU_BLOB_FLAG_USE_MAPPABLE     0x0001
>  #define VIRTGPU_BLOB_FLAG_USE_SHAREABLE    0x0002
>  #define VIRTGPU_BLOB_FLAG_USE_CROSS_DEVICE 0x0004
> +/* Guest-only flags */
> +#define VIRTGPU_BLOB_FLAG_USE_USERPTR      0x0008
> +#define VIRTGPU_BLOB_FLAG_USERPTR_RDONLY   0x0010

[Severity: High]
Do these guest-only flags leak to the host and break the virtio wire ABI?

When userspace calls the DRM_IOCTL_VIRTGPU_RESOURCE_CREATE_BLOB ioctl,
verify_blob() assigns rc_blob->blob_flags directly to params->blob_flags.
This struct is passed to virtio_gpu_userptr_create(), which calls
virtio_gpu_cmd_resource_create_blob().

In virtio_gpu_cmd_resource_create_blob(), the flags are written directly to
the command without masking:

drivers/gpu/drm/virtio/virtgpu_vq.c:virtio_gpu_cmd_resource_create_blob() {
    ...
    cmd_p->blob_flags = cpu_to_le32(params->blob_flags);
    ...
}

If these guest-only flags are not masked out before being sent to the host,
will strict hosts reject the command with an error, making the userptr
feature unusable? 

I noticed this wire ABI violation appears to remain unfixed at the end of
the patch series (commit 357076bf581c).

[ ... ]

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=2

Reply via email to