From nobody Tue Feb 10 20:14:30 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) client-ip=208.118.235.17; envelope-from=qemu-devel-bounces+importer=patchew.org@nongnu.org; helo=lists.gnu.org; Authentication-Results: mx.zohomail.com; dkim=fail; spf=pass (zoho.com: domain of gnu.org designates 208.118.235.17 as permitted sender) smtp.mailfrom=qemu-devel-bounces+importer=patchew.org@nongnu.org Return-Path: Received: from lists.gnu.org (lists.gnu.org [208.118.235.17]) by mx.zohomail.com with SMTPS id 1501124220775814.100395040213; Wed, 26 Jul 2017 19:57:00 -0700 (PDT) Received: from localhost ([::1]:40929 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1daYyx-00028h-ES for importer@patchew.org; Wed, 26 Jul 2017 22:56:59 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:55098) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1daYly-00062M-8H for qemu-devel@nongnu.org; Wed, 26 Jul 2017 22:43:35 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1daYlx-0008Kj-26 for qemu-devel@nongnu.org; Wed, 26 Jul 2017 22:43:34 -0400 Received: from mail-qk0-x242.google.com ([2607:f8b0:400d:c09::242]:38228) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1daYlw-0008KY-TA; Wed, 26 Jul 2017 22:43:32 -0400 Received: by mail-qk0-x242.google.com with SMTP id v76so5570737qka.5; Wed, 26 Jul 2017 19:43:32 -0700 (PDT) Received: from yoga.offpageads.com ([138.117.48.223]) by smtp.gmail.com with ESMTPSA id g27sm13221147qtg.84.2017.07.26.19.43.28 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Wed, 26 Jul 2017 19:43:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=sender:from:to:cc:subject:date:message-id:in-reply-to:references :mime-version:content-transfer-encoding; bh=01ywgbYAmvRif3f1oGnhtntNv5w9K5Glmnc9tmFpHxE=; b=KFFbkNlhCFwtPCH+mJ4MFLK4y3IlUoEDJ51rbDiJn7bKv98K3t5B5IuoAbnm62z13T UaIYdV3NQbjxZg8S6sum55h05AdIOJdbrQy7yWeBnLVEcBSleBFa0m7HmGbH2hhh6trl zgwnnBWdKsTZo8Zdb4X0p4ZfXavwwnkQ/dgNSvj1+BJwyGHQV/971heXSP/UXjPi2idY kXPaG+b6DEkbQDmNmLWi4BBTfG7QbIeTatB7KYCmDXrYM2LYXv1QK07QUUgVS6DqXvrc 2C/PY6+hg0NDXjSkjhPHLifleK5EefXWAGYgFzp9b9kMl0Cyk5Vmsf/r1AaQKfU3O/u8 LqRw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:sender:from:to:cc:subject:date:message-id :in-reply-to:references:mime-version:content-transfer-encoding; bh=01ywgbYAmvRif3f1oGnhtntNv5w9K5Glmnc9tmFpHxE=; b=dlaQgC7EFvxA1id7r3h7f0I6DdphjEadWGcjasANoUy/KmPQXc/NSVgZ+fnR7H5xZu IwIe7LHmxey+rFu4tLGLkQEIttGx3pK1nTYWNAXXiIlhsRdcly+irg8394It7HIQQuUW eBddtVe7xrFr2ii54YJGvtBd76HDiKJmQUFXke/CQumMnouKlXgObMf3y90bPA6BTcNZ C8m/U+cI12r8RoCCpC5Mfndyj9LouyOFiCamsm9+kdvyCJq8KECHIbDfhnEtz3CJLV+z nE25CrsTklAoo9iXmgZmskb77Ewy6oKAZkUIYsFnNighI7Fv7O5gjslJno1p7yvhxraX sRjg== X-Gm-Message-State: AIVw110QpFGgw99ljxJB+4rSQJW4ztk+JJL2LBwWAnTwgFCYmcrUwVll qtrVfK5aDCkBYw== X-Received: by 10.55.80.6 with SMTP id e6mr4185074qkb.109.1501123412361; Wed, 26 Jul 2017 19:43:32 -0700 (PDT) From: =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= To: Peter Maydell , =?UTF-8?q?Marc-Andr=C3=A9=20Lureau?= , Paolo Bonzini , Eric Blake , David Gibson , Alexander Graf Date: Wed, 26 Jul 2017 23:42:23 -0300 Message-Id: <20170727024224.22900-19-f4bug@amsat.org> X-Mailer: git-send-email 2.13.3 In-Reply-To: <20170727024224.22900-1-f4bug@amsat.org> References: <20170727024224.22900-1-f4bug@amsat.org> MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-detected-operating-system: by eggs.gnu.org: Genre and OS details not recognized. X-Received-From: 2607:f8b0:400d:c09::242 Subject: [Qemu-devel] [PATCH for 2.10 v2 19/20] spapr_vio: fix overflow of qdevs in spapr_dt_vdevice() X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: qemu-trivial@nongnu.org, qemu-ppc@nongnu.org, =?UTF-8?q?Philippe=20Mathieu-Daud=C3=A9?= , qemu-devel@nongnu.org Errors-To: qemu-devel-bounces+importer=patchew.org@nongnu.org Sender: "Qemu-devel" X-ZohoMail-DKIM: fail (Header signature does not verify) X-ZohoMail: RDKM_2 RSF_0 Z_629925259 SPT_0 sizeof(ptr) was used instead of sizeof(struct)... also use g_malloc_n() which take care of possible type overflow. hw/ppc/spapr_vio.c:641:22: warning: The code calls sizeof() on a pointer ty= pe. This can produce an unexpected result qdevs =3D g_malloc(sizeof(qdev) * num); ^ ~~~~~~ hw/ppc/spapr_vio.c:648:23: warning: The code calls sizeof() on a pointer ty= pe. This can produce an unexpected result qsort(qdevs, num, sizeof(qdev), compare_reg); ^ ~~~~~~ Reported-by: Clang Static Analyzer Signed-off-by: Philippe Mathieu-Daud=C3=A9 --- hw/ppc/spapr_vio.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/hw/ppc/spapr_vio.c b/hw/ppc/spapr_vio.c index ea3bc8bd9e..9991b44c9f 100644 --- a/hw/ppc/spapr_vio.c +++ b/hw/ppc/spapr_vio.c @@ -638,14 +638,14 @@ void spapr_dt_vdevice(VIOsPAPRBus *bus, void *fdt) } =20 /* Copy out into an array of pointers */ - qdevs =3D g_malloc(sizeof(qdev) * num); + qdevs =3D g_malloc_n(num, sizeof(*qdev)); num =3D 0; QTAILQ_FOREACH(kid, &bus->bus.children, sibling) { qdevs[num++] =3D kid->child; } =20 /* Sort the array */ - qsort(qdevs, num, sizeof(qdev), compare_reg); + qsort(qdevs, num, sizeof(*qdev), compare_reg); =20 /* Hack alert. Give the devices to libfdt in reverse order, we happen * to know that will mean they are in forward order in the tree. */ --=20 2.13.3