From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:40612) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1addhl-0000xO-1G for qemu-devel@nongnu.org; Wed, 09 Mar 2016 07:59:09 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1addhh-0002gl-HV for qemu-devel@nongnu.org; Wed, 09 Mar 2016 07:59:08 -0500 Received: from mail-wm0-x244.google.com ([2a00:1450:400c:c09::244]:34008) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1addhh-0002gf-At for qemu-devel@nongnu.org; Wed, 09 Mar 2016 07:59:05 -0500 Received: by mail-wm0-x244.google.com with SMTP id p65so9919895wmp.1 for ; Wed, 09 Mar 2016 04:59:05 -0800 (PST) Sender: Paolo Bonzini References: <1457420446-25276-1-git-send-email-peterx@redhat.com> <1457420446-25276-5-git-send-email-peterx@redhat.com> <56DEC3E0.1010404@redhat.com> <20160309050812.GK2377@pxdev.xzpeter.org> <56DFD66F.9030900@redhat.com> <20160309080750.GR2377@pxdev.xzpeter.org> From: Paolo Bonzini Message-ID: <56E01E17.6000508@redhat.com> Date: Wed, 9 Mar 2016 13:59:03 +0100 MIME-Version: 1.0 In-Reply-To: <20160309080750.GR2377@pxdev.xzpeter.org> Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit Subject: Re: [Qemu-devel] [PATCH 4/8] usb: fix unbounded stack for xhci_dma_write_u32s List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Peter Xu Cc: qemu-devel@nongnu.org, Gerd Hoffmann On 09/03/2016 09:07, Peter Xu wrote: >>> > > pxdev:bin# gcc -v >>> > > Using built-in specs. >>> > > COLLECT_GCC=/bin/gcc >>> > > COLLECT_LTO_WRAPPER=/usr/libexec/gcc/x86_64-redhat-linux/4.8.5/lto-wrapper >>> > > Target: x86_64-redhat-linux >>> > > Configured with: ../configure --prefix=/usr --mandir=/usr/share/man --infodir=/usr/share/info --with-bugurl=http://bugzilla.redhat.com/bugzilla --enable-bootstrap --enable-shared --enable-threads=posix --enable-checking=release --with-system-zlib --enable-__cxa_atexit --disable-libunwind-exceptions --enable-gnu-unique-object --enable-linker-build-id --with-linker-hash-style=gnu --enable-languages=c,c++,objc,obj-c++,java,fortran,ada,go,lto --enable-plugin --enable-initfini-array --disable-libgcj --with-isl=/builddir/build/BUILD/gcc-4.8.5-20150702/obj-x86_64-redhat-linux/isl-install --with-cloog=/builddir/build/BUILD/gcc-4.8.5-20150702/obj-x86_64-redhat-linux/cloog-install --enable-gnu-indirect-function --with-tune=generic --with-arch_32=x86-64 --build=x86_64-redhat-linux >>> > > Thread model: posix >>> > > gcc version 4.8.5 20150623 (Red Hat 4.8.5-4) (GCC) >>> > > >>> > > Do you know why "might not be inlinable"? Failed to figure it out >>> > > myself as mentioned in cover letter.. >> > >> > It's just a difference in compiler versions. But ARRAY_SIZE should be >> > enough to fix it. > It's dynamically allocated in stack, can we still use ARRAY_SIZE in > this case? > > Maybe for this case, best to use both stack and heap? malloc only if > buffer big enough. If you look at users, they only write about 20 bytes at most. My suggestion is to use your patch, and replace assert(__BUF_SIZE >= n); with assert(n < ARRAY_SIZE(tmp)); Then you don't need the #define. Paolo