On Mon, 2012-08-13 at 12:02 +0300, Michael S. Tsirkin wrote:
> On Mon, Aug 13, 2012 at 08:35:17AM +0000, Nicholas A. Bellinger wrote:
> > From: Nicholas Bellinger <[email protected]>
> >
> > This patch fixes bug in the definition of VirtIOSCSI->cmd_vqs[0],
> > where the return of virtio_add_queue() in virtio_scsi_init() ends up
> > overwriting past the end of ->cmd_vqs[0].
> >
> > Since virtio_scsi currently assumes a single vqs for data, this patch
> > simply changes ->cmd_vqs[1] to handle the single VirtQueue.
> >
> > Cc: Paolo Bonzini <[email protected]>
> > Cc: Stefan Hajnoczi <[email protected]>
> > Cc: Michael S. Tsirkin <[email protected]>
> > Signed-off-by: Nicholas Bellinger <[email protected]>
>
> This is a bugfix we need even without vhost, right?
>
I believe so, as it appears to be stomping past the end of memory for
every virtio-scsi initialization regardless of vhost usage..
Paolo, can you pickup this fix now for stable so it can be dropped from
RFC-v3..?
--nab
> > ---
> > hw/virtio-scsi.c | 2 +-
> > 1 files changed, 1 insertions(+), 1 deletions(-)
> >
> > diff --git a/hw/virtio-scsi.c b/hw/virtio-scsi.c
> > index 5e2ff6b..2c70f89 100644
> > --- a/hw/virtio-scsi.c
> > +++ b/hw/virtio-scsi.c
> > @@ -150,7 +150,7 @@ typedef struct {
> > bool events_dropped;
> > VirtQueue *ctrl_vq;
> > VirtQueue *event_vq;
> > - VirtQueue *cmd_vqs[0];
> > + VirtQueue *cmd_vqs[1];
> >
> > bool vhost_started;
> > VHostSCSI *vhost_scsi;
> > --
> > 1.7.2.5
> --
> To unsubscribe from this list: send the line "unsubscribe target-devel" in
> the body of a message to [email protected]
> More majordomo info at http://vger.kernel.org/majordomo-info.html
_______________________________________________
Virtualization mailing list
[email protected]
https://lists.linuxfoundation.org/mailman/listinfo/virtualization