From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mailman by lists.gnu.org with tmda-scanned (Exim 4.43) id 1LVXeM-00068t-7D for qemu-devel@nongnu.org; Fri, 06 Feb 2009 15:50:10 -0500 Received: from exim by lists.gnu.org with spam-scanned (Exim 4.43) id 1LVXeI-00066i-Uc for qemu-devel@nongnu.org; Fri, 06 Feb 2009 15:50:09 -0500 Received: from [199.232.76.173] (port=46853 helo=monty-python.gnu.org) by lists.gnu.org with esmtp (Exim 4.43) id 1LVXeI-00066Z-MV for qemu-devel@nongnu.org; Fri, 06 Feb 2009 15:50:06 -0500 Received: from moutng.kundenserver.de ([212.227.126.186]:62096) by monty-python.gnu.org with esmtp (Exim 4.60) (envelope-from ) id 1LVXeI-0005t7-1h for qemu-devel@nongnu.org; Fri, 06 Feb 2009 15:50:06 -0500 Received: from localhost ([127.0.0.1] ident=stefan) by flocke.weilnetz.de with esmtp (Exim 4.69) (envelope-from ) id 1LVXeD-0000f0-LT for qemu-devel@nongnu.org; Fri, 06 Feb 2009 21:50:01 +0100 Message-ID: <498CA279.401@mail.berlios.de> Date: Fri, 06 Feb 2009 21:50:01 +0100 From: Stefan Weil MIME-Version: 1.0 Subject: [Qemu-devel] [PATCH] Fix SIGSEGV crash in slirp networking code Content-Type: multipart/mixed; boundary="------------060801040208080307050707" Reply-To: qemu-devel@nongnu.org List-Id: qemu-devel.nongnu.org List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: QEMU Developers This is a multi-part message in MIME format. --------------060801040208080307050707 Content-Type: text/plain; charset=ISO-8859-15 Content-Transfer-Encoding: 7bit Hello, this patch fixes a bug which was introduced in r6288. Please apply it to Qemu trunk. See this discussion for details: http://lists.gnu.org/archive/cgi-bin/namazu.cgi?query=Regression+in+networking+code+(SIGSEGV)&submit=Search&idxname=qemu-devel Regards Stefan Weil --------------060801040208080307050707 Content-Type: text/x-diff; name="slirp.patch" Content-Transfer-Encoding: 7bit Content-Disposition: inline; filename="slirp.patch" Fix SIGSEGV crash in networking code (bug was introduced in r6288). Thanks to Gleb Natapov for finding this fix. Signed-off-by: Stefan Weil Index: trunk/slirp/ip_input.c =================================================================== --- trunk.orig/slirp/ip_input.c 2009-02-05 22:16:34.000000000 +0100 +++ trunk/slirp/ip_input.c 2009-02-05 22:17:02.000000000 +0100 @@ -392,8 +392,7 @@ * into the new buffer. */ if (m->m_flags & M_EXT) { - int delta; - delta = (char *)ip - m->m_dat; + int delta = (char *)q - m->m_dat; q = (struct ipasfrag *)(m->m_ext + delta); } --------------060801040208080307050707--