Commit 1e5efe6d93 for qemu.org
commit 1e5efe6d93701d6b2b05b62822c02eee935490b5
Author: Laurent Vivier <lvivier@redhat.com>
Date: Wed Jul 22 13:24:49 2026 +0200
hw/net/igb: recalculate rx_desc_len on migration load
rx_desc_len is migrated as a raw uint8_t from the stream but is a
derived value. Currently igb_rx_use_legacy_descriptor() is a stub
that always returns false, so rx_desc_len is always set to
sizeof(union e1000_adv_rx_desc). Recalculate it in post_load to
prevent a crafted migration stream from setting an invalid value.
Cc: qemu-stable@nongnu.org
Signed-off-by: Laurent Vivier <lvivier@redhat.com>
Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
Message-ID: <20260722112449.1386162-3-lvivier@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
diff --git a/hw/net/igb_core.c b/hw/net/igb_core.c
index 45d8fd795b..2a48839073 100644
--- a/hw/net/igb_core.c
+++ b/hw/net/igb_core.c
@@ -4548,5 +4548,7 @@ igb_core_post_load(IGBCore *core)
igb_intrmgr_resume(core);
igb_autoneg_resume(core);
+ igb_calc_rxdesclen(core);
+
return 0;
}