From: Markus Armbruster <armbru@redhat.com>
To: qemu-devel@nongnu.org
Subject: [Qemu-devel] [PULL 10/25] qobject: qobject_from_jsonv() is dangerous, hide it away
Date: Thu, 16 Aug 2018 10:36:46 +0200 [thread overview]
Message-ID: <20180816083701.3932-11-armbru@redhat.com> (raw)
In-Reply-To: <20180816083701.3932-1-armbru@redhat.com>
qobject_from_jsonv() takes ownership of %p arguments. On failure, we
can't generally know whether we failed before or after %p, so
ownership becomes indeterminate. To avoid leaks, callers passing %p
must terminate on error, e.g. by passing &error_abort. Trap for the
unwary; document and give the function internal linkage.
Signed-off-by: Markus Armbruster <armbru@redhat.com>
Reviewed-by: Philippe Mathieu-Daudé <f4bug@amsat.org>
Reviewed-by: Eric Blake <eblake@redhat.com>
Message-Id: <20180806065344.7103-11-armbru@redhat.com>
---
include/qapi/qmp/qjson.h | 2 --
qobject/qjson.c | 13 ++++++++++++-
2 files changed, 12 insertions(+), 3 deletions(-)
diff --git a/include/qapi/qmp/qjson.h b/include/qapi/qmp/qjson.h
index dce78583dc..5ebbe5a118 100644
--- a/include/qapi/qmp/qjson.h
+++ b/include/qapi/qmp/qjson.h
@@ -15,8 +15,6 @@
#define QJSON_H
QObject *qobject_from_json(const char *string, Error **errp);
-QObject *qobject_from_jsonv(const char *string, va_list *ap, Error **errp)
- GCC_FMT_ATTR(1, 0);
QObject *qobject_from_vjsonf_nofail(const char *string, va_list ap)
GCC_FMT_ATTR(1, 0);
diff --git a/qobject/qjson.c b/qobject/qjson.c
index 2e450231ff..ab4040f235 100644
--- a/qobject/qjson.c
+++ b/qobject/qjson.c
@@ -39,7 +39,18 @@ static void parse_json(JSONMessageParser *parser, GQueue *tokens)
s->result = json_parser_parse_err(tokens, s->ap, &s->err);
}
-QObject *qobject_from_jsonv(const char *string, va_list *ap, Error **errp)
+/*
+ * Parse @string as JSON value.
+ * If @ap is non-null, interpolate %-escapes.
+ * Takes ownership of %p arguments.
+ * On success, return the JSON value.
+ * On failure, store an error through @errp and return NULL.
+ * Ownership of %p arguments becomes indeterminate then. To avoid
+ * leaks, callers passing %p must terminate on error, e.g. by passing
+ * &error_abort.
+ */
+static QObject *qobject_from_jsonv(const char *string, va_list *ap,
+ Error **errp)
{
JSONParsingState state = {};
--
2.17.1
next prev parent reply other threads:[~2018-08-16 8:37 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2018-08-16 8:36 [Qemu-devel] [PULL 00/25] Testing patches for 2018-08-16 Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 01/25] libqtest: Rename functions to send QMP messages Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 02/25] libqtest: Clean up how we read device_del messages Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 03/25] libqtest: Clean up how we read the QMP greeting Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 04/25] libqtest: Remove qtest_qmp_discard_response() & friends Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 05/25] libqtest: Document calling conventions Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 06/25] qobject: Replace qobject_from_jsonf() by qobject_from_jsonf_nofail() Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 07/25] qobject: New qobject_from_vjsonf_nofail(), qdict_from_vjsonf_nofail() Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 08/25] libqtest: Simplify qmp_fd_vsend() a bit Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 09/25] test-qobject-input-visitor: Avoid format string ambiguity Markus Armbruster
2018-08-16 8:36 ` Markus Armbruster [this message]
2018-08-16 8:36 ` [Qemu-devel] [PULL 11/25] tests: Pass literal format strings directly to qmp_FOO() Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 12/25] tests: Clean up string interpolation into QMP input (simple cases) Markus Armbruster
2018-08-24 22:41 ` Eric Blake
2018-08-27 4:15 ` Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 13/25] cpu-plug-test: Don't pass integers as strings to device_add Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 14/25] tests: Clean up string interpolation around qtest_qmp_device_add() Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 15/25] migration-test: Make wait_command() return the "return" member Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 16/25] tests: New helper qtest_qmp_receive_success() Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 17/25] migration-test: Make wait_command() cope with '%' Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 18/25] migration-test: Clean up string interpolation into QMP, part 1 Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 19/25] migration-test: Clean up string interpolation into QMP, part 2 Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 20/25] migration-test: Clean up string interpolation into QMP, part 3 Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 21/25] libqtest: Enable compile-time format string checking Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 22/25] libqtest: Replace qtest_startf() by qtest_initf() Markus Armbruster
2018-08-16 8:36 ` [Qemu-devel] [PULL 23/25] libqtest: Rename qtest_FOOv() to qtest_vFOO() for consistency Markus Armbruster
2018-08-16 8:37 ` [Qemu-devel] [PULL 24/25] tests/libqtest: Improve kill_qemu() Markus Armbruster
2018-08-16 8:37 ` [Qemu-devel] [PULL 25/25] libqtest: Improve error reporting for bad read from QEMU Markus Armbruster
2018-08-16 9:49 ` [Qemu-devel] [PULL 00/25] Testing patches for 2018-08-16 Peter Maydell
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20180816083701.3932-11-armbru@redhat.com \
--to=armbru@redhat.com \
--cc=qemu-devel@nongnu.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).