[Qemu-devel] [PATCH] vl: fix possible int overflow for qemu_timedate_diff()

Gonglei posted 1 patch 6 years, 2 months ago
Patches applied successfully (tree, apply log)
git fetch https://github.com/patchew-project/qemu tags/patchew/1517486372-22868-1-git-send-email-arei.gonglei@huawei.com
Test checkpatch passed
Test docker-build@min-glib passed
Test docker-mingw@fedora passed
Test docker-quick@centos6 passed
Test ppc passed
Test s390x passed
include/qemu-common.h | 2 +-
vl.c                  | 4 ++--
2 files changed, 3 insertions(+), 3 deletions(-)
[Qemu-devel] [PATCH] vl: fix possible int overflow for qemu_timedate_diff()
Posted by Gonglei 6 years, 2 months ago
From: shenghualong <shenghualong@huawei.com>

When the Windows guest users set the time to year 2099,
the return value of qemu_timedate_diff() will overflow
with variable clock mode as below format:

 <clock offset='variable' adjustment='-1201568405' basis='utc'>

Let's change the return value of qemu_timedate_diff() from
int to time_t to fix the possible overflow problem.

Signed-off-by: shenghualong <shenghualong@huawei.com>
Signed-off-by: Gonglei <arei.gonglei@huawei.com>
---
 include/qemu-common.h | 2 +-
 vl.c                  | 4 ++--
 2 files changed, 3 insertions(+), 3 deletions(-)

diff --git a/include/qemu-common.h b/include/qemu-common.h
index 05319b9..6fb80aa 100644
--- a/include/qemu-common.h
+++ b/include/qemu-common.h
@@ -33,7 +33,7 @@ int qemu_main(int argc, char **argv, char **envp);
 #endif
 
 void qemu_get_timedate(struct tm *tm, int offset);
-int qemu_timedate_diff(struct tm *tm);
+time_t qemu_timedate_diff(struct tm *tm);
 
 #define qemu_isalnum(c)		isalnum((unsigned char)(c))
 #define qemu_isalpha(c)		isalpha((unsigned char)(c))
diff --git a/vl.c b/vl.c
index e517a8d..9d225da 100644
--- a/vl.c
+++ b/vl.c
@@ -146,7 +146,7 @@ int nb_nics;
 NICInfo nd_table[MAX_NICS];
 int autostart;
 static int rtc_utc = 1;
-static int rtc_date_offset = -1; /* -1 means no change */
+static time_t rtc_date_offset = -1; /* -1 means no change */
 QEMUClockType rtc_clock;
 int vga_interface_type = VGA_NONE;
 static int full_screen = 0;
@@ -812,7 +812,7 @@ void qemu_get_timedate(struct tm *tm, int offset)
     }
 }
 
-int qemu_timedate_diff(struct tm *tm)
+time_t qemu_timedate_diff(struct tm *tm)
 {
     time_t seconds;
 
-- 
1.8.3.1



Re: [Qemu-devel] [PATCH] vl: fix possible int overflow for qemu_timedate_diff()
Posted by Paolo Bonzini 6 years, 2 months ago
On 01/02/2018 12:59, Gonglei wrote:
> From: shenghualong <shenghualong@huawei.com>
> 
> When the Windows guest users set the time to year 2099,
> the return value of qemu_timedate_diff() will overflow
> with variable clock mode as below format:
> 
>  <clock offset='variable' adjustment='-1201568405' basis='utc'>
> 
> Let's change the return value of qemu_timedate_diff() from
> int to time_t to fix the possible overflow problem.
> 
> Signed-off-by: shenghualong <shenghualong@huawei.com>
> Signed-off-by: Gonglei <arei.gonglei@huawei.com>

Thanks, this makes sense.  However, looking at the users, you should
also change the type of:

- the diff variable in hw/timer/m48t59.c function set_alarm;

- the offset argument of the RTC_CHANGE QAPI event (to int64)

- the sec_offset and alm_sec fields of MenelausState in hw/timer/twl92230.c

- the offset argument of qemu_get_timedate.

Thanks,

Paolo

> ---
>  include/qemu-common.h | 2 +-
>  vl.c                  | 4 ++--
>  2 files changed, 3 insertions(+), 3 deletions(-)
> 
> diff --git a/include/qemu-common.h b/include/qemu-common.h
> index 05319b9..6fb80aa 100644
> --- a/include/qemu-common.h
> +++ b/include/qemu-common.h
> @@ -33,7 +33,7 @@ int qemu_main(int argc, char **argv, char **envp);
>  #endif
>  
>  void qemu_get_timedate(struct tm *tm, int offset);
> -int qemu_timedate_diff(struct tm *tm);
> +time_t qemu_timedate_diff(struct tm *tm);
>  
>  #define qemu_isalnum(c)		isalnum((unsigned char)(c))
>  #define qemu_isalpha(c)		isalpha((unsigned char)(c))
> diff --git a/vl.c b/vl.c
> index e517a8d..9d225da 100644
> --- a/vl.c
> +++ b/vl.c
> @@ -146,7 +146,7 @@ int nb_nics;
>  NICInfo nd_table[MAX_NICS];
>  int autostart;
>  static int rtc_utc = 1;
> -static int rtc_date_offset = -1; /* -1 means no change */
> +static time_t rtc_date_offset = -1; /* -1 means no change */
>  QEMUClockType rtc_clock;
>  int vga_interface_type = VGA_NONE;
>  static int full_screen = 0;
> @@ -812,7 +812,7 @@ void qemu_get_timedate(struct tm *tm, int offset)
>      }
>  }
>  
> -int qemu_timedate_diff(struct tm *tm)
> +time_t qemu_timedate_diff(struct tm *tm)
>  {
>      time_t seconds;
>  
> 


Re: [Qemu-devel] [PATCH] vl: fix possible int overflow for qemu_timedate_diff()
Posted by Gonglei (Arei) 6 years, 2 months ago
> -----Original Message-----
> From: Paolo Bonzini [mailto:pbonzini@redhat.com]
> Sent: Tuesday, February 06, 2018 11:52 PM
> To: Gonglei (Arei); qemu-devel@nongnu.org
> Cc: shenghualong
> Subject: Re: [PATCH] vl: fix possible int overflow for qemu_timedate_diff()
> 
> On 01/02/2018 12:59, Gonglei wrote:
> > From: shenghualong <shenghualong@huawei.com>
> >
> > When the Windows guest users set the time to year 2099,
> > the return value of qemu_timedate_diff() will overflow
> > with variable clock mode as below format:
> >
> >  <clock offset='variable' adjustment='-1201568405' basis='utc'>
> >
> > Let's change the return value of qemu_timedate_diff() from
> > int to time_t to fix the possible overflow problem.
> >
> > Signed-off-by: shenghualong <shenghualong@huawei.com>
> > Signed-off-by: Gonglei <arei.gonglei@huawei.com>
> 
> Thanks, this makes sense.  However, looking at the users, you should
> also change the type of:
> 
> - the diff variable in hw/timer/m48t59.c function set_alarm;
> 
> - the offset argument of the RTC_CHANGE QAPI event (to int64)
> 
> - the sec_offset and alm_sec fields of MenelausState in hw/timer/twl92230.c
> 
> - the offset argument of qemu_get_timedate.
> 
OK, will do.

Thanks,
-Gonglei

> Thanks,
> 
> Paolo
> 
> > ---
> >  include/qemu-common.h | 2 +-
> >  vl.c                  | 4 ++--
> >  2 files changed, 3 insertions(+), 3 deletions(-)
> >
> > diff --git a/include/qemu-common.h b/include/qemu-common.h
> > index 05319b9..6fb80aa 100644
> > --- a/include/qemu-common.h
> > +++ b/include/qemu-common.h
> > @@ -33,7 +33,7 @@ int qemu_main(int argc, char **argv, char **envp);
> >  #endif
> >
> >  void qemu_get_timedate(struct tm *tm, int offset);
> > -int qemu_timedate_diff(struct tm *tm);
> > +time_t qemu_timedate_diff(struct tm *tm);
> >
> >  #define qemu_isalnum(c)		isalnum((unsigned char)(c))
> >  #define qemu_isalpha(c)		isalpha((unsigned char)(c))
> > diff --git a/vl.c b/vl.c
> > index e517a8d..9d225da 100644
> > --- a/vl.c
> > +++ b/vl.c
> > @@ -146,7 +146,7 @@ int nb_nics;
> >  NICInfo nd_table[MAX_NICS];
> >  int autostart;
> >  static int rtc_utc = 1;
> > -static int rtc_date_offset = -1; /* -1 means no change */
> > +static time_t rtc_date_offset = -1; /* -1 means no change */
> >  QEMUClockType rtc_clock;
> >  int vga_interface_type = VGA_NONE;
> >  static int full_screen = 0;
> > @@ -812,7 +812,7 @@ void qemu_get_timedate(struct tm *tm, int offset)
> >      }
> >  }
> >
> > -int qemu_timedate_diff(struct tm *tm)
> > +time_t qemu_timedate_diff(struct tm *tm)
> >  {
> >      time_t seconds;
> >
> >