From mboxrd@z Thu Jan 1 00:00:00 1970 From: Isaku Yamahata Subject: Re: [Qemu-devel] [PATCH 2/2] pci init: Check if devfn exceeding the max devices number supported on bus Date: Mon, 23 Aug 2010 18:56:56 +0900 Message-ID: <20100823095656.GG20428@valinux.co.jp> References: <20100823053342.2537.19008.stgit@k1> <20100823053350.2560.472.stgit@k1> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Cc: kvm@vger.kernel.org, mtosatti@redhat.com, qemu-devel@nongnu.org To: Ken CC Return-path: Received: from mail.valinux.co.jp ([210.128.90.3]:39697 "EHLO mail.valinux.co.jp" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1753709Ab0HWJqp (ORCPT ); Mon, 23 Aug 2010 05:46:45 -0400 Content-Disposition: inline In-Reply-To: <20100823053350.2560.472.stgit@k1> Sender: kvm-owner@vger.kernel.org List-ID: How did you trigger the bug? I suppose parse_pci_devfn() in qdev-properties should check the error. Although I'm not objecting this patch itself, it's caller's bug. Just assert(devfn < PCIBUS_MAX_DEVICES)? On Mon, Aug 23, 2010 at 01:56:31PM +0800, Ken CC wrote: > > Check before trying subindexing. > > Signed-off-by: Ken CC > --- > hw/pci.c | 4 ++++ > 1 files changed, 4 insertions(+), 0 deletions(-) > > diff --git a/hw/pci.c b/hw/pci.c > index a09fbac..f6f00c6 100644 > --- a/hw/pci.c > +++ b/hw/pci.c > @@ -675,6 +675,10 @@ static PCIDevice *do_pci_register_device(PCIDevice *pci_dev, PCIBus *bus, > error_report("PCI: no slot/function available for %s, all in use", name); > return NULL; > found: ; > + } else if (devfn > PCIBUS_MAX_DEVICES - 1) { > + error_report("PCI: devfn is out of bus capacity." > + " Only %d devices supported.", PCIBUS_MAX_DEVICES); > + return NULL; > } else if (bus->devices[devfn]) { > error_report("PCI: slot %d function %d not available for %s, in use by %s", > PCI_SLOT(devfn), PCI_FUNC(devfn), name, bus->devices[devfn]->name); > > > -- yamahata