1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
|
socket: 0.983
user-level: 0.966
kernel: 0.956
network: 0.942
performance: 0.924
device: 0.914
architecture: 0.893
arm: 0.889
graphic: 0.863
x86: 0.820
PID: 0.818
files: 0.815
permissions: 0.808
ppc: 0.793
register: 0.768
debug: 0.758
vnc: 0.742
mistranslation: 0.721
VMM: 0.712
TCG: 0.696
risc-v: 0.681
boot: 0.674
assembly: 0.650
hypervisor: 0.605
peripherals: 0.601
i386: 0.596
semantic: 0.594
KVM: 0.473
virtual: 0.204
linux-user: sendmsg fails to send messages without iov
Description of problem:
When run via qemu `sendmsg` fails to send messages which contain a zero length `iov` but _do_ contain ancillary data. This works fine on plain Linux.
A practical example: the `ell` library relies on this for setting the IV on a kernel crypto (`AF_ALG`) socket: https://git.kernel.org/pub/scm/libs/ell/ell.git/tree/ell/cipher.c#n526
A message without data but only ancillary data is used to set the IV.
Steps to reproduce:
See [qemu_ancillary.c](/uploads/84ee20aa3b9178022847d6cd7fcf0048/qemu_ancillary.c) for a self contained testcase which sends two mesages (one with `msg_iovlen=0`, one with `msg_iovlen=1`).
(Test case is to be considered GPL, as I've copied bits from `ell`)
Native:
```
$ strace -esendmsg ./a.out
sendmsg(6, {msg_name=NULL, msg_namelen=0, msg_iov=NULL, msg_iovlen=0, msg_control=[{cmsg_len=36, cmsg_level=SOL_ALG, cmsg_type=0x2}], msg_controllen=40, msg_flags=0}, 0) = 0
sendmsg(6, {msg_name=NULL, msg_namelen=0, msg_iov=[{iov_base="\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", iov_len=16}], msg_iovlen=1, msg_control=[{cmsg_len=36, cmsg_level=SOL_ALG, cmsg_type=0x2}], msg_controllen=40, msg_flags=0}, 0) = 16
+++ exited with 0 +++
```
Qemu (observe missing sendmsg call):
```
$ strace -esendmsg ~/debug/qemu/build/qemu-x86_64 ./a.out
sendmsg(6, {msg_name=NULL, msg_namelen=0, msg_iov=[{iov_base="\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0\0", iov_len=16}], msg_iovlen=1, msg_control=[{cmsg_len=36, cmsg_level=SOL_ALG, cmsg_type=0x2}], msg_controllen=40, msg_flags=0}, 0) = 16
+++ exited with 0 +++
```
For a practical reproducer:
1. Compile and run `ell`'s `test-cipher` test case:
```
$ ~/debug/qemu/build/qemu-x86_64 ./unit/test-cipher
TEST: unsupported
TEST: aes
TEST: aes_ctr
test-cipher: unit/test-cipher.c:102: test_aes_ctr: Assertion `!r' failed.
Aborted (core dumped)
```
A strace will look similar.
|