From nobody Mon Feb 9 05:40:00 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of redhat.com designates 216.205.24.124 as permitted sender) client-ip=216.205.24.124; envelope-from=libvir-list-bounces@redhat.com; helo=us-smtp-delivery-124.mimecast.com; Authentication-Results: mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of redhat.com designates 216.205.24.124 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com; dmarc=pass(p=none dis=none) header.from=redhat.com ARC-Seal: i=1; a=rsa-sha256; t=1606913058; cv=none; d=zohomail.com; s=zohoarc; b=SmtlkLiVtoKZojj7Ei8yQmtwTv495mDgX2D8NPPwbL2aevp58YRTtz0uCvWW77Pfe1OCG+ICrLkgzLvEtqjqWEbuUHoqcTscp70pKSBiYtkby24HZDRvu/Jcrxizs86kMMr2wWDj8SqBLx5bu2fPvBWLf0tpq0h79O9+81DcWvE= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1606913058; h=Content-Type:Content-Transfer-Encoding:Date:From:In-Reply-To:List-Subscribe:List-Post:List-Id:List-Archive:List-Help:List-Unsubscribe:MIME-Version:Message-ID:References:Sender:Subject:To; bh=GJ6AsM0RbNIUPdOMkx+8haJLRaAfiJowPSqqgA0Il3Q=; b=a+3Yv7K/RjGa9ilCMNM/cQ122L8mPHoXon/voJyxZrCiW+rf2oNlvF5ppLYYM1/JYIkXePFwCXfKoEYvoDKcP9PzAQqn9hFiphliWTgXQ1k4RfTb9yf5D55+bVeWkpLgWI78iy88K5IySvZNre/diG7RjW9uwqkLmwsm8x9mAZY= ARC-Authentication-Results: i=1; mx.zohomail.com; dkim=pass; spf=pass (zohomail.com: domain of redhat.com designates 216.205.24.124 as permitted sender) smtp.mailfrom=libvir-list-bounces@redhat.com; dmarc=pass header.from= (p=none dis=none) header.from= Return-Path: Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [216.205.24.124]) by mx.zohomail.com with SMTPS id 1606913058154583.0536063008892; Wed, 2 Dec 2020 04:44:18 -0800 (PST) Received: from mimecast-mx01.redhat.com (mimecast-mx01.redhat.com [209.132.183.4]) (Using TLS) by relay.mimecast.com with ESMTP id us-mta-307-oBZ9H-mbOJ6pkwN4m1fU7A-1; Wed, 02 Dec 2020 07:44:14 -0500 Received: from smtp.corp.redhat.com (int-mx06.intmail.prod.int.phx2.redhat.com [10.5.11.16]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by mimecast-mx01.redhat.com (Postfix) with ESMTPS id EE5C78144E9; Wed, 2 Dec 2020 12:44:08 +0000 (UTC) Received: from colo-mx.corp.redhat.com (colo-mx01.intmail.prod.int.phx2.redhat.com [10.5.11.20]) by smtp.corp.redhat.com (Postfix) with ESMTPS id CDFF65C224; Wed, 2 Dec 2020 12:44:08 +0000 (UTC) Received: from lists01.pubmisc.prod.ext.phx2.redhat.com (lists01.pubmisc.prod.ext.phx2.redhat.com [10.5.19.33]) by colo-mx.corp.redhat.com (Postfix) with ESMTP id 9799C1809CA8; Wed, 2 Dec 2020 12:44:08 +0000 (UTC) Received: from smtp.corp.redhat.com (int-mx02.intmail.prod.int.phx2.redhat.com [10.5.11.12]) by lists01.pubmisc.prod.ext.phx2.redhat.com (8.13.8/8.13.8) with ESMTP id 0B2ChSQl003713 for ; Wed, 2 Dec 2020 07:43:28 -0500 Received: by smtp.corp.redhat.com (Postfix) id E9DAB60C0F; Wed, 2 Dec 2020 12:43:28 +0000 (UTC) Received: from fedora.redhat.com (ovpn-112-197.phx2.redhat.com [10.3.112.197]) by smtp.corp.redhat.com (Postfix) with ESMTP id AD59060BFA for ; Wed, 2 Dec 2020 12:43:28 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1606913057; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:mime-version:mime-version: content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references:list-id:list-help: list-unsubscribe:list-subscribe:list-post; bh=GJ6AsM0RbNIUPdOMkx+8haJLRaAfiJowPSqqgA0Il3Q=; b=JclqBacKY1beCBMLR0cwkdhSoTdB7X35Fx9Diq0JsfqReocRpTAvc7lP/NWnIxPWHiOgNG d3Tagbufejxk31tvVm+Q1EK0gLBmkw5EboZGBu617hSOJJdYU4eYGPPBrTeb9ywArODpXM uo6dfFwovawDQluI2CVVUHZUIjNF4Kc= X-MC-Unique: oBZ9H-mbOJ6pkwN4m1fU7A-1 From: John Ferlan To: libvir-list@redhat.com Subject: [PATCH 7/7] qemu: Fix some issues in virQEMUDriverConfigLoadNVRAMEntry Date: Wed, 2 Dec 2020 07:43:21 -0500 Message-Id: <20201202124321.765271-8-jferlan@redhat.com> In-Reply-To: <20201202124321.765271-1-jferlan@redhat.com> References: <20201202124321.765271-1-jferlan@redhat.com> MIME-Version: 1.0 X-Scanned-By: MIMEDefang 2.79 on 10.5.11.12 X-loop: libvir-list@redhat.com X-BeenThere: libvir-list@redhat.com X-Mailman-Version: 2.1.12 Precedence: junk List-Id: Development discussions about the libvirt library & tools List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: libvir-list-bounces@redhat.com Errors-To: libvir-list-bounces@redhat.com X-Scanned-By: MIMEDefang 2.79 on 10.5.11.16 Authentication-Results: relay.mimecast.com; auth=pass smtp.auth=CUSA124A263 smtp.mailfrom=libvir-list-bounces@redhat.com X-Mimecast-Spam-Score: 0 X-Mimecast-Originator: redhat.com Content-Transfer-Encoding: quoted-printable X-ZohoMail-DKIM: pass (identity @redhat.com) Content-Type: text/plain; charset="utf-8" Commit c4f4e195 fixed a double free, but if the code returns before we realloc the list and virFirmwareFreeList was called with cfg->nfirmwares > 0 (e.g. during virQEMUDriverConfigDispose), then it would be rather disasterous. So let's reinitialze that too to indicate the list is empty. Coverity pointed out that using nvram[0] as a guard to reallocating the list could lead to a possible NULL deref. While nvram[0] may always be true in this case, if it wasn't then the subsequent for loop would fail. Just reallocate always regardless - even if nfirmwares =3D=3D 0 as virFirmwareFreeList will free it for us anyway. Signed-off-by: John Ferlan Reviewed-by: J=C3=A1n Tomko --- src/qemu/qemu_conf.c | 5 ++--- 1 file changed, 2 insertions(+), 3 deletions(-) diff --git a/src/qemu/qemu_conf.c b/src/qemu/qemu_conf.c index cbdde0c0dc..690cfd39f9 100644 --- a/src/qemu/qemu_conf.c +++ b/src/qemu/qemu_conf.c @@ -835,6 +835,7 @@ virQEMUDriverConfigLoadNVRAMEntry(virQEMUDriverConfigPt= r cfg, =20 virFirmwareFreeList(cfg->firmwares, cfg->nfirmwares); cfg->firmwares =3D NULL; + cfg->nfirmwares =3D 0; =20 if (qemuFirmwareFetchConfigs(&fwList, privileged) < 0) return -1; @@ -843,13 +844,11 @@ virQEMUDriverConfigLoadNVRAMEntry(virQEMUDriverConfig= Ptr cfg, VIR_WARN("Obsolete nvram variable is set while firmware metada= ta " "files found. Note that the nvram config file variabl= e is " "going to be ignored."); - cfg->nfirmwares =3D 0; return 0; } =20 cfg->nfirmwares =3D virStringListLength((const char *const *)nvram= ); - if (nvram[0]) - cfg->firmwares =3D g_new0(virFirmwarePtr, cfg->nfirmwares); + cfg->firmwares =3D g_new0(virFirmwarePtr, cfg->nfirmwares); =20 for (i =3D 0; nvram[i] !=3D NULL; i++) { cfg->firmwares[i] =3D g_new0(virFirmware, 1); --=20 2.28.0