qemu-devel.nongnu.org archive mirror
 help / color / mirror / Atom feed
From: Paolo Bonzini <pbonzini@redhat.com>
To: qemu-devel@nongnu.org
Cc: Thomas Huth <thuth@redhat.com>
Subject: [Qemu-devel] [PULL 09/29] disas: Always initialize read_memory_inner_func properly
Date: Wed, 18 Oct 2017 18:12:01 +0200	[thread overview]
Message-ID: <1508343141-31835-10-git-send-email-pbonzini@redhat.com> (raw)
In-Reply-To: <1508343141-31835-1-git-send-email-pbonzini@redhat.com>

From: Thomas Huth <thuth@redhat.com>

I've recently seen this with valgrind while running the HMP tester:

==22373== Conditional jump or move depends on uninitialised value(s)
==22373==    at 0x4A41FD: arm_disas_set_info (cpu.c:504)
==22373==    by 0x3867A7: monitor_disas (disas.c:390)
==22373==    by 0x38E80E: memory_dump (monitor.c:1339)
==22373==    by 0x38FA43: handle_hmp_command (monitor.c:3123)
==22373==    by 0x38FB9E: qmp_human_monitor_command (monitor.c:613)
==22373==    by 0x4E3124: qmp_marshal_human_monitor_command (qmp-marshal.c:1736)
==22373==    by 0x769678: do_qmp_dispatch (qmp-dispatch.c:104)
==22373==    by 0x769678: qmp_dispatch (qmp-dispatch.c:131)
==22373==    by 0x38B734: handle_qmp_command (monitor.c:3853)
==22373==    by 0x76ED07: json_message_process_token (json-streamer.c:105)
==22373==    by 0x78D40A: json_lexer_feed_char (json-lexer.c:323)
==22373==    by 0x78D4CD: json_lexer_feed (json-lexer.c:373)
==22373==    by 0x38A08D: monitor_qmp_read (monitor.c:3895)

And indeed, in monitor_disas, the read_memory_inner_func variable was
not initialized, but arm_disas_set_info() expects this to be NULL
or a valid pointer. Let's properly set this to NULL in the
INIT_DISASSEMBLE_INFO to fix it in all functions that use the
disassemble_info struct.

Fixes: f7478a92dd9ee2276bfaa5b7317140d3f9d6a53b ("Fix Thumb-1 BE32 execution")
Signed-off-by: Thomas Huth <thuth@redhat.com>
Message-Id: <1506524313-20037-1-git-send-email-thuth@redhat.com>
---
 disas.c             | 1 -
 include/disas/bfd.h | 1 +
 2 files changed, 1 insertion(+), 1 deletion(-)

diff --git a/disas.c b/disas.c
index d6a1eb9..54eea3f 100644
--- a/disas.c
+++ b/disas.c
@@ -190,7 +190,6 @@ void target_disas(FILE *out, CPUState *cpu, target_ulong code,
 
     s.cpu = cpu;
     s.info.read_memory_func = target_read_memory;
-    s.info.read_memory_inner_func = NULL;
     s.info.buffer_vma = code;
     s.info.buffer_length = size;
     s.info.print_address_func = generic_print_address;
diff --git a/include/disas/bfd.h b/include/disas/bfd.h
index b01e002..d99da68 100644
--- a/include/disas/bfd.h
+++ b/include/disas/bfd.h
@@ -479,6 +479,7 @@ int generic_symbol_at_address(bfd_vma, struct disassemble_info *);
   (INFO).buffer_vma = 0, \
   (INFO).buffer_length = 0, \
   (INFO).read_memory_func = buffer_read_memory, \
+  (INFO).read_memory_inner_func = NULL, \
   (INFO).memory_error_func = perror_memory, \
   (INFO).print_address_func = generic_print_address, \
   (INFO).print_insn = NULL, \
-- 
1.8.3.1

  parent reply	other threads:[~2017-10-18 16:13 UTC|newest]

Thread overview: 32+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-10-18 16:11 [Qemu-devel] [PULL 00/29] Misc patches for 2017-10-18 Paolo Bonzini
2017-10-18 16:11 ` [Qemu-devel] [PULL 01/29] checkpatch: refine mode selection Paolo Bonzini
2017-10-18 16:11 ` [Qemu-devel] [PULL 02/29] scsi-disk: support reporting of rotation rate Paolo Bonzini
2017-10-18 16:11 ` [Qemu-devel] [PULL 03/29] ide: " Paolo Bonzini
2017-10-18 16:11 ` [Qemu-devel] [PULL 04/29] char: don't skip client cleanup if 'connected' flag is unset Paolo Bonzini
2017-10-18 16:11 ` [Qemu-devel] [PULL 05/29] exec: add page_mask for flatview_do_translate Paolo Bonzini
2017-10-18 16:11 ` [Qemu-devel] [PULL 06/29] exec: simplify address_space_get_iotlb_entry Paolo Bonzini
2017-10-18 16:11 ` [Qemu-devel] [PULL 07/29] memory: fix off-by-one error in memory_region_notify_one() Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 08/29] pc: make sure that plugged CPUs are of the same type Paolo Bonzini
2017-10-18 16:12 ` Paolo Bonzini [this message]
2017-10-18 16:12 ` [Qemu-devel] [PULL 10/29] build: remove CONFIG_LIBDECNUMBER Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 11/29] nios2: define tcg_env Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 12/29] docs/devel/loads-stores.rst: Document our various load and store APIs Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 13/29] tco: add trace events Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 14/29] target/i386: introduce x86_ld*_code Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 15/29] target/i386: trap on instructions longer than >15 bytes Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 16/29] memory: call log_start after region_add Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 17/29] kvm: fix alignment of ram address Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 18/29] kvm: tolerate non-existing slot for log_start/log_stop/log_sync Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 19/29] kvm: fix error message when failing to unregister slot Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 20/29] kvm: region_add and region_del is not called on updates Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 21/29] kvm: simplify kvm_align_section() Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 22/29] memory: reuse section_from_flat_range() Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 23/29] notdirty_mem_write: implement 8-byte accesses Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 24/29] watch_mem_write: " Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 25/29] qemu-pr-helper: use new libmultipath API Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 26/29] qdev: store DeviceState's canonical path to use when unparenting Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 27/29] Revert "qdev: Free QemuOpts when the QOM path goes away" Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 28/29] qdev: defer DEVICE_DEL event until instance_finalize() Paolo Bonzini
2017-10-18 16:12 ` [Qemu-devel] [PULL 29/29] scsi: reject configurations with logical block size > physical block size Paolo Bonzini
2017-10-18 17:13 ` [Qemu-devel] [PULL 00/29] Misc patches for 2017-10-18 no-reply
2017-10-19 15:47 ` Peter Maydell

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1508343141-31835-10-git-send-email-pbonzini@redhat.com \
    --to=pbonzini@redhat.com \
    --cc=qemu-devel@nongnu.org \
    --cc=thuth@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).