From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id C31861FF0E5 for ; Wed, 29 Jul 2026 10:41:51 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 8869A2132F; Wed, 29 Jul 2026 10:41:51 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785314481; x=1785919281; darn=lists.proxmox.com; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:from:to:cc:subject:date:message-id:reply-to :content-type; bh=I5PHDp7eVJWNGvReF5glgtEcOxR2LZpsFBsgl4/OGs0=; b=cpZhczfK1KRYZSX3gb4y+X4bqJI/gWbmK5IK6D57ugvZGCjV90v/Wr0GsBssfd/FbO lXf8lng45EbmEcuE+48xQV63yFvzZvKomVZ7qQbnpxXhBdf/HfUX87b4YhbtuX4Rjb8u kwQDIW0LFLB5oVt8saDQWj/YAWejGPGrLiHUgAjnJSJgM/M1FCTOGdUAw/O6r3TbUx9Z +7kEZCu5ZLnTgB5dmWNJ0A1ccDyocaKTVpIXuQNwnpc5OF2xDiEHOF2yL+tQ/9NfFI4k U6ASFoD+loIalboUHb77Fslm4Tci2WcL65QycNgqSyrDLds/m7ka0BV+Nn2DKq6lCCVl 5k8A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785314481; x=1785919281; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=I5PHDp7eVJWNGvReF5glgtEcOxR2LZpsFBsgl4/OGs0=; b=RKSMVqH1hhdtjPWFH3hp5zwp/5xHyeuikMR3EHSRMSHfYMVKAgrgaN7r8i/LDSeDM2 UwBd/jZxDoMvnpDjN2YboIUAOTHZpcaYnK/rFxv5LSi0i7yoPiW63dq3kr3Y5IdIc/uQ riyaBDz6V31sina5peYdgSZ57cf9CLOGQ5C8RFi5et+/Uzg70btJdWHgASJ23v/bi41V SZqjnaT+i0yeYGKpSPNSumepA/02NeVjsl09rwdoMReGtZPopIC9vlEMN5mgWZlRSAyA K+44X/OoKoZl5Y3hY94TlTV6VeJN64WZJ6sHcoc6WjQ0VtgugU7pXq6W+NKZqOrL3JlO qTqQ== X-Forwarded-Encrypted: i=1; AHgh+RqxHvBzEmIrWelOhGFEpbGv/Z1pFARq4Kbv9JZpWlgOrj9uqsy+dlONgzIpYOiEOUqhj66Px1jCoRo=@lists.proxmox.com X-Gm-Message-State: AOJu0YzsM4ixi7Mbr4Y45pO4sPsB6/GsZJ25fYwvxSDi+masB4g+j7cE WJAXmp2LP5voSUOLJGzCSMza1CvcW5Tteylh+A6RgF7xo5MELtQwLJYM X-Gm-Gg: AR+sD13Cuf12qFcU+5ET6xMSP6oHxEpEsDwQpnuFZffzRVIUfPi81XaVduEWfRZE0CT 8NrKtV+Sb/6e1svilS5D+tDQErVnJ6SKlloDwnjPgz3gVcoOh5q8NSDygMe71cB9aprJVkPuf9u nESfPyqyz/zFz108WQrRHLBv6f3PiKT433j5Cxhf7u6mK1an7iiKQWCwxwK2gUr9pwIOC1jEjK/ 0Rt9rBiXppi+8B1ualNt+7wk08ppLgxfVuyaNV/l8xUqDExZpu0g8ZvRzauJnnVQyGat8uoAnC+ I1qFYHmZcdDSxjhT4WxTsbHiQXMzisV9VgPgtKGWeE1RDOjf2rtPxgkWcYQj9+BqaingqTvWif7 dopstqNIUfGx23eZt7H35fGjVusZGTHZM9zfFaPS7giNsKxq1D4jwjpxwKuxtvRVrZEwpywbVDd j1U/FSQYX1NmtXz9DMZXTNo4QwEK4wg+CrWLFXUs2z5YpSOTttbxIxxYp+UOyoRamNxQj04hHGz 9oftsoxXfvgh1X5ug== X-Received: by 2002:a17:90b:2692:b0:38e:2aa8:60d0 with SMTP id 98e67ed59e1d1-38f6a567423mr6141389a91.37.1785314481209; Wed, 29 Jul 2026 01:41:21 -0700 (PDT) Message-ID: <105b4d4d-440d-4a7b-a305-2ad3019820e4@gmail.com> Date: Wed, 29 Jul 2026 16:41:17 +0800 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH qemu-server] query-machine-capabilities: check vendor string length for strncmp To: =?UTF-8?Q?Fabian_Gr=C3=BCnbichler?= , pve-devel@lists.proxmox.com References: <20260603055031.106241-1-wukaiyang@loongfans.cn> <1783951945.bjj3it71oe.astroid@yuna.none> Content-Language: en-US From: Kaiyang Wu In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 0 AWL 0.000 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy FREEMAIL_ENVFROM_END_DIGIT 1 Envelope-from freemail username ends in digit FREEMAIL_FROM 0.001 Sender email is commonly abused enduser mail provider RCVD_IN_DNSWL_NONE -0.0001 Sender listed at https://www.dnswl.org/, no trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: ZGEZ6XNW4V7JOZ5TXJFKKNCFH4UZUEQ2 X-Message-ID-Hash: ZGEZ6XNW4V7JOZ5TXJFKKNCFH4UZUEQ2 X-MailFrom: wukaiyang2003@gmail.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Kaiyang Wu X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Gentle ping. Kaiyang On 2026-07-16 10:31, Kaiyang Wu wrote: > Intel TDX and AMD SEV are both x86_64 only extensions [0] [1]. I wonder > if the best approach for this issue is to just add a conditional > compilation check for x86_64 target architecture. > > If that works I will switch to compile time architecture check in v2. > > [0]: https://docs.kernel.org/arch/x86/tdx.html > [1]: https://docs.kernel.org/virt/kvm/x86/amd-memory-encryption.html > > On 2026-07-13 22:15, Fabian Grünbichler wrote: >> On June 3, 2026 7:50 am, Kaiyang Wu wrote: >>> Fix build error on unknown vendors ('fallback'): >>> >>>     error: ‘strncmp’ of strings of length 7 and 12 and bound of 12 >>> evaluates to nonzero [-Werror=string-compare] >>> >>> Signed-off-by: Kaiyang Wu >>> --- >>>   src/query-machine-capabilities/query-machine-capabilities.c | 4 ++-- >>>   1 file changed, 2 insertions(+), 2 deletions(-) >>> >>> diff --git a/src/query-machine-capabilities/query-machine- >>> capabilities.c b/src/query-machine-capabilities/query-machine- >>> capabilities.c >>> index abb47acd..25d06db7 100644 >>> --- a/src/query-machine-capabilities/query-machine-capabilities.c >>> +++ b/src/query-machine-capabilities/query-machine-capabilities.c >>> @@ -204,7 +204,7 @@ int main() { >>>           eprintf("Error writing to file '" OUTPUT_PATH "': %s\n", >>> strerror(errno)); >>>       } >>> -    if (strncmp(vendor, "AuthenticAMD", 12) == 0) { >>> +    if (strncmp(vendor, "AuthenticAMD", strnlen(vendor, 12)) == 0) { >> >> this is wrong - if the vendor is "Authentic" the code would now think >> it's AMD.. the same would be true if vendor is "AuthenticAMDsomething", >> because it would only look at the first 12 bytes (granted, that is a >> pre-existing issue ;)). >> >> instead, we'd first need to check for the length, and if it is 12, do >> the existing checks, if not, either add checks for other vendors, or >> reject/abort.. >> >>>           cpu_caps_amd_sev_t caps_sev; >>>           query_cpu_capabilities_sev(&caps_sev); >>> @@ -222,7 +222,7 @@ int main() { >>>               caps_sev.sev_es_support ? "true" : "false", >>>               caps_sev.sev_snp_support ? "true" : "false" >>>           ); >>> -    } else if (strncmp(vendor, "GenuineIntel", 12) == 0) { >>> +    } else if (strncmp(vendor, "GenuineIntel", strnlen(vendor, 12)) >>> == 0) { >> >> same applies here, but with `Genuine` (or any other substring prefix of >> `GenuineIntel`).. >> >>>           cpu_caps_intel_tdx_t caps_tdx; >>>           if (query_cpu_capabilities_tdx(&caps_tdx) == 0) { >>>               ret = fprintf(file, >>> -- >>> 2.52.0 >>> >>> >>> >>> >>> >> >