From: Juergen Gross <jgross@suse.com>
To: dmitry.semenets@gmail.com, xen-devel@lists.xenproject.org
Cc: Oleksandr Andrushchenko <oleksandr_andrushchenko@epam.com>,
Wei Liu <wl@xen.org>, Anthony PERARD <anthony.perard@citrix.com>,
Dmytro Semenets <dmytro_semenets@epam.com>
Subject: Re: [PATCH v2 2/4] tools: allow vchan XenStore paths more then 64 bytes long
Date: Mon, 1 Aug 2022 10:59:13 +0200 [thread overview]
Message-ID: <124efe96-ed51-6312-75a8-1248724b619e@suse.com> (raw)
In-Reply-To: <20220713150311.4152528-2-dmitry.semenets@gmail.com>
[-- Attachment #1.1.1: Type: text/plain, Size: 3916 bytes --]
On 13.07.22 17:03, dmitry.semenets@gmail.com wrote:
> From: Oleksandr Andrushchenko <oleksandr_andrushchenko@epam.com>
>
> Current vchan implementation, while dealing with XenStore paths,
> allocates 64 bytes buffer on the stack which may not be enough for
> some use-cases. Make the buffer longer to respect maximum allowed
> XenStore path of XENSTORE_ABS_PATH_MAX.
>
> Signed-off-by: Oleksandr Andrushchenko <oleksandr_andrushchenko@epam.com>
> Signed-off-by: Dmytro Semenets <dmytro_semenets@epam.com>
> ---
> tools/libs/vchan/init.c | 28 ++++++++++++++++++++++------
> 1 file changed, 22 insertions(+), 6 deletions(-)
>
> diff --git a/tools/libs/vchan/init.c b/tools/libs/vchan/init.c
> index 9195bd3b98..38658f30af 100644
> --- a/tools/libs/vchan/init.c
> +++ b/tools/libs/vchan/init.c
> @@ -249,7 +249,7 @@ static int init_xs_srv(struct libxenvchan *ctrl, int domain, const char* xs_base
> int ret = -1;
> struct xs_handle *xs;
> struct xs_permissions perms[2];
> - char buf[64];
> + char *buf;
> char ref[16];
> char* domid_str = NULL;
> xs_transaction_t xs_trans = XBT_NULL;
> @@ -259,6 +259,12 @@ static int init_xs_srv(struct libxenvchan *ctrl, int domain, const char* xs_base
> if (!ctrl->xs_path)
> return -1;
>
> + buf = malloc(XENSTORE_ABS_PATH_MAX);
> + if (!buf) {
> + free(ctrl);
> + return 0;
> + }
> +
> xs = xs_open(0);
> if (!xs)
> goto fail;
> @@ -280,14 +286,14 @@ retry_transaction:
> goto fail_xs_open;
>
> snprintf(ref, sizeof ref, "%d", ring_ref);
> - snprintf(buf, sizeof buf, "%s/ring-ref", xs_base);
> + snprintf(buf, XENSTORE_ABS_PATH_MAX, "%s/ring-ref", xs_base);
> if (!xs_write(xs, xs_trans, buf, ref, strlen(ref)))
> goto fail_xs_open;
> if (!xs_set_permissions(xs, xs_trans, buf, perms, 2))
> goto fail_xs_open;
>
> snprintf(ref, sizeof ref, "%d", ctrl->event_port);
> - snprintf(buf, sizeof buf, "%s/event-channel", xs_base);
> + snprintf(buf, XENSTORE_ABS_PATH_MAX, "%s/event-channel", xs_base);
> if (!xs_write(xs, xs_trans, buf, ref, strlen(ref)))
> goto fail_xs_open;
> if (!xs_set_permissions(xs, xs_trans, buf, perms, 2))
> @@ -303,6 +309,7 @@ retry_transaction:
> free(domid_str);
> xs_close(xs);
> fail:
> + free(buf);
> return ret;
> }
>
> @@ -419,13 +426,20 @@ struct libxenvchan *libxenvchan_client_init(struct xentoollog_logger *logger,
> {
> struct libxenvchan *ctrl = malloc(sizeof(struct libxenvchan));
> struct xs_handle *xs = NULL;
> - char buf[64];
> + char *buf;
> char *ref;
> int ring_ref;
> unsigned int len;
>
> if (!ctrl)
> return 0;
> +
> + buf = malloc(XENSTORE_ABS_PATH_MAX);
> + if (!buf) {
> + free(ctrl);
> + return 0;
> + }
> +
> ctrl->ring = NULL;
> ctrl->event = NULL;
> ctrl->gnttab = NULL;
> @@ -436,8 +450,9 @@ struct libxenvchan *libxenvchan_client_init(struct xentoollog_logger *logger,
> if (!xs)
> goto fail;
>
> +
> // find xenstore entry
> - snprintf(buf, sizeof buf, "%s/ring-ref", xs_path);
> + snprintf(buf, XENSTORE_ABS_PATH_MAX, "%s/ring-ref", xs_path);
> ref = xs_read(xs, 0, buf, &len);
> if (!ref)
> goto fail;
> @@ -445,7 +460,7 @@ struct libxenvchan *libxenvchan_client_init(struct xentoollog_logger *logger,
> free(ref);
> if (!ring_ref)
> goto fail;
> - snprintf(buf, sizeof buf, "%s/event-channel", xs_path);
> + snprintf(buf, XENSTORE_ABS_PATH_MAX, "%s/event-channel", xs_path);
> ref = xs_read(xs, 0, buf, &len);
> if (!ref)
> goto fail;
> @@ -475,6 +490,7 @@ struct libxenvchan *libxenvchan_client_init(struct xentoollog_logger *logger,
> out:
> if (xs)
> xs_close(xs);
> + free(buf);
> return ctrl;
> fail:
> libxenvchan_close(ctrl);
I think you are leaking buf in case of "goto fail".
Juergen
[-- Attachment #1.1.2: OpenPGP public key --]
[-- Type: application/pgp-keys, Size: 3149 bytes --]
[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 495 bytes --]
next prev parent reply other threads:[~2022-08-01 8:59 UTC|newest]
Thread overview: 12+ messages / expand[flat|nested] mbox.gz Atom feed top
2022-07-13 15:03 [PATCH v2 1/4] tools: remove xenstore entries on vchan server closure dmitry.semenets
2022-07-13 15:03 ` [PATCH v2 2/4] tools: allow vchan XenStore paths more then 64 bytes long dmitry.semenets
2022-08-01 8:59 ` Juergen Gross [this message]
2022-08-01 9:11 ` Dmytro Semenets
2022-08-01 9:17 ` Juergen Gross
2022-09-27 15:00 ` Anthony PERARD
2022-07-13 15:03 ` [PATCH v2 3/4] tools/libs/light: Add vchan support to libxl dmitry.semenets
2022-07-13 15:03 ` [PATCH v2 4/4] tools/xl: Add pcid daemon to xl dmitry.semenets
2022-09-27 17:20 ` Anthony PERARD
2022-08-01 8:57 ` [PATCH v2 1/4] tools: remove xenstore entries on vchan server closure Juergen Gross
2022-09-22 6:29 ` Jan Beulich
2022-09-27 14:37 ` Anthony PERARD
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=124efe96-ed51-6312-75a8-1248724b619e@suse.com \
--to=jgross@suse.com \
--cc=anthony.perard@citrix.com \
--cc=dmitry.semenets@gmail.com \
--cc=dmytro_semenets@epam.com \
--cc=oleksandr_andrushchenko@epam.com \
--cc=wl@xen.org \
--cc=xen-devel@lists.xenproject.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.