From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:33978) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TXxN8-0004Io-Kw for qemu-devel@nongnu.org; Mon, 12 Nov 2012 12:00:33 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1TXxN5-0001sO-IM for qemu-devel@nongnu.org; Mon, 12 Nov 2012 12:00:30 -0500 Received: from outgoing.csail.mit.edu ([128.30.2.149]:48035) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TXxN5-0001qN-EV for qemu-devel@nongnu.org; Mon, 12 Nov 2012 12:00:27 -0500 From: Nickolai Zeldovich Date: Mon, 12 Nov 2012 11:59:49 -0500 Message-Id: <1352739589-5264-1-git-send-email-nickolai@csail.mit.edu> Subject: [Qemu-devel] [PATCH v2] slirp: Don't crash on packets from 0.0.0.0/8. List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Cc: Jan Kiszka , Nickolai Zeldovich LWIP can generate packets with a source of 0.0.0.0, which triggers an assertion failure in arp_table_add(). Instead of crashing, simply return to avoid adding an invalid ARP table entry. Signed-off-by: Nickolai Zeldovich --- slirp/arp_table.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) Change from v1: adhere to qemu's code style (put braces around all indentation blocks). diff --git a/slirp/arp_table.c b/slirp/arp_table.c index 5d7b8ac..bf698c1 100644 --- a/slirp/arp_table.c +++ b/slirp/arp_table.c @@ -38,7 +38,9 @@ void arp_table_add(Slirp *slirp, uint32_t ip_addr, uint8_t ethaddr[ETH_ALEN]) ethaddr[3], ethaddr[4], ethaddr[5])); /* Check 0.0.0.0/8 invalid source-only addresses */ - assert((ip_addr & htonl(~(0xf << 28))) != 0); + if ((ip_addr & htonl(~(0xf << 28))) == 0) { + return; + } if (ip_addr == 0xffffffff || ip_addr == broadcast_addr) { /* Do not register broadcast addresses */ -- 1.7.10.4