vdpa_sim_net: check TX pull result before RX copy

vringh_iov_pull_iotlb() returns a signed byte count.  A failed TX pull is
currently added to the unsigned byte counter and then passed as a size_t
length to receive_filter() and vringh_iov_push_iotlb().  A negative error
can therefore become a large length in the RX path.

Handle non-positive pull results before every length use.  Count the TX
error and complete the consumed TX descriptor with zero bytes.

I found this bug myself, though the patch was written with AI assistance.

Fixes: cfe2268929 ("vdpa_sim: filter destination mac address")
Assisted-by: OpenAI-Codex:GPT-5
Signed-off-by: Linfeng Sun <linfeng.sun.dev@gmail.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Message-ID: <20260901094842.25875-1-linfeng.sun.dev@gmail.com>
This commit is contained in:
Linfeng Sun 2026-09-01 17:48:42 +08:00 committed by Michael S. Tsirkin
parent 0a8693f00c
commit 0d195797a8

View File

@ -225,10 +225,15 @@ static void vdpasim_net_work(struct vdpasim *vdpasim)
break;
}
++tx_pkts;
read = vringh_iov_pull_iotlb(&txq->vring, &txq->out_iov,
net->buffer, PAGE_SIZE);
if (read <= 0) {
++tx_errors;
vdpasim_net_complete(txq, 0);
continue;
}
++tx_pkts;
tx_bytes += read;
if (!receive_filter(vdpasim, read)) {