From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from [140.186.70.92] (port=53943 helo=eggs.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1OTWVt-00036z-2f for qemu-devel@nongnu.org; Tue, 29 Jun 2010 04:49:54 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.69) (envelope-from ) id 1OTWVp-0004hy-Pc for qemu-devel@nongnu.org; Tue, 29 Jun 2010 04:49:52 -0400 Received: from mailout4.samsung.com ([203.254.224.34]:23034) by eggs.gnu.org with esmtp (Exim 4.69) (envelope-from ) id 1OTWVp-0004cw-EC for qemu-devel@nongnu.org; Tue, 29 Jun 2010 04:49:49 -0400 Received: from epmmp2 (mailout4.samsung.com [203.254.224.34]) by mailout4.samsung.com (Sun Java(tm) System Messaging Server 7u3-15.01 64bit (built Feb 12 2010)) with ESMTP id <0L4R00JM5PUBQM70@mailout4.samsung.com> for qemu-devel@nongnu.org; Tue, 29 Jun 2010 17:49:23 +0900 (KST) Received: from TNRNDGASPAPP1.tn.corp.samsungelectronics.net ([165.213.149.150]) by mmp2.samsung.com (iPlanet Messaging Server 5.2 Patch 2 (built Jul 14 2004)) with ESMTPA id <0L4R00AMBPUBNN@mmp2.samsung.com> for qemu-devel@nongnu.org; Tue, 29 Jun 2010 17:49:23 +0900 (KST) Date: Tue, 29 Jun 2010 17:50:20 +0900 From: Mike McCormack Message-id: <4C29B3CC.8040400@samsung.com> MIME-version: 1.0 Content-type: text/plain; charset=ISO-8859-1; format=flowed Content-transfer-encoding: 7BIT Subject: [Qemu-devel] [PATCH] Fix null pointer dereference when parsing chardevs without a backend option. List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org qemu_opt_get may return NULL, so handle that rather than crashing. Signed-off-by: Mike McCormack --- qemu-char.c | 9 ++++++++- 1 files changed, 8 insertions(+), 1 deletions(-) diff --git a/qemu-char.c b/qemu-char.c index 9b69d92..f292ee7 100644 --- a/qemu-char.c +++ b/qemu-char.c @@ -2434,6 +2434,7 @@ CharDriverState *qemu_chr_open_opts(QemuOpts *opts, void (*init)(struct CharDriverState *s)) { CharDriverState *chr; + const char *backend; int i; if (qemu_opts_id(opts) == NULL) { @@ -2441,8 +2442,14 @@ CharDriverState *qemu_chr_open_opts(QemuOpts *opts, return NULL; } + backend = qemu_opt_get(opts, "backend"); + if (!backend) { + fprintf(stderr, "chardev: backend option not specified\n"); + return NULL; + } + for (i = 0; i < ARRAY_SIZE(backend_table); i++) { - if (strcmp(backend_table[i].name, qemu_opt_get(opts, "backend")) == 0) + if (strcmp(backend_table[i].name, backend) == 0) break; } if (i == ARRAY_SIZE(backend_table)) { -- 1.5.4.3