From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:47843) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TXiNM-0006SU-4V for qemu-devel@nongnu.org; Sun, 11 Nov 2012 19:59:47 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1TXiNJ-0002Zy-26 for qemu-devel@nongnu.org; Sun, 11 Nov 2012 19:59:44 -0500 Received: from mail-vc0-f173.google.com ([209.85.220.173]:63822) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TXiNI-0002Zq-Tk for qemu-devel@nongnu.org; Sun, 11 Nov 2012 19:59:40 -0500 Received: by mail-vc0-f173.google.com with SMTP id fl15so5527522vcb.4 for ; Sun, 11 Nov 2012 16:59:40 -0800 (PST) Sender: Nickolai Zeldovich From: Nickolai Zeldovich Date: Sun, 11 Nov 2012 19:59:43 -0500 Message-Id: <1352681983-23159-1-git-send-email-nickolai@csail.mit.edu> Subject: [Qemu-devel] [PATCH] slirp: Don't crash on packets from 0.0.0.0/8. List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Cc: Jan Kiszka , Nickolai Zeldovich LWIP can generate packets with a source of 0.0.0.0, which triggers an assertion failure in arp_table_add(). Instead of crashing, simply return to avoid adding an invalid ARP table entry. Signed-off-by: Nickolai Zeldovich --- slirp/arp_table.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/slirp/arp_table.c b/slirp/arp_table.c index 5d7b8ac..3318ce9 100644 --- a/slirp/arp_table.c +++ b/slirp/arp_table.c @@ -38,7 +38,8 @@ void arp_table_add(Slirp *slirp, uint32_t ip_addr, uint8_t ethaddr[ETH_ALEN]) ethaddr[3], ethaddr[4], ethaddr[5])); /* Check 0.0.0.0/8 invalid source-only addresses */ - assert((ip_addr & htonl(~(0xf << 28))) != 0); + if ((ip_addr & htonl(~(0xf << 28))) == 0) + return; if (ip_addr == 0xffffffff || ip_addr == broadcast_addr) { /* Do not register broadcast addresses */ -- 1.7.10.4