From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from [140.186.70.92] (port=35980 helo=eggs.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1OnTc9-0005Pr-Pl for qemu-devel@nongnu.org; Mon, 23 Aug 2010 05:46:50 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.69) (envelope-from ) id 1OnTc8-00085o-Mf for qemu-devel@nongnu.org; Mon, 23 Aug 2010 05:46:49 -0400 Received: from mail.valinux.co.jp ([210.128.90.3]:60770) by eggs.gnu.org with esmtp (Exim 4.69) (envelope-from ) id 1OnTc8-00085Q-Do for qemu-devel@nongnu.org; Mon, 23 Aug 2010 05:46:48 -0400 Date: Mon, 23 Aug 2010 18:56:56 +0900 From: Isaku Yamahata Subject: Re: [Qemu-devel] [PATCH 2/2] pci init: Check if devfn exceeding the max devices number supported on bus Message-ID: <20100823095656.GG20428@valinux.co.jp> References: <20100823053342.2537.19008.stgit@k1> <20100823053350.2560.472.stgit@k1> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20100823053350.2560.472.stgit@k1> List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Ken CC Cc: mtosatti@redhat.com, qemu-devel@nongnu.org, kvm@vger.kernel.org How did you trigger the bug? I suppose parse_pci_devfn() in qdev-properties should check the error. Although I'm not objecting this patch itself, it's caller's bug. Just assert(devfn < PCIBUS_MAX_DEVICES)? On Mon, Aug 23, 2010 at 01:56:31PM +0800, Ken CC wrote: > > Check before trying subindexing. > > Signed-off-by: Ken CC > --- > hw/pci.c | 4 ++++ > 1 files changed, 4 insertions(+), 0 deletions(-) > > diff --git a/hw/pci.c b/hw/pci.c > index a09fbac..f6f00c6 100644 > --- a/hw/pci.c > +++ b/hw/pci.c > @@ -675,6 +675,10 @@ static PCIDevice *do_pci_register_device(PCIDevice *pci_dev, PCIBus *bus, > error_report("PCI: no slot/function available for %s, all in use", name); > return NULL; > found: ; > + } else if (devfn > PCIBUS_MAX_DEVICES - 1) { > + error_report("PCI: devfn is out of bus capacity." > + " Only %d devices supported.", PCIBUS_MAX_DEVICES); > + return NULL; > } else if (bus->devices[devfn]) { > error_report("PCI: slot %d function %d not available for %s, in use by %s", > PCI_SLOT(devfn), PCI_FUNC(devfn), name, bus->devices[devfn]->name); > > > -- yamahata