From: Markus Armbruster <armbru@redhat.com>
To: qemu-devel@nongnu.org
Cc: thuth@redhat.com, f4bug@amsat.org, eblake@redhat.com
Subject: [Qemu-devel] [PATCH v3 10/23] qobject: qobject_from_jsonv() is dangerous, hide it away
Date: Mon, 6 Aug 2018 08:53:31 +0200 [thread overview]
Message-ID: <20180806065344.7103-11-armbru@redhat.com> (raw)
In-Reply-To: <20180806065344.7103-1-armbru@redhat.com>
qobject_from_jsonv() takes ownership of %p arguments. On failure, we
can't generally know whether we failed before or after %p, so
ownership becomes indeterminate. To avoid leaks, callers passing %p
must terminate on error, e.g. by passing &error_abort. Trap for the
unwary; document and give the function internal linkage.
Signed-off-by: Markus Armbruster <armbru@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <f4bug@amsat.org>
Reviewed-by: Eric Blake <eblake@redhat.com>
---
include/qapi/qmp/qjson.h | 2 --
qobject/qjson.c | 13 ++++++++++++-
2 files changed, 12 insertions(+), 3 deletions(-)
diff --git a/include/qapi/qmp/qjson.h b/include/qapi/qmp/qjson.h
index dce78583dc..5ebbe5a118 100644
--- a/include/qapi/qmp/qjson.h
+++ b/include/qapi/qmp/qjson.h
@@ -15,8 +15,6 @@
#define QJSON_H
QObject *qobject_from_json(const char *string, Error **errp);
-QObject *qobject_from_jsonv(const char *string, va_list *ap, Error **errp)
- GCC_FMT_ATTR(1, 0);
QObject *qobject_from_vjsonf_nofail(const char *string, va_list ap)
GCC_FMT_ATTR(1, 0);
diff --git a/qobject/qjson.c b/qobject/qjson.c
index 2e450231ff..ab4040f235 100644
--- a/qobject/qjson.c
+++ b/qobject/qjson.c
@@ -39,7 +39,18 @@ static void parse_json(JSONMessageParser *parser, GQueue *tokens)
s->result = json_parser_parse_err(tokens, s->ap, &s->err);
}
-QObject *qobject_from_jsonv(const char *string, va_list *ap, Error **errp)
+/*
+ * Parse @string as JSON value.
+ * If @ap is non-null, interpolate %-escapes.
+ * Takes ownership of %p arguments.
+ * On success, return the JSON value.
+ * On failure, store an error through @errp and return NULL.
+ * Ownership of %p arguments becomes indeterminate then. To avoid
+ * leaks, callers passing %p must terminate on error, e.g. by passing
+ * &error_abort.
+ */
+static QObject *qobject_from_jsonv(const char *string, va_list *ap,
+ Error **errp)
{
JSONParsingState state = {};
--
2.17.1
next prev parent reply other threads:[~2018-08-06 6:53 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-08-06 6:53 [Qemu-devel] [PATCH v3 00/23] tests: Compile-time format string checking for libqtest.h Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 01/23] libqtest: Rename functions to send QMP messages Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 02/23] libqtest: Clean up how we read device_del messages Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 03/23] libqtest: Clean up how we read the QMP greeting Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 04/23] libqtest: Remove qtest_qmp_discard_response() & friends Markus Armbruster
2018-08-06 7:02 ` Thomas Huth
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 05/23] libqtest: Document calling conventions Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 06/23] qobject: Replace qobject_from_jsonf() by qobject_from_jsonf_nofail() Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 07/23] qobject: New qobject_from_vjsonf_nofail(), qdict_from_vjsonf_nofail() Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 08/23] libqtest: Simplify qmp_fd_vsend() a bit Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 09/23] test-qobject-input-visitor: Avoid format string ambiguity Markus Armbruster
2018-08-06 6:53 ` Markus Armbruster [this message]
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 11/23] tests: Pass literal format strings directly to qmp_FOO() Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 12/23] tests: Clean up string interpolation into QMP input (simple cases) Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 13/23] cpu-plug-test: Don't pass integers as strings to device_add Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 14/23] tests: Clean up string interpolation around qtest_qmp_device_add() Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 15/23] migration-test: Make wait_command() return the "return" member Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 16/23] tests: New helper qtest_qmp_receive_success() Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 17/23] migration-test: Make wait_command() cope with '%' Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 18/23] migration-test: Clean up string interpolation into QMP, part 1 Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 19/23] migration-test: Clean up string interpolation into QMP, part 2 Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 20/23] migration-test: Clean up string interpolation into QMP, part 3 Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 21/23] libqtest: Enable compile-time format string checking Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 22/23] libqtest: Replace qtest_startf() by qtest_initf() Markus Armbruster
2018-08-06 6:53 ` [Qemu-devel] [PATCH v3 23/23] libqtest: Rename qtest_FOOv() to qtest_vFOO() for consistency Markus Armbruster
2018-08-12 10:02 ` Paolo Bonzini
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20180806065344.7103-11-armbru@redhat.com \
--to=armbru@redhat.com \
--cc=eblake@redhat.com \
--cc=f4bug@amsat.org \
--cc=qemu-devel@nongnu.org \
--cc=thuth@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.