Commit 1e5efe6d93 for qemu.org

commit 1e5efe6d93701d6b2b05b62822c02eee935490b5
Author: Laurent Vivier <lvivier@redhat.com>
Date:   Wed Jul 22 13:24:49 2026 +0200

    hw/net/igb: recalculate rx_desc_len on migration load

    rx_desc_len is migrated as a raw uint8_t from the stream but is a
    derived value. Currently igb_rx_use_legacy_descriptor() is a stub
    that always returns false, so rx_desc_len is always set to
    sizeof(union e1000_adv_rx_desc). Recalculate it in post_load to
    prevent a crafted migration stream from setting an invalid value.

    Cc: qemu-stable@nongnu.org
    Signed-off-by: Laurent Vivier <lvivier@redhat.com>
    Reviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>
    Message-ID: <20260722112449.1386162-3-lvivier@redhat.com>
    Reviewed-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>
    Signed-off-by: Philippe Mathieu-Daudé <philmd@oss.qualcomm.com>

diff --git a/hw/net/igb_core.c b/hw/net/igb_core.c
index 45d8fd795b..2a48839073 100644
--- a/hw/net/igb_core.c
+++ b/hw/net/igb_core.c
@@ -4548,5 +4548,7 @@ igb_core_post_load(IGBCore *core)
     igb_intrmgr_resume(core);
     igb_autoneg_resume(core);

+    igb_calc_rxdesclen(core);
+
     return 0;
 }