From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([208.118.235.92]:55052) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TkdeF-0004P0-CP for qemu-devel@nongnu.org; Mon, 17 Dec 2012 11:34:36 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1TkdeE-0002BV-60 for qemu-devel@nongnu.org; Mon, 17 Dec 2012 11:34:35 -0500 Received: from mx1.redhat.com ([209.132.183.28]:6552) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1TkdeD-0002AT-VF for qemu-devel@nongnu.org; Mon, 17 Dec 2012 11:34:34 -0500 Received: from int-mx01.intmail.prod.int.phx2.redhat.com (int-mx01.intmail.prod.int.phx2.redhat.com [10.5.11.11]) by mx1.redhat.com (8.14.4/8.14.4) with ESMTP id qBHGYWWL004654 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK) for ; Mon, 17 Dec 2012 11:34:32 -0500 Date: Mon, 17 Dec 2012 22:04:29 +0530 From: Amit Shah Message-ID: <20121217163429.GE21639@amit.redhat.com> References: <93bab39d85368c53633059501e58dc726d50c457.1355396592.git.amit.shah@redhat.com> <87sj74stw6.fsf@blackfin.pond.sub.org> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <87sj74stw6.fsf@blackfin.pond.sub.org> Subject: Re: [Qemu-devel] [PATCH 1/1] virtio-serial-bus: send_control_msg should not deal with cpkts List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Markus Armbruster Cc: qemu list On (Mon) 17 Dec 2012 [14:14:17], Markus Armbruster wrote: > Amit Shah writes: > > > Stuff the cpkt before calling send_control_msg(). it should not be > > concerned about contents, just send across the buffer. > > > > A few code refactorings recently have made mkaing this change easier > > than earlier. Ugh, I'll fix the typo and incoherent language here before merging. > > Coverity and clang have flagged this code several times in the past > > (cpkt->id not set before send_control_event() passed it on to > > send_control_msg()). This will finally eliminate the false-positive. > > > > CC: Markus Armbruster > > Signed-off-by: Amit Shah > > Patch makes sense to me, and the Coverity defect report is gone. Thanks for checking! > However, it now worries find_port_by_id() in remove_port() could return > a null pointer, which is then dereferenced. No idea why it didn't > report that before. Obvious suppressor: > > diff --git a/hw/virtio-serial-bus.c b/hw/virtio-serial-bus.c > index 47d0481..7ff7505 100644 > --- a/hw/virtio-serial-bus.c > +++ b/hw/virtio-serial-bus.c > @@ -826,6 +826,7 @@ static void remove_port(VirtIOSerial *vser, uint32_t port_id) > vser->ports_map[i] &= ~(1U << (port_id % 32)); > > port = find_port_by_id(vser, port_id); > + assert(port); > /* Flush out any unconsumed buffers first */ > discard_vq_data(port->ovq, &port->vser->vdev); remove_port() is called by the hot-unplug qdev callback, and if the port's missing from our tailq, something's gone wrong anyway. So this patch makes sense too. > Reviewed-by: Markus Armbruster Thanks! Amit