All of lore.kernel.org
 help / color / mirror / Atom feed
From: Markus Armbruster <armbru@redhat.com>
To: Gerd Hoffmann <kraxel@redhat.com>
Cc: qemu-devel@nongnu.org
Subject: Re: [Qemu-devel] [PATCH 1/2] qdev: factor out qdev_print_devinfo.
Date: Mon, 03 Aug 2009 10:24:44 +0200	[thread overview]
Message-ID: <8763d5i9tf.fsf@pike.pond.sub.org> (raw)
In-Reply-To: <4A7696BE.6030100@redhat.com> (Gerd Hoffmann's message of "Mon\, 03 Aug 2009 09\:50\:22 +0200")

Gerd Hoffmann <kraxel@redhat.com> writes:

> On 08/01/09 01:44, Markus Armbruster wrote:
>> Gerd Hoffmann<kraxel@redhat.com>  writes:
>>
>>> Signed-off-by: Gerd Hoffmann<kraxel@redhat.com>
>>> ---
>>>   hw/qdev.c |   19 ++++++++++++++++++-
>>>   1 files changed, 18 insertions(+), 1 deletions(-)
>>>
>>> diff --git a/hw/qdev.c b/hw/qdev.c
>>> index 479eb72..6f05232 100644
>>> --- a/hw/qdev.c
>>> +++ b/hw/qdev.c
>>> @@ -105,6 +105,21 @@ DeviceState *qdev_create(BusState *bus, const char *name)
>>>       return dev;
>>>   }
>>>
>>> +static int qdev_print_devinfo(DeviceInfo *info, char *dest, int len)
>>> +{
>>> +    int pos = 0;
>>> +
>>> +    pos += snprintf(dest+pos, len-pos, "name \"%s\", bus %s",
>>> +                    info->name, info->bus_info->name);
>>> +    if (info->alias)
>>> +        pos += snprintf(dest+pos, len-pos, ", alias \"%s\"", info->alias);
>>> +    if (info->desc)
>>> +        pos += snprintf(dest+pos, len-pos, ", desc \"%s\"", info->desc);
>>> +    if (info->no_user)
>>> +        pos += snprintf(dest+pos, len-pos, ", no-user");
>>> +    return pos;
>>> +}
>>> +
>>
>> Isn't len-pos vulnerable to underflow here?  The formal parameter type
>> is size_t...
>>
>> [...]
>
> Huh?  You mean you want be able to pass a buffer larger than 2^31 to
> that function?
>
> cheers
>   Gerd

snprintf() returns length of output.  This may exceed its buffer size
argument.  Therefore, pos can grow beyond len, and then len-pos becomes
negative.  Parameter passing casts that to size_t, and snprintf()
happily writes beyond the buffer.

  reply	other threads:[~2009-08-03  8:24 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-07-29 11:12 [Qemu-devel] [PATCH 1/2] qdev: factor out qdev_print_devinfo Gerd Hoffmann
2009-07-29 11:12 ` [Qemu-devel] [PATCH 2/2] qdev/core: add monitor command to list all drivers Gerd Hoffmann
2009-08-02 14:10   ` Avi Kivity
2009-08-03 10:05     ` Gerd Hoffmann
2009-08-03 12:51       ` Avi Kivity
2009-07-31 23:44 ` [Qemu-devel] [PATCH 1/2] qdev: factor out qdev_print_devinfo Markus Armbruster
2009-08-03  7:50   ` Gerd Hoffmann
2009-08-03  8:24     ` Markus Armbruster [this message]
2009-08-03  9:23       ` Gerd Hoffmann

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=8763d5i9tf.fsf@pike.pond.sub.org \
    --to=armbru@redhat.com \
    --cc=kraxel@redhat.com \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.