other: 0.948 permissions: 0.917 semantic: 0.887 device: 0.868 KVM: 0.863 vnc: 0.863 debug: 0.857 graphic: 0.850 PID: 0.832 performance: 0.818 boot: 0.806 files: 0.662 network: 0.623 socket: 0.595 [OSS-Fuzz] Issue 29174 sb16: Abrt in audio_bug === Reproducer === cat << EOF | ../build-system/qemu-system-i386 \ -machine q35 -device sb16,audiodev=snd0 \ -audiodev none,id=snd0 -nographic -nodefaults \ -qtest stdio outw 0x22c 0x41 outb 0x22c 0x0 outw 0x22c 0x1004 outw 0x22c 0x1c EOF === Stack Trace === A bug was just triggered in audio_calloc Save all your work and restart without audio I am sorry Context: Aborted #0 raise #1 abort #2 audio_bug /src/qemu/audio/audio.c:119:9 #3 audio_calloc /src/qemu/audio/audio.c:154:9 #4 audio_pcm_sw_alloc_resources_out /src/qemu/audio/audio_template.h:116:15 #5 audio_pcm_sw_init_out /src/qemu/audio/audio_template.h:175:11 #6 audio_pcm_create_voice_pair_out /src/qemu/audio/audio_template.h:410:9 #7 AUD_open_out /src/qemu/audio/audio_template.h:503:14 #8 continue_dma8 /src/qemu/hw/audio/sb16.c:216:20 #9 dma_cmd8 /src/qemu/hw/audio/sb16.c:276:5 #10 command /src/qemu/hw/audio/sb16.c:0 #11 dsp_write /src/qemu/hw/audio/sb16.c:949:13 #12 portio_write /src/qemu/softmmu/ioport.c:205:13 #13 memory_region_write_accessor /src/qemu/softmmu/memory.c:491:5 #14 access_with_adjusted_size /src/qemu/softmmu/memory.c:552:18 #15 memory_region_dispatch_write /src/qemu/softmmu/memory.c:0:13 #16 flatview_write_continue /src/qemu/softmmu/physmem.c:2759:23 #17 flatview_write /src/qemu/softmmu/physmem.c:2799:14 #18 address_space_write /src/qemu/softmmu/physmem.c:2891:18 #19 cpu_outw /src/qemu/softmmu/ioport.c:70:5 OSS-Fuzz Report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=29174 This is still reproducible with the current version of QEMU. Marking this as "Confirmed" While the SB16 seems to work up to 48000 Hz, the "Sound Blaster Series Hardware Programming Guide" limit the sampling range from 4000 Hz to 44100 Hz (Section 3-9, 3-10: Digitized Sound I/O Programming, tables 3-2 and 3-3). Later, section 6-15 (DSP Commands) is more specific regarding the 41h / 42h registers (Set digitized sound output sampling rate): Valid sampling rates range from 5000 to 45000 Hz inclusive. There is no comment regarding error handling if the register is filled with an out-of-range value. (See also section 3-28 "8-bit or 16-bit Auto-initialize Transfer"). Assume limits are enforced in hardware. This fixes triggering an assertion in audio_calloc(): #1 abort #2 audio_bug audio/audio.c:119:9 #3 audio_calloc audio/audio.c:154:9 #4 audio_pcm_sw_alloc_resources_out audio/audio_template.h:116:15 #5 audio_pcm_sw_init_out audio/audio_template.h:175:11 #6 audio_pcm_create_voice_pair_out audio/audio_template.h:410:9 #7 AUD_open_out audio/audio_template.h:503:14 #8 continue_dma8 hw/audio/sb16.c:216:20 #9 dma_cmd8 hw/audio/sb16.c:276:5 #10 command hw/audio/sb16.c:0 #11 dsp_write hw/audio/sb16.c:949:13 #12 portio_write softmmu/ioport.c:205:13 #13 memory_region_write_accessor softmmu/memory.c:491:5 #14 access_with_adjusted_size softmmu/memory.c:552:18 #15 memory_region_dispatch_write softmmu/memory.c:0:13 #16 flatview_write_continue softmmu/physmem.c:2759:23 #17 flatview_write softmmu/physmem.c:2799:14 #18 address_space_write softmmu/physmem.c:2891:18 #19 cpu_outw softmmu/ioport.c:70:5 [*] http://www.baudline.com/solutions/full_duplex/sb16_pci/index.html Fixes: 85571bc7415 ("audio merge (malc)") Buglink: https://bugs.launchpad.net/bugs/1910603 OSS-Fuzz Report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=29174 Signed-off-by: Philippe Mathieu-Daudé