From: Markus Armbruster <armbru@redhat.com>
To: Gerd Hoffmann <kraxel@redhat.com>
Cc: qemu-devel@nongnu.org
Subject: Re: [Qemu-devel] [PATCH 1/2] qdev: factor out qdev_print_devinfo.
Date: Mon, 03 Aug 2009 10:24:44 +0200 [thread overview]
Message-ID: <8763d5i9tf.fsf@pike.pond.sub.org> (raw)
In-Reply-To: <4A7696BE.6030100@redhat.com> (Gerd Hoffmann's message of "Mon\, 03 Aug 2009 09\:50\:22 +0200")
Gerd Hoffmann <kraxel@redhat.com> writes:
> On 08/01/09 01:44, Markus Armbruster wrote:
>> Gerd Hoffmann<kraxel@redhat.com> writes:
>>
>>> Signed-off-by: Gerd Hoffmann<kraxel@redhat.com>
>>> ---
>>> hw/qdev.c | 19 ++++++++++++++++++-
>>> 1 files changed, 18 insertions(+), 1 deletions(-)
>>>
>>> diff --git a/hw/qdev.c b/hw/qdev.c
>>> index 479eb72..6f05232 100644
>>> --- a/hw/qdev.c
>>> +++ b/hw/qdev.c
>>> @@ -105,6 +105,21 @@ DeviceState *qdev_create(BusState *bus, const char *name)
>>> return dev;
>>> }
>>>
>>> +static int qdev_print_devinfo(DeviceInfo *info, char *dest, int len)
>>> +{
>>> + int pos = 0;
>>> +
>>> + pos += snprintf(dest+pos, len-pos, "name \"%s\", bus %s",
>>> + info->name, info->bus_info->name);
>>> + if (info->alias)
>>> + pos += snprintf(dest+pos, len-pos, ", alias \"%s\"", info->alias);
>>> + if (info->desc)
>>> + pos += snprintf(dest+pos, len-pos, ", desc \"%s\"", info->desc);
>>> + if (info->no_user)
>>> + pos += snprintf(dest+pos, len-pos, ", no-user");
>>> + return pos;
>>> +}
>>> +
>>
>> Isn't len-pos vulnerable to underflow here? The formal parameter type
>> is size_t...
>>
>> [...]
>
> Huh? You mean you want be able to pass a buffer larger than 2^31 to
> that function?
>
> cheers
> Gerd
snprintf() returns length of output. This may exceed its buffer size
argument. Therefore, pos can grow beyond len, and then len-pos becomes
negative. Parameter passing casts that to size_t, and snprintf()
happily writes beyond the buffer.
next prev parent reply other threads:[~2009-08-03 8:24 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-07-29 11:12 [Qemu-devel] [PATCH 1/2] qdev: factor out qdev_print_devinfo Gerd Hoffmann
2009-07-29 11:12 ` [Qemu-devel] [PATCH 2/2] qdev/core: add monitor command to list all drivers Gerd Hoffmann
2009-08-02 14:10 ` Avi Kivity
2009-08-03 10:05 ` Gerd Hoffmann
2009-08-03 12:51 ` Avi Kivity
2009-07-31 23:44 ` [Qemu-devel] [PATCH 1/2] qdev: factor out qdev_print_devinfo Markus Armbruster
2009-08-03 7:50 ` Gerd Hoffmann
2009-08-03 8:24 ` Markus Armbruster [this message]
2009-08-03 9:23 ` Gerd Hoffmann
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=8763d5i9tf.fsf@pike.pond.sub.org \
--to=armbru@redhat.com \
--cc=kraxel@redhat.com \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.