From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [45.144.208.40]) by lore.proxmox.com (Postfix) with ESMTPS id D22541FF0E5 for ; Wed, 29 Jul 2026 13:14:17 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id A3DBC2134B; Wed, 29 Jul 2026 13:14:17 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785323626; x=1785928426; darn=lists.proxmox.com; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:from:to:cc:subject:date:message-id:reply-to :content-type; bh=BupGHIFH1NqQODI0T0nYPMv+VMKGzvdlR/8/bFp1JHU=; b=Zd/vWCirSwuOJVIzuAEH12Sug+vhoxbOJGGZnplvcx0c9Qg1/Y/P+lT3ENpVZpviL+ TZI/8Ov1pnuCVY4E42vEFmAo9LdykBBWqDf+m7s1fVNw+fQRj8XIp6i9DJK3LCJ7Mc46 VwwFa7Ls4vJMo4WzMCvbGfqXMuCYEoaPDAtxDO60L0IOfCF7JfHHjo8CCl76L9X2pkFg vzyRg9hO0NKHB5qOA3Pl/BeLnCW2eABW8kigjpcwo+ODZBbRdL545tTGj+sfo/+gTa9R JWDOPW+DxsfK1rOXIrVJtDBDCM3SaRVNql4t75FHXYXOapwExgcqHfcDCzuYfrDPyZlO pvUw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785323626; x=1785928426; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=BupGHIFH1NqQODI0T0nYPMv+VMKGzvdlR/8/bFp1JHU=; b=htljxIpE+oDxlVry0sIGtrzrASRQItsjTpKsdZ8pwN7huCluswCb79CySZbucLIRCD GJeKx7VQMs7UUelIEpBNyGA/bYMUjHDNFzknZ4wooyqsDS0Fql1uYdQ3fpmKg7Iz0NuE vn3IhOM7QhBTJiP53tj2/md0E8mA65l0ky/up97EITRasOotzvKubkzWwp21KUcr11M+ U7s3u9Ew/dYm2Uo9ypTNE+tYKik/+17s7ZAzHa5I+BiXeeSeZEK5GT+oZeGqIdQ81Win pDPpLfTqqmcFWkW0knuZZJYl3Xwk5OS2aQApNJJ3iCrCfxrm/9h675OshX+UpBt45iNS CQxA== X-Forwarded-Encrypted: i=1; AHgh+Rred2aUF0x1kXirABoZOLpcZfV5Frn6GOlzCkmosf7jIn2hPkuko+/aayWRh0c1BPELTDQaGXEehIs=@lists.proxmox.com X-Gm-Message-State: AOJu0YyxgGWvHuJRdwSjR02pzCC3QyKhdVz2b2H25q/a9isIaLw77PNG GN0+gsBSRH6Yh3TZ4el2TgX9KekTUz50nXRECQePV0FN2W2KdHwaMBQeaf0vaEHx3RoMcQ== X-Gm-Gg: AR+sD13YPqT9kQS3P99X/+yDDIF6zpL3yMTffDu1HUxoB4m7ptiXpW+kvbfqmdDKkC6 enAC1LSB7cXi6FExpXBtbkgQAPUivVNT11rVf1JcaVHUrl7tB5FccM+B04cjGsPCIZtbi1v5Gf4 WJ/7rlkYbtDZOoMkW0KqP8W2gVhtS21fbSAhDDyU7FeBXoFUaiDDtb07FRZlY7kRmPiLMy3SyOa xkQAtKYhDiHH511JTmyj1CAZy/cdz5QGgUv+pfoRLyV9VcyXfvB5duEXUsbPwWcSwEzd0OY8bFS MPKE8VP86HJo5aoA3xnS7Ni7IJ/7gZIjyGSHc3qJJirxM1SQRsEaUx/yCL1DIn9sYk2NZ/CDPaR jJpPFgp59uyXk+wAkf/kwG/AL/o+Zz0pCIvzbhGdwy04Ll6hCFAdmbyuGKGG97X0uQ8uI5/q5yc m6FtU6YfkwUCjA6+k5uQHZAjX+lK0YDXUx4lP4VRIhMEEH7PHLOvDTkv2lMGMCsPWnZmVOISd+2 N551tdY X-Received: by 2002:a17:903:3c45:b0:2cc:dacc:fe27 with SMTP id d9443c01a7336-2d015cfc0famr71141145ad.30.1785323626255; Wed, 29 Jul 2026 04:13:46 -0700 (PDT) Message-ID: <0144a509-387a-4906-9b3a-39ed8da841ba@gmail.com> Date: Wed, 29 Jul 2026 19:13:43 +0800 MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: superseded: [PATCH qemu-server] query-machine-capabilities: check vendor string length for strncmp To: Fiona Ebner , =?UTF-8?Q?Fabian_Gr=C3=BCnbichler?= , pve-devel@lists.proxmox.com References: <20260603055031.106241-1-wukaiyang@loongfans.cn> <1783951945.bjj3it71oe.astroid@yuna.none> <105b4d4d-440d-4a7b-a305-2ad3019820e4@gmail.com> Content-Language: en-US From: Kaiyang Wu In-Reply-To: Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 0 AWL 0.000 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy FREEMAIL_ENVFROM_END_DIGIT 1 Envelope-from freemail username ends in digit FREEMAIL_FROM 0.001 Sender email is commonly abused enduser mail provider RCVD_IN_DNSWL_NONE -0.0001 Sender listed at https://www.dnswl.org/, no trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: T266465MVEHTKPC7IVI2OS4VEFA3CLWA X-Message-ID-Hash: T266465MVEHTKPC7IVI2OS4VEFA3CLWA X-MailFrom: wukaiyang2003@gmail.com X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Kaiyang Wu X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: https://lore.proxmox.com/pve-devel/20260729111024.58285-2-wukaiyang@loongfans.cn/ On 2026-07-29 18:16, Fiona Ebner wrote: > Am 29.07.26 um 10:41 AM schrieb Kaiyang Wu: >> Gentle ping. >> >> Kaiyang >> >> On 2026-07-16 10:31, Kaiyang Wu wrote: >>> Intel TDX and AMD SEV are both x86_64 only extensions [0] [1]. I >>> wonder if the best approach for this issue is to just add a >>> conditional compilation check for x86_64 target architecture. >>> >>> If that works I will switch to compile time architecture check in v2. >>> >>> [0]: https://docs.kernel.org/arch/x86/tdx.html >>> [1]: https://docs.kernel.org/virt/kvm/x86/amd-memory-encryption.html >>> > > Yes, I think the checks for AuthenticAMD and GenuineIntel can be put > into conditional compilation for x86_64 right now. There already is a > conditional inside query_cpu_capabilities_sev() but that can be dropped > afterwards. > >>> On 2026-07-13 22:15, Fabian Grünbichler wrote: >>>> On June 3, 2026 7:50 am, Kaiyang Wu wrote: >>>>> Fix build error on unknown vendors ('fallback'): >>>>> >>>>>     error: ‘strncmp’ of strings of length 7 and 12 and bound of 12 >>>>> evaluates to nonzero [-Werror=string-compare] >>>>> >>>>> Signed-off-by: Kaiyang Wu >>>>> --- >>>>>   src/query-machine-capabilities/query-machine-capabilities.c | 4 ++-- >>>>>   1 file changed, 2 insertions(+), 2 deletions(-) >>>>> >>>>> diff --git a/src/query-machine-capabilities/query-machine- >>>>> capabilities.c b/src/query-machine-capabilities/query-machine- >>>>> capabilities.c >>>>> index abb47acd..25d06db7 100644 >>>>> --- a/src/query-machine-capabilities/query-machine-capabilities.c >>>>> +++ b/src/query-machine-capabilities/query-machine-capabilities.c >>>>> @@ -204,7 +204,7 @@ int main() { >>>>>           eprintf("Error writing to file '" OUTPUT_PATH "': %s\n", >>>>> strerror(errno)); >>>>>       } >>>>> -    if (strncmp(vendor, "AuthenticAMD", 12) == 0) { >>>>> +    if (strncmp(vendor, "AuthenticAMD", strnlen(vendor, 12)) == 0) { >>>> >>>> this is wrong - if the vendor is "Authentic" the code would now think >>>> it's AMD.. the same would be true if vendor is "AuthenticAMDsomething", >>>> because it would only look at the first 12 bytes (granted, that is a >>>> pre-existing issue ;)). >>>> >>>> instead, we'd first need to check for the length, and if it is 12, do >>>> the existing checks, if not, either add checks for other vendors, or >>>> reject/abort.. >>>> >>>>>           cpu_caps_amd_sev_t caps_sev; >>>>>           query_cpu_capabilities_sev(&caps_sev); >>>>> @@ -222,7 +222,7 @@ int main() { >>>>>               caps_sev.sev_es_support ? "true" : "false", >>>>>               caps_sev.sev_snp_support ? "true" : "false" >>>>>           ); >>>>> -    } else if (strncmp(vendor, "GenuineIntel", 12) == 0) { >>>>> +    } else if (strncmp(vendor, "GenuineIntel", strnlen(vendor, 12)) >>>>> == 0) { >>>> >>>> same applies here, but with `Genuine` (or any other substring prefix of >>>> `GenuineIntel`).. >>>> >>>>>           cpu_caps_intel_tdx_t caps_tdx; >>>>>           if (query_cpu_capabilities_tdx(&caps_tdx) == 0) { >>>>>               ret = fprintf(file, >>>>> -- >>>>> 2.52.0 >>>>> >>>>> >>>>> >>>>> >>>>> >>>> >>> >> >> >> >> > >