[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Qemu-devel] [PATCH v4 12/29] qemu-char: fix qemu_chr_fe_set_msgfds() cr
From: |
marcandre . lureau |
Subject: |
[Qemu-devel] [PATCH v4 12/29] qemu-char: fix qemu_chr_fe_set_msgfds() crash when disconnected |
Date: |
Thu, 7 Jul 2016 03:00:36 +0200 |
From: Marc-André Lureau <address@hidden>
Calling qemu_chr_fe_set_msgfds() on unconnected socket leads to crash
since s->ioc is NULL in this case. Return an error earlier instead.
Signed-off-by: Marc-André Lureau <address@hidden>
---
qemu-char.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)
diff --git a/qemu-char.c b/qemu-char.c
index 0698b98..c4fa779 100644
--- a/qemu-char.c
+++ b/qemu-char.c
@@ -2760,14 +2760,16 @@ static int tcp_set_msgfds(CharDriverState *chr, int
*fds, int num)
{
TCPCharDriver *s = chr->opaque;
- if (!qio_channel_has_feature(s->ioc,
- QIO_CHANNEL_FEATURE_FD_PASS)) {
- return -1;
- }
/* clear old pending fd array */
g_free(s->write_msgfds);
s->write_msgfds = NULL;
+ if (!s->connected ||
+ !qio_channel_has_feature(s->ioc,
+ QIO_CHANNEL_FEATURE_FD_PASS)) {
+ return -1;
+ }
+
if (num) {
s->write_msgfds = g_new(int, num);
memcpy(s->write_msgfds, fds, num * sizeof(int));
--
2.9.0
- [Qemu-devel] [PATCH v4 03/29] vhost: don't assume opaque is a fd, use backend cleanup, (continued)
- [Qemu-devel] [PATCH v4 03/29] vhost: don't assume opaque is a fd, use backend cleanup, marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 02/29] vhost-user: minor simplification, marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 04/29] vhost: make vhost_log_put() idempotent, marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 05/29] vhost: assert the log was cleaned up, marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 06/29] vhost: fix cleanup on not fully initialized device, marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 08/29] vhost-net: always call vhost_dev_cleanup() on failure, marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 09/29] vhost: fix calling vhost_dev_cleanup() after vhost_dev_init(), marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 07/29] vhost: make vhost_dev_cleanup() idempotent, marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 10/29] vhost: do not assert() on vhost_ops failure, marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 11/29] vhost: use error_report() instead of fprintf(stderr, ...), marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 12/29] qemu-char: fix qemu_chr_fe_set_msgfds() crash when disconnected,
marcandre . lureau <=
- [Qemu-devel] [PATCH v4 15/29] vhost-user: check vhost_user_{read, write}() return value, marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 14/29] vhost-user: check qemu_chr_fe_set_msgfds() return value, marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 13/29] vhost-user: call set_msgfds unconditionally, marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 17/29] vhost-user: add get_vhost_net() assertions, marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 16/29] vhost-user: keep vhost_net after a disconnection, marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 18/29] Revert "vhost-net: do not crash if backend is not present", marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 19/29] vhost-net: vhost_migration_done is vhost-user specific, marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 20/29] vhost: add assert() to check runtime behaviour, marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 22/29] char: add and use tcp_chr_wait_connected, marcandre . lureau, 2016/07/06
- [Qemu-devel] [PATCH v4 21/29] char: add chr_wait_connected callback, marcandre . lureau, 2016/07/06