From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 9EBA11FF0E5 for ; Wed, 29 Jul 2026 12:17:22 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id 0140D21353; Wed, 29 Jul 2026 12:17:22 +0200 (CEST) Message-ID: Date: Wed, 29 Jul 2026 12:16:59 +0200 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH qemu-server] query-machine-capabilities: check vendor string length for strncmp To: Kaiyang Wu , =?UTF-8?Q?Fabian_Gr=C3=BCnbichler?= , pve-devel@lists.proxmox.com References: <20260603055031.106241-1-wukaiyang@loongfans.cn> <1783951945.bjj3it71oe.astroid@yuna.none> <105b4d4d-440d-4a7b-a305-2ad3019820e4@gmail.com> Content-Language: en-US From: Fiona Ebner In-Reply-To: <105b4d4d-440d-4a7b-a305-2ad3019820e4@gmail.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1785320180631 X-SPAM-LEVEL: Spam detection results: 0 AWL 0.174 Adjusted score from AWL reputation of From: address DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment (newer systems) RCVD_IN_DNSWL_LOW -0.7 Sender listed at https://www.dnswl.org/, low trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: GOJYINF4DDISN2AXRCDKZSCZC5TIYHCL X-Message-ID-Hash: GOJYINF4DDISN2AXRCDKZSCZC5TIYHCL X-MailFrom: f.ebner@proxmox.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Kaiyang Wu X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Am 29.07.26 um 10:41 AM schrieb Kaiyang Wu: > Gentle ping. > > Kaiyang > > On 2026-07-16 10:31, Kaiyang Wu wrote: >> Intel TDX and AMD SEV are both x86_64 only extensions [0] [1]. I >> wonder if the best approach for this issue is to just add a >> conditional compilation check for x86_64 target architecture. >> >> If that works I will switch to compile time architecture check in v2. >> >> [0]: https://docs.kernel.org/arch/x86/tdx.html >> [1]: https://docs.kernel.org/virt/kvm/x86/amd-memory-encryption.html >> Yes, I think the checks for AuthenticAMD and GenuineIntel can be put into conditional compilation for x86_64 right now. There already is a conditional inside query_cpu_capabilities_sev() but that can be dropped afterwards. >> On 2026-07-13 22:15, Fabian Grünbichler wrote: >>> On June 3, 2026 7:50 am, Kaiyang Wu wrote: >>>> Fix build error on unknown vendors ('fallback'): >>>> >>>>     error: ‘strncmp’ of strings of length 7 and 12 and bound of 12 >>>> evaluates to nonzero [-Werror=string-compare] >>>> >>>> Signed-off-by: Kaiyang Wu >>>> --- >>>>   src/query-machine-capabilities/query-machine-capabilities.c | 4 ++-- >>>>   1 file changed, 2 insertions(+), 2 deletions(-) >>>> >>>> diff --git a/src/query-machine-capabilities/query-machine- >>>> capabilities.c b/src/query-machine-capabilities/query-machine- >>>> capabilities.c >>>> index abb47acd..25d06db7 100644 >>>> --- a/src/query-machine-capabilities/query-machine-capabilities.c >>>> +++ b/src/query-machine-capabilities/query-machine-capabilities.c >>>> @@ -204,7 +204,7 @@ int main() { >>>>           eprintf("Error writing to file '" OUTPUT_PATH "': %s\n", >>>> strerror(errno)); >>>>       } >>>> -    if (strncmp(vendor, "AuthenticAMD", 12) == 0) { >>>> +    if (strncmp(vendor, "AuthenticAMD", strnlen(vendor, 12)) == 0) { >>> >>> this is wrong - if the vendor is "Authentic" the code would now think >>> it's AMD.. the same would be true if vendor is "AuthenticAMDsomething", >>> because it would only look at the first 12 bytes (granted, that is a >>> pre-existing issue ;)). >>> >>> instead, we'd first need to check for the length, and if it is 12, do >>> the existing checks, if not, either add checks for other vendors, or >>> reject/abort.. >>> >>>>           cpu_caps_amd_sev_t caps_sev; >>>>           query_cpu_capabilities_sev(&caps_sev); >>>> @@ -222,7 +222,7 @@ int main() { >>>>               caps_sev.sev_es_support ? "true" : "false", >>>>               caps_sev.sev_snp_support ? "true" : "false" >>>>           ); >>>> -    } else if (strncmp(vendor, "GenuineIntel", 12) == 0) { >>>> +    } else if (strncmp(vendor, "GenuineIntel", strnlen(vendor, 12)) >>>> == 0) { >>> >>> same applies here, but with `Genuine` (or any other substring prefix of >>> `GenuineIntel`).. >>> >>>>           cpu_caps_intel_tdx_t caps_tdx; >>>>           if (query_cpu_capabilities_tdx(&caps_tdx) == 0) { >>>>               ret = fprintf(file, >>>> --  >>>> 2.52.0 >>>> >>>> >>>> >>>> >>>> >>> >> > > > >