From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id B96691FF0E5 for ; Wed, 29 Jul 2026 13:13:25 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 8728421353; Wed, 29 Jul 2026 13:13:25 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785323578; x=1785928378; darn=lists.proxmox.com; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:from:to:cc:subject:date:message-id:reply-to :content-type; bh=oq7orI4tkwzdH+iddOyJdt1n0fhyIhiMD1wJWsUPrJ8=; b=WbsYPeXhr96ZEF6LG9CXffEaS+8fAX0K+6KezhkVm2Tw1LhCnEqzuKIygKdQDl3qOD idgUTLIIj5lS8lO9AhFXwOZ3mtxYQjRn6SYSKQLy6QauOc76A0If91B1xZIAc+JOWsta laiuckBeckQ+X2kFH20qnkDM8Dn+2NCVqsLX3Euk7iJUx2ZhrJr71lMkEEu4BD5CpwUI Evv3HVWraH4ouoJQSP+muVhxNb/nVaFMdm9bGZcmXsBj7mW2RU9vc3xzV/c8xpESXyVA 5FpS0hPbTAWu/pO+AyEdWqwCpi/+3lCWifqIqk3dCfMZ3l4YB88mVzHpxEwPOIaGVUrx XV1g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785323578; x=1785928378; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=oq7orI4tkwzdH+iddOyJdt1n0fhyIhiMD1wJWsUPrJ8=; b=DHDJyi6mke1Ic0k8OS0YHKH3TtVMMxOpBqEp4hiw7lKydJalrNCOVCJKNHVZEYQNyr hHzcExkup6XfbFK1gBjc7WhzMIwN453TteACYemsD10ox7MIrnnlqPvQnLBW5EEU3WLK ep7kIOjol5ntKSDo3yyV6kg1EvULjOHmA6Tv9uCNF9IS7c0irYyEallX9cnxTvVGPAQy WZgpEhNY6kdgcjpIZDm/jPXP0VX4gCkt5II0745t1thvSS1ne4RASw9bE4KvSDk44GLr CMgVxMt8+hbI6+eU7AHLBjD9WgikKpO6/lqfSGzDRABHI5TVKVLUvpJnhwqcyPPy95hN eT7w== X-Forwarded-Encrypted: i=1; AHgh+RqQRgFZUeRkbK9fBBzjyywHL2Qj4fjuNyusdGlgyKx5QHokxcByuBfYvXsZz980crCGjYAmj0tXI0E=@lists.proxmox.com X-Gm-Message-State: AOJu0YzP66c3cRGf5cU6mCt/8IwVDh0/SZyfFImiXwPWp31fkYSRiiyK zGCFhzxL2/ALqQPePSUhlXqBCiF69xDd5T/Hdq/LoqWeLvrlQHK9sbLY X-Gm-Gg: AR+sD10uk00ohzOyRxy2vuiVpqBtBn6Q8E1DbFa1QMryDcWBmMnq7EMjo63QI81jPev nlCTjtSYEx0spnb2azTt2ND6ZqmKYUWXQIk2DMUwVLQ5pkrUg45YFk3xM7T7yRP7Cp6iePhXaeh LmvyvIR9ztpCrXopvV9QW9mTFGmZPxUpPhCYF1MAx5N/trNIVNOgGPrhlcKed9+c2pRxGo3alAD YkgzC9bdFz5irUGZnlTsnhKRLkwskg4FVId10h555aJ20xag3BQh9n+NoO99iofSMVAbRbC8IqY bJJnMfK+Zj3m156ahUKbXfntmMYmWzKaOUy/hHtL5YJDq9CEtxSUao7GFQIKTlg8HMe7cR574Bb PPAaLS2d/zYee/Lwa4eMei4K+34X2fjR2swBy2GTeLbXfVx8POfLQO9ifRDHNATAvsFTn1AhJwo 3KwAOS6unelIrsX6WiBz4j4TYnwJz3jF6oMD4JC7onOK2LF94/szAuT8VLcAmDBizXaRbVyV+Qq ayTdW6mIUTm/13eTw== X-Received: by 2002:a17:902:fa10:b0:2cf:b9f9:18bb with SMTP id d9443c01a7336-2d0266889b1mr11637715ad.4.1785323577774; Wed, 29 Jul 2026 04:12:57 -0700 (PDT) Message-ID: <2354a528-3abe-4f09-b842-70b6a8174110@gmail.com> Date: Wed, 29 Jul 2026 19:12:54 +0800 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH qemu-server] query-machine-capabilities: check vendor string length for strncmp To: Fiona Ebner , =?UTF-8?Q?Fabian_Gr=C3=BCnbichler?= , pve-devel@lists.proxmox.com References: <20260603055031.106241-1-wukaiyang@loongfans.cn> <1783951945.bjj3it71oe.astroid@yuna.none> <105b4d4d-440d-4a7b-a305-2ad3019820e4@gmail.com> Content-Language: en-US From: Kaiyang Wu In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 0 AWL 0.000 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy FREEMAIL_ENVFROM_END_DIGIT 1 Envelope-from freemail username ends in digit FREEMAIL_FROM 0.001 Sender email is commonly abused enduser mail provider RCVD_IN_DNSWL_NONE -0.0001 Sender listed at https://www.dnswl.org/, no trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: LLDRWTH4P3OWDCWDDMTOXFLKODBBWWYE X-Message-ID-Hash: LLDRWTH4P3OWDCWDDMTOXFLKODBBWWYE X-MailFrom: wukaiyang2003@gmail.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Kaiyang Wu X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Thanks, v2 addressed this using conditional compilation. On 2026-07-29 18:16, Fiona Ebner wrote: > Am 29.07.26 um 10:41 AM schrieb Kaiyang Wu: >> Gentle ping. >> >> Kaiyang >> >> On 2026-07-16 10:31, Kaiyang Wu wrote: >>> Intel TDX and AMD SEV are both x86_64 only extensions [0] [1]. I >>> wonder if the best approach for this issue is to just add a >>> conditional compilation check for x86_64 target architecture. >>> >>> If that works I will switch to compile time architecture check in v2. >>> >>> [0]: https://docs.kernel.org/arch/x86/tdx.html >>> [1]: https://docs.kernel.org/virt/kvm/x86/amd-memory-encryption.html >>> > > Yes, I think the checks for AuthenticAMD and GenuineIntel can be put > into conditional compilation for x86_64 right now. There already is a > conditional inside query_cpu_capabilities_sev() but that can be dropped > afterwards. > >>> On 2026-07-13 22:15, Fabian Grünbichler wrote: >>>> On June 3, 2026 7:50 am, Kaiyang Wu wrote: >>>>> Fix build error on unknown vendors ('fallback'): >>>>> >>>>>     error: ‘strncmp’ of strings of length 7 and 12 and bound of 12 >>>>> evaluates to nonzero [-Werror=string-compare] >>>>> >>>>> Signed-off-by: Kaiyang Wu >>>>> --- >>>>>   src/query-machine-capabilities/query-machine-capabilities.c | 4 ++-- >>>>>   1 file changed, 2 insertions(+), 2 deletions(-) >>>>> >>>>> diff --git a/src/query-machine-capabilities/query-machine- >>>>> capabilities.c b/src/query-machine-capabilities/query-machine- >>>>> capabilities.c >>>>> index abb47acd..25d06db7 100644 >>>>> --- a/src/query-machine-capabilities/query-machine-capabilities.c >>>>> +++ b/src/query-machine-capabilities/query-machine-capabilities.c >>>>> @@ -204,7 +204,7 @@ int main() { >>>>>           eprintf("Error writing to file '" OUTPUT_PATH "': %s\n", >>>>> strerror(errno)); >>>>>       } >>>>> -    if (strncmp(vendor, "AuthenticAMD", 12) == 0) { >>>>> +    if (strncmp(vendor, "AuthenticAMD", strnlen(vendor, 12)) == 0) { >>>> >>>> this is wrong - if the vendor is "Authentic" the code would now think >>>> it's AMD.. the same would be true if vendor is "AuthenticAMDsomething", >>>> because it would only look at the first 12 bytes (granted, that is a >>>> pre-existing issue ;)). >>>> >>>> instead, we'd first need to check for the length, and if it is 12, do >>>> the existing checks, if not, either add checks for other vendors, or >>>> reject/abort.. >>>> >>>>>           cpu_caps_amd_sev_t caps_sev; >>>>>           query_cpu_capabilities_sev(&caps_sev); >>>>> @@ -222,7 +222,7 @@ int main() { >>>>>               caps_sev.sev_es_support ? "true" : "false", >>>>>               caps_sev.sev_snp_support ? "true" : "false" >>>>>           ); >>>>> -    } else if (strncmp(vendor, "GenuineIntel", 12) == 0) { >>>>> +    } else if (strncmp(vendor, "GenuineIntel", strnlen(vendor, 12)) >>>>> == 0) { >>>> >>>> same applies here, but with `Genuine` (or any other substring prefix of >>>> `GenuineIntel`).. >>>> >>>>>           cpu_caps_intel_tdx_t caps_tdx; >>>>>           if (query_cpu_capabilities_tdx(&caps_tdx) == 0) { >>>>>               ret = fprintf(file, >>>>> -- >>>>> 2.52.0 >>>>> >>>>> >>>>> >>>>> >>>>> >>>> >>> >> >> >> >> > >