qemu-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Qemu-devel] [PATCH 1/4] hw/net/can: Fix segfaults when using the device


From: Thomas Huth
Subject: [Qemu-devel] [PATCH 1/4] hw/net/can: Fix segfaults when using the devices without bus
Date: Fri, 16 Mar 2018 10:51:29 +0100

The CAN devices can currently be used to crash QEMU, e.g.:

$ x86_64-softmmu/qemu-system-x86_64 -device kvaser_pci
Segmentation fault (core dumped)

So we've got to add a proper check here that the corresponding
bus is available.

Signed-off-by: Thomas Huth <address@hidden>
---
 hw/net/can/can_sja1000.c  | 4 ++++
 scripts/device-crash-test | 3 ---
 2 files changed, 4 insertions(+), 3 deletions(-)

diff --git a/hw/net/can/can_sja1000.c b/hw/net/can/can_sja1000.c
index 6293233..9a85038 100644
--- a/hw/net/can/can_sja1000.c
+++ b/hw/net/can/can_sja1000.c
@@ -866,6 +866,10 @@ int can_sja_connect_to_bus(CanSJA1000State *s, CanBusState 
*bus)
 {
     s->bus_client.info = &can_sja_bus_client_info;
 
+    if (!bus) {
+        return -EINVAL;
+    }
+
     if (can_bus_insert_client(bus, &s->bus_client) < 0) {
         return -1;
     }
diff --git a/scripts/device-crash-test b/scripts/device-crash-test
index f04f349..7ff351d 100755
--- a/scripts/device-crash-test
+++ b/scripts/device-crash-test
@@ -223,9 +223,6 @@ ERROR_WHITELIST = [
     {'exitcode':-11, 'device':'sb16', 'loglevel':logging.ERROR, 
'expected':True},
     {'exitcode':-11, 'device':'cs4231a', 'loglevel':logging.ERROR, 
'expected':True},
     {'exitcode':-11, 'machine':'isapc', 'device':'.*-iommu', 
'loglevel':logging.ERROR, 'expected':True},
-    {'exitcode':-11, 'device':'mioe3680_pci', 'loglevel':logging.ERROR, 
'expected':True},
-    {'exitcode':-11, 'device':'pcm3680_pci', 'loglevel':logging.ERROR, 
'expected':True},
-    {'exitcode':-11, 'device':'kvaser_pci', 'loglevel':logging.ERROR, 
'expected':True},
 
     # everything else (including SIGABRT and SIGSEGV) will be a fatal error:
     {'exitcode':None, 'fatal':True, 'loglevel':logging.FATAL},
-- 
1.8.3.1




reply via email to

[Prev in Thread] Current Thread [Next in Thread]