qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Markus Armbruster <armbru@redhat.com>
To: qemu-devel@nongnu.org
Cc: claudio.fontana@huawei.com, cam@cs.ualberta.ca,
	mlureau@redhat.com, david.marchand@6wind.com,
	pbonzini@redhat.com
Subject: [Qemu-devel] [PATCH v3 22/40] ivshmem: Simplify rejection of invalid peer ID from server
Date: Tue, 15 Mar 2016 19:34:37 +0100	[thread overview]
Message-ID: <1458066895-20632-23-git-send-email-armbru@redhat.com> (raw)
In-Reply-To: <1458066895-20632-1-git-send-email-armbru@redhat.com>

ivshmem_read() processes server messages.  These are 64 bit signed
integers.  -1 is shared memory setup, 16 bit unsigned is a peer ID,
anything else is invalid.

ivshmem_read() rejects invalid negative messages right away, silently.

Invalid positive messages get rejected only in resize_peers(), and
ivshmem_read() then prints the rather cryptic message "failed to
resize peers array".

Extend the first check to cover all invalid messages, make it report
"server sent invalid message", and drop the second check.

Now resize_peers() can't fail anymore; simplify.

Signed-off-by: Markus Armbruster <armbru@redhat.com>
Reviewed-by: Marc-André Lureau <marcandre.lureau@redhat.com>
---
 hw/misc/ivshmem.c | 61 ++++++++++++++++++++-----------------------------------
 1 file changed, 22 insertions(+), 39 deletions(-)

diff --git a/hw/misc/ivshmem.c b/hw/misc/ivshmem.c
index 61e21cd..703b3bf 100644
--- a/hw/misc/ivshmem.c
+++ b/hw/misc/ivshmem.c
@@ -39,7 +39,7 @@
 #define PCI_VENDOR_ID_IVSHMEM   PCI_VENDOR_ID_REDHAT_QUMRANET
 #define PCI_DEVICE_ID_IVSHMEM   0x1110
 
-#define IVSHMEM_MAX_PEERS G_MAXUINT16
+#define IVSHMEM_MAX_PEERS UINT16_MAX
 #define IVSHMEM_IOEVENTFD   0
 #define IVSHMEM_MSI     1
 
@@ -93,7 +93,7 @@ typedef struct IVShmemState {
     uint32_t ivshmem_64bit;
 
     Peer *peers;
-    int nb_peers; /* how many peers we have space for */
+    int nb_peers;               /* space in @peers[] */
 
     int vm_id;
     uint32_t vectors;
@@ -451,34 +451,21 @@ static void close_peer_eventfds(IVShmemState *s, int posn)
     s->peers[posn].nb_eventfds = 0;
 }
 
-/* this function increase the dynamic storage need to store data about other
- * peers */
-static int resize_peers(IVShmemState *s, int new_min_size)
+static void resize_peers(IVShmemState *s, int nb_peers)
 {
+    int old_nb_peers = s->nb_peers;
+    int i;
 
-    int j, old_size;
+    assert(nb_peers > old_nb_peers);
+    IVSHMEM_DPRINTF("bumping storage to %d peers\n", nb_peers);
 
-    /* limit number of max peers */
-    if (new_min_size <= 0 || new_min_size > IVSHMEM_MAX_PEERS) {
-        return -1;
-    }
-    if (new_min_size <= s->nb_peers) {
-        return 0;
-    }
-
-    old_size = s->nb_peers;
-    s->nb_peers = new_min_size;
+    s->peers = g_realloc(s->peers, nb_peers * sizeof(Peer));
+    s->nb_peers = nb_peers;
 
-    IVSHMEM_DPRINTF("bumping storage to %d peers\n", s->nb_peers);
-
-    s->peers = g_realloc(s->peers, s->nb_peers * sizeof(Peer));
-
-    for (j = old_size; j < s->nb_peers; j++) {
-        s->peers[j].eventfds = g_new0(EventNotifier, s->vectors);
-        s->peers[j].nb_eventfds = 0;
+    for (i = old_nb_peers; i < nb_peers; i++) {
+        s->peers[i].eventfds = g_new0(EventNotifier, s->vectors);
+        s->peers[i].nb_eventfds = 0;
     }
-
-    return 0;
 }
 
 static bool fifo_update_and_get(IVShmemState *s, const uint8_t *buf, int size,
@@ -590,25 +577,21 @@ static void ivshmem_read(void *opaque, const uint8_t *buf, int size)
         return;
     }
 
-    if (incoming_posn < -1) {
-        IVSHMEM_DPRINTF("invalid incoming_posn %" PRId64 "\n", incoming_posn);
-        return;
-    }
-
-    /* pick off s->server_chr->msgfd and store it, posn should accompany msg */
     incoming_fd = qemu_chr_fe_get_msgfd(s->server_chr);
     IVSHMEM_DPRINTF("posn is %" PRId64 ", fd is %d\n",
                     incoming_posn, incoming_fd);
 
-    /* make sure we have enough space for this peer */
+    if (incoming_posn < -1 || incoming_posn > IVSHMEM_MAX_PEERS) {
+        error_report("server sent invalid message %" PRId64,
+                     incoming_posn);
+        if (incoming_fd != -1) {
+            close(incoming_fd);
+        }
+        return;
+    }
+
     if (incoming_posn >= s->nb_peers) {
-        if (resize_peers(s, incoming_posn + 1) < 0) {
-            error_report("failed to resize peers array");
-            if (incoming_fd != -1) {
-                close(incoming_fd);
-            }
-            return;
-        }
+        resize_peers(s, incoming_posn + 1);
     }
 
     peer = &s->peers[incoming_posn];
-- 
2.4.3

  parent reply	other threads:[~2016-03-15 18:35 UTC|newest]

Thread overview: 49+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2016-03-15 18:34 [Qemu-devel] [PATCH v3 00/40] ivshmem: Fixes, cleanups, device model split Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 01/40] target-ppc: Document TOCTTOU in hugepage support Markus Armbruster
2016-03-18 15:04   ` Marc-André Lureau
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 02/40] ivshmem-server: Fix and clean up command line help Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 03/40] ivshmem-server: Don't overload POSIX shmem and file name Markus Armbruster
2016-03-18 15:04   ` Marc-André Lureau
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 04/40] qemu-doc: Fix ivshmem huge page example Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 05/40] event_notifier: Make event_notifier_init_fd() #ifdef CONFIG_EVENTFD Markus Armbruster
2016-03-21 12:48   ` Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 06/40] tests/libqos/pci-pc: Fix qpci_pc_iomap() to map BARs aligned Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 07/40] ivshmem-test: Improve test case /ivshmem/single Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 08/40] ivshmem-test: Clean up wait for devices to become operational Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 09/40] ivshmem-test: Improve test cases /ivshmem/server-* Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 10/40] ivshmem: Rewrite specification document Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 11/40] ivshmem: Add missing newlines to debug printfs Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 12/40] ivshmem: Compile debug prints unconditionally to prevent bit-rot Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 13/40] ivshmem: Clean up after commit 9940c32 Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 14/40] ivshmem: Drop ivshmem_event() stub Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 15/40] ivshmem: Don't destroy the chardev on version mismatch Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 16/40] ivshmem: Fix harmless misuse of Error Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 17/40] ivshmem: Failed realize() can leave migration blocker behind Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 18/40] ivshmem: Clean up register callbacks Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 19/40] ivshmem: Clean up MSI-X conditions Markus Armbruster
2016-03-18 15:04   ` Marc-André Lureau
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 20/40] ivshmem: Leave INTx alone when using MSI-X Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 21/40] ivshmem: Assert interrupts are set up once Markus Armbruster
2016-03-15 18:34 ` Markus Armbruster [this message]
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 23/40] ivshmem: Disentangle ivshmem_read() Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 24/40] ivshmem: Plug leaks on unplug, fix peer disconnect Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 25/40] ivshmem: Receive shared memory synchronously in realize() Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 26/40] ivshmem: Propagate errors through ivshmem_recv_setup() Markus Armbruster
2016-03-18 15:04   ` Marc-André Lureau
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 27/40] ivshmem: Rely on server sending the ID right after the version Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 28/40] ivshmem: Drop the hackish test for UNIX domain chardev Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 29/40] ivshmem: Simplify how we cope with short reads from server Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 30/40] ivshmem: Tighten check of property "size" Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 31/40] ivshmem: Implement shm=... with a memory backend Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 32/40] ivshmem: Simplify memory regions for BAR 2 (shared memory) Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 33/40] ivshmem: Inline check_shm_size() into its only caller Markus Armbruster
2016-03-18 15:04   ` Marc-André Lureau
2016-03-18 16:50     ` Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 34/40] qdev: New DEFINE_PROP_ON_OFF_AUTO Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 35/40] ivshmem: Replace int role_val by OnOffAuto master Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 36/40] ivshmem: Split ivshmem-plain, ivshmem-doorbell off ivshmem Markus Armbruster
2016-03-21 12:32   ` Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 37/40] ivshmem: Clean up after the previous commit Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 38/40] ivshmem: Drop ivshmem property x-memdev Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 39/40] ivshmem: Require master to have ID zero Markus Armbruster
2016-03-15 18:34 ` [Qemu-devel] [PATCH v3 40/40] contrib/ivshmem-server: Print "not for production" warning Markus Armbruster

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1458066895-20632-23-git-send-email-armbru@redhat.com \
    --to=armbru@redhat.com \
    --cc=cam@cs.ualberta.ca \
    --cc=claudio.fontana@huawei.com \
    --cc=david.marchand@6wind.com \
    --cc=mlureau@redhat.com \
    --cc=pbonzini@redhat.com \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).