AMD General

This part need some input from maintainer, these flags do not seem to have 
effect on the QEMU side.

-----Original Message-----
From: [email protected] <[email protected]>
Sent: Thursday, September 17, 2026 6:35 PM
To: Huang, Honglei1 <[email protected]>
Cc: Michael S. Tsirkin <[email protected]>; [email protected]; 
[email protected]; Eugenio Perez <[email protected]>
Subject: Re: [PATCH v6 2/4] drm/virtgpu api: add blob userptr resource

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [High] virtio-gpu: guest-only blob flags leaked to host breaking wire ABI
--

commit ce150cb1a68528e491d40b28c03376311a653c0c
Author: Honglei Huang <[email protected]>

drm/virtgpu api: add blob userptr resource

This commit adds DRM ioctl flags and a userptr field to allow userspace to 
request a blob backed by an existing process mapping. It introduces guest-only 
flags VIRTGPU_BLOB_FLAG_USE_USERPTR and VIRTGPU_BLOB_FLAG_USERPTR_RDONLY for 
guest pin behavior.

> diff --git a/include/uapi/drm/virtgpu_drm.h
> b/include/uapi/drm/virtgpu_drm.h index 95587e12aed57..6171b4e2300b1
> 100644
> --- a/include/uapi/drm/virtgpu_drm.h
> +++ b/include/uapi/drm/virtgpu_drm.h
> @@ -186,6 +186,9 @@ struct drm_virtgpu_resource_create_blob {
>  #define VIRTGPU_BLOB_FLAG_USE_MAPPABLE     0x0001
>  #define VIRTGPU_BLOB_FLAG_USE_SHAREABLE    0x0002
>  #define VIRTGPU_BLOB_FLAG_USE_CROSS_DEVICE 0x0004
> +/* Guest-only flags */
> +#define VIRTGPU_BLOB_FLAG_USE_USERPTR      0x0008
> +#define VIRTGPU_BLOB_FLAG_USERPTR_RDONLY   0x0010

[Severity: High]
Do these guest-only flags leak to the host and break the virtio wire ABI?

When userspace calls the DRM_IOCTL_VIRTGPU_RESOURCE_CREATE_BLOB ioctl,
verify_blob() assigns rc_blob->blob_flags directly to params->blob_flags.
This struct is passed to virtio_gpu_userptr_create(), which calls 
virtio_gpu_cmd_resource_create_blob().

In virtio_gpu_cmd_resource_create_blob(), the flags are written directly to the 
command without masking:

drivers/gpu/drm/virtio/virtgpu_vq.c:virtio_gpu_cmd_resource_create_blob() {
    ...
    cmd_p->blob_flags = cpu_to_le32(params->blob_flags);
    ...
}

If these guest-only flags are not masked out before being sent to the host, 
will strict hosts reject the command with an error, making the userptr feature 
unusable?

I noticed this wire ABI violation appears to remain unfixed at the end of the 
patch series (commit 357076bf581c).

[ ... ]

--
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=2

Reply via email to