I appreciate that hardening fixes are not always easy to test, due to
their nature. A big focus on testing here, then, should be on preventing
regressions for the normal, non-adversarial, case. Something that
exercises the code paths that are being changed.

I see that your test plan covers that. I also see this part:

"For each hardened interface, exercise it with out-of-range/invalid values from 
the guest and
   confirm QEMU rejects them gracefully instead of crashing/hanging:"

If you can do that, i.e., "exercise out-of-range/invalid values" and
check for rejections, great. But I wouldn't hold you to it if it becomes
too complex, and I would value the other parts of the test plan more, as
they focus on the code paths and normal usage.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2160034

Title:
  [Ubuntu 26.04] qemu s390x: interface hardening fixes

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu-z-systems/+bug/2160034/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to