[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Qemu-devel] [PULL 24/41] qemu-char: fix qemu_chr_fe_set_msgfds() crash
From: |
Michael S. Tsirkin |
Subject: |
[Qemu-devel] [PULL 24/41] qemu-char: fix qemu_chr_fe_set_msgfds() crash when disconnected |
Date: |
Fri, 29 Jul 2016 06:16:28 +0300 |
From: Marc-André Lureau <address@hidden>
Calling qemu_chr_fe_set_msgfds() on unconnected socket leads to crash
since s->ioc is NULL in this case. Return an error earlier instead.
Signed-off-by: Marc-André Lureau <address@hidden>
Reviewed-by: Michael S. Tsirkin <address@hidden>
Signed-off-by: Michael S. Tsirkin <address@hidden>
---
qemu-char.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)
diff --git a/qemu-char.c b/qemu-char.c
index e4b8448..1274f50 100644
--- a/qemu-char.c
+++ b/qemu-char.c
@@ -2760,14 +2760,16 @@ static int tcp_set_msgfds(CharDriverState *chr, int
*fds, int num)
{
TCPCharDriver *s = chr->opaque;
- if (!qio_channel_has_feature(s->ioc,
- QIO_CHANNEL_FEATURE_FD_PASS)) {
- return -1;
- }
/* clear old pending fd array */
g_free(s->write_msgfds);
s->write_msgfds = NULL;
+ if (!s->connected ||
+ !qio_channel_has_feature(s->ioc,
+ QIO_CHANNEL_FEATURE_FD_PASS)) {
+ return -1;
+ }
+
if (num) {
s->write_msgfds = g_new(int, num);
memcpy(s->write_msgfds, fds, num * sizeof(int));
--
MST
- [Qemu-devel] [PULL 15/41] vhost: make vhost_log_put() idempotent, (continued)
- [Qemu-devel] [PULL 15/41] vhost: make vhost_log_put() idempotent, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 14/41] vhost: don't assume opaque is a fd, use backend cleanup, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 16/41] vhost: assert the log was cleaned up, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 17/41] vhost: fix cleanup on not fully initialized device, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 18/41] vhost: make vhost_dev_cleanup() idempotent, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 19/41] vhost-net: always call vhost_dev_cleanup() on failure, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 20/41] vhost: fix calling vhost_dev_cleanup() after vhost_dev_init(), Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 22/41] vhost: add missing VHOST_OPS_DEBUG, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 21/41] vhost: do not assert() on vhost_ops failure, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 23/41] vhost: use error_report() instead of fprintf(stderr, ...), Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 24/41] qemu-char: fix qemu_chr_fe_set_msgfds() crash when disconnected,
Michael S. Tsirkin <=
- [Qemu-devel] [PULL 25/41] vhost-user: call set_msgfds unconditionally, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 26/41] vhost-user: check qemu_chr_fe_set_msgfds() return value, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 27/41] vhost-user: check vhost_user_{read, write}() return value, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 28/41] vhost-user: keep vhost_net after a disconnection, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 29/41] vhost-user: add get_vhost_net() assertions, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 30/41] Revert "vhost-net: do not crash if backend is not present", Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 31/41] vhost-net: vhost_migration_done is vhost-user specific, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 32/41] vhost: add assert() to check runtime behaviour, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 33/41] char: add chr_wait_connected callback, Michael S. Tsirkin, 2016/07/28
- [Qemu-devel] [PULL 35/41] vhost-user: wait until backend init is completed, Michael S. Tsirkin, 2016/07/28