All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Philippe Mathieu-Daudé" <philmd@redhat.com>
To: "Marc-André Lureau" <marcandre.lureau@redhat.com>,
	"Paolo Bonzini" <pbonzini@redhat.com>
Cc: qemu-devel <qemu-devel@nongnu.org>,
	Prasad J Pandit <pjp@fedoraproject.org>,
	Jason Wang <jasowang@redhat.com>,
	Anthony Perard <anthony.perard@citrix.com>,
	qemu-ppc@nongnu.org, Stefan Berger <stefanb@linux.ibm.com>,
	David Gibson <david@gibson.dropbear.id.au>,
	Gerd Hoffmann <kraxel@redhat.com>,
	Zhang Chen <zhangckid@gmail.com>,
	xen-devel@lists.xenproject.org, Cornelia Huck <cohuck@redhat.com>,
	Samuel Thibault <samuel.thibault@ens-lyon.org>,
	Christian Borntraeger <borntraeger@de.ibm.com>,
	Amit Shah <amit@kernel.org>,
	Li Zhijian <lizhijian@cn.fujitsu.com>,
	Corey Minyard <minyard@acm.org>,
	"Michael S. Tsirkin" <mst@redhat.com>,
	Paul Durrant <paul.durrant@citrix.com>,
	Halil Pasic <pasic@linux.ibm.com>,
	Stefano Stabellini <sstabellini@kernel.org>,
	qemu-s390x@nongnu.org, Pavel Dovgalyuk <pavel.dovgaluk@ispras.ru>
Subject: Re: [Qemu-devel] [PATCH v3 02/25] chardev: Assert IOCanReadHandler can not be negative
Date: Fri, 22 Feb 2019 01:39:04 +0100	[thread overview]
Message-ID: <74dc80bc-d2cd-c79d-4787-6870b450a505@redhat.com> (raw)
In-Reply-To: <68f7233c-8b95-8782-27a7-106fc2997646@redhat.com>

On 2/20/19 12:13 PM, Philippe Mathieu-Daudé wrote:
> On 2/20/19 11:03 AM, Marc-André Lureau wrote:
>> Hi
>>
>> On Wed, Feb 20, 2019 at 2:03 AM Philippe Mathieu-Daudé
>> <philmd@redhat.com> wrote:
>>>
>>> The backend should not return a negative length to read.
>>> We will later change the prototype of IOCanReadHandler to return an
>>> unsigned length. Meanwhile make sure the return length is positive.
>>>
>>> Suggested-by: Paolo Bonzini <pbonzini@redhat.com>
>>> Signed-off-by: Philippe Mathieu-Daudé <philmd@redhat.com>
>>
>> In such patch, you should do extensive review of existing callbacks,
>> or find a convincing argument that this can't break.
> 
> Argh I missed that.
> 
>> The problem is there are a lot of can_read callbacks, and it's not
>> trivial. The *first* of git-grep is rng_egd_chr_can_read()
>>
>>  57     QSIMPLEQ_FOREACH(req, &s->parent.requests, next) {
>>  58         size += req->size - req->offset;
>>  59     }
>>  60
>>  61     return size;
>>
>> Clearly not obvious if it returns >= 0.
>>
>> Another approach is to look at the caller and the return value
>> handling. If none handle negative values (or would have wrong
>> behaviour with negative values), the assert() is perhaps justified, as
>> it could prevent from doing more harm.
> 
> I'll go and audit all of them.

Actually I already did the work, but it is in the part #2 after this
series, as suggested by Paolo:

https://lists.gnu.org/archive/html/qemu-devel/2018-10/msg02294.html

I'll simply cherry-pick the commit from series #2 before this patch.

Thanks,

Phil.

>>> ---
>>>  chardev/char.c | 5 ++++-
>>>  1 file changed, 4 insertions(+), 1 deletion(-)
>>>
>>> diff --git a/chardev/char.c b/chardev/char.c
>>> index f6d61fa5f8..71ecd32b25 100644
>>> --- a/chardev/char.c
>>> +++ b/chardev/char.c
>>> @@ -159,12 +159,15 @@ int qemu_chr_write(Chardev *s, const uint8_t *buf, int len, bool write_all)
>>>  int qemu_chr_be_can_write(Chardev *s)
>>>  {
>>>      CharBackend *be = s->be;
>>> +    int receivable_bytes;
>>>
>>>      if (!be || !be->chr_can_read) {
>>>          return 0;
>>>      }
>>>
>>> -    return be->chr_can_read(be->opaque);
>>> +    receivable_bytes = be->chr_can_read(be->opaque);
>>> +    assert(receivable_bytes >= 0);
>>> +    return receivable_bytes;
>>>  }
>>>
>>>  void qemu_chr_be_write_impl(Chardev *s, uint8_t *buf, int len)
>>> --
>>> 2.20.1
>>>

  reply	other threads:[~2019-02-22  0:39 UTC|newest]

Thread overview: 132+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2019-02-20  1:02 [Qemu-devel] [PATCH v3 00/25] chardev: Convert qemu_chr_write() to take a size_t argument Philippe Mathieu-Daudé
2019-02-20  1:02 ` Philippe Mathieu-Daudé
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 01/25] chardev: Simplify IOWatchPoll::fd_can_read as a GSourceFunc Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20  9:45   ` [Qemu-devel] " Marc-André Lureau
2019-02-20  9:45     ` Marc-André Lureau
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 02/25] chardev: Assert IOCanReadHandler can not be negative Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 10:03   ` [Qemu-devel] " Marc-André Lureau
2019-02-20 11:13     ` Philippe Mathieu-Daudé
2019-02-20 11:13       ` Philippe Mathieu-Daudé
2019-02-22  0:39       ` Philippe Mathieu-Daudé [this message]
2019-02-22  0:39       ` Philippe Mathieu-Daudé
2019-02-20 10:03   ` Marc-André Lureau
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 03/25] chardev/wctablet: Use unsigned type to hold unsigned value Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20  7:32   ` [Qemu-devel] " Gerd Hoffmann
2019-02-20  7:32   ` Gerd Hoffmann
2019-02-20 10:17   ` Marc-André Lureau
2019-02-20 10:17   ` [Qemu-devel] " Marc-André Lureau
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 04/25] chardev: Let qemu_chr_be_can_write() return a size_t types Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 10:40   ` Marc-André Lureau
2019-02-20 10:40   ` [Qemu-devel] " Marc-André Lureau
2019-02-20 11:26     ` Philippe Mathieu-Daudé
2019-02-20 11:26       ` Philippe Mathieu-Daudé
2019-02-20 13:28       ` [Qemu-devel] " Marc-André Lureau
2019-02-20 13:28         ` Marc-André Lureau
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 05/25] gdbstub: Use size_t for strlen() return value Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 10:57   ` Marc-André Lureau
2019-02-20 10:57   ` [Qemu-devel] " Marc-André Lureau
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 06/25] gdbstub: Use size_t to hold GDBState::last_packet_len Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 10:59   ` [Qemu-devel] " Marc-André Lureau
2019-02-20 10:59     ` Marc-André Lureau
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 07/25] gdbstub: Let put_buffer() use size_t Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 11:02   ` [Qemu-devel] " Marc-André Lureau
2019-02-20 11:02     ` Marc-André Lureau
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 08/25] ui/gtk: Remove pointless cast Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20  7:32   ` [Qemu-devel] " Gerd Hoffmann
2019-02-20  7:32     ` Gerd Hoffmann
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 09/25] vhost-user: Express sizeof with size_t Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 11:06   ` Marc-André Lureau
2019-02-20 11:06   ` [Qemu-devel] " Marc-André Lureau
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 10/25] usb-redir: Verify usbredirparser_write get called with positive count Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20  7:32   ` [Qemu-devel] " Gerd Hoffmann
2019-02-20  7:32     ` Gerd Hoffmann
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 11/25] xen: Let xencons_send() take a 'size' argument Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 11:07   ` [Qemu-devel] " Marc-André Lureau
2019-02-20 11:07     ` Marc-André Lureau
2019-02-21  9:34   ` [Qemu-devel] " Paul Durrant
2019-02-21  9:34     ` Paul Durrant
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 12/25] xen: Let buffer_append() return the size consumed Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 11:13   ` [Qemu-devel] " Marc-André Lureau
2019-02-20 11:13     ` Marc-André Lureau
2019-02-20  1:02 ` [Qemu-devel] [RFC PATCH v3 13/25] xen: Let buffer_append() return a size_t Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-21  9:54   ` [Qemu-devel] " Paul Durrant
2019-02-21  9:54     ` Paul Durrant
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 14/25] virtio-serial: Let VirtIOSerialPortClass::have_data() use size_t Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 11:21   ` [Qemu-devel] " Marc-André Lureau
2019-02-20 11:21     ` Marc-André Lureau
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 15/25] spapr-vty: Let vty_putchars() " Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20  1:39   ` [Qemu-devel] " David Gibson
2019-02-20  1:39     ` David Gibson
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 16/25] tpm: Use size_t to hold sizes Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 11:22   ` [Qemu-devel] " Marc-André Lureau
2019-02-20 11:22     ` Marc-André Lureau
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 17/25] net/filter-mirror: Use size_t Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 11:23   ` [Qemu-devel] " Marc-André Lureau
2019-02-20 11:23     ` Marc-André Lureau
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 18/25] s390x/3270: Let insert_IAC_escape_char() use size_t Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20  9:37   ` [Qemu-devel] " Cornelia Huck
2019-02-20  9:37   ` Cornelia Huck
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 19/25] s390/ebcdic: Use size_t to iterate over arrays Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20  9:40   ` [Qemu-devel] " Cornelia Huck
2019-02-20  9:40     ` Cornelia Huck
2019-02-20 11:37     ` [Qemu-devel] " Philippe Mathieu-Daudé
2019-02-20 11:37     ` Philippe Mathieu-Daudé
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 20/25] s390x/sclp: Use a const variable to improve readability Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 10:53   ` [Qemu-devel] " Cornelia Huck
2019-02-20 10:53     ` Cornelia Huck
2019-03-08 19:12     ` [Qemu-devel] " Philippe Mathieu-Daudé
2019-03-08 19:12       ` Philippe Mathieu-Daudé
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 21/25] s390x/sclp: Use size_t in process_mdb() Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 10:53   ` [Qemu-devel] " Cornelia Huck
2019-02-20 10:53     ` Cornelia Huck
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 22/25] s390x/sclp: Let write_console_data() take a size_t Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 10:54   ` [Qemu-devel] " Cornelia Huck
2019-02-20 10:54     ` Cornelia Huck
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 23/25] hw/ipmi: Assert outlen > outpos Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 13:36   ` [Qemu-devel] " Marc-André Lureau
2019-02-20 13:36     ` Marc-André Lureau
2019-02-20 13:36   ` [Qemu-devel] " Corey Minyard
2019-02-20 13:36     ` Corey Minyard
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 24/25] chardev: Let qemu_chr_fe_write[_all] use size_t type argument Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 13:44   ` [Qemu-devel] " Marc-André Lureau
2019-02-20 13:44     ` Marc-André Lureau
2019-02-20  1:02 ` [Qemu-devel] [PATCH v3 25/25] chardev: Let qemu_chr_write[_all] use size_t Philippe Mathieu-Daudé
2019-02-20  1:02   ` Philippe Mathieu-Daudé
2019-02-20 10:38   ` [Qemu-devel] " Daniel P. Berrangé
2019-02-20 10:42     ` Marc-André Lureau
2019-02-20 10:42       ` Marc-André Lureau
2019-02-20 11:31       ` Philippe Mathieu-Daudé
2019-02-20 11:31         ` Philippe Mathieu-Daudé
2019-02-20 10:38   ` Daniel P. Berrangé
2019-02-20 10:53 ` [Qemu-devel] [PATCH v3 00/25] chardev: Convert qemu_chr_write() to take a size_t argument Marc-André Lureau
2019-02-20 10:53   ` Marc-André Lureau
2019-02-20 10:57   ` [Qemu-devel] " Cornelia Huck
2019-02-20 10:57     ` Cornelia Huck
2019-02-20 11:30   ` [Qemu-devel] " Daniel P. Berrangé
2019-02-20 11:30     ` Daniel P. Berrangé
2019-02-20 14:20     ` Eric Blake
2019-02-20 14:20       ` Eric Blake

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=74dc80bc-d2cd-c79d-4787-6870b450a505@redhat.com \
    --to=philmd@redhat.com \
    --cc=amit@kernel.org \
    --cc=anthony.perard@citrix.com \
    --cc=borntraeger@de.ibm.com \
    --cc=cohuck@redhat.com \
    --cc=david@gibson.dropbear.id.au \
    --cc=jasowang@redhat.com \
    --cc=kraxel@redhat.com \
    --cc=lizhijian@cn.fujitsu.com \
    --cc=marcandre.lureau@redhat.com \
    --cc=minyard@acm.org \
    --cc=mst@redhat.com \
    --cc=pasic@linux.ibm.com \
    --cc=paul.durrant@citrix.com \
    --cc=pavel.dovgaluk@ispras.ru \
    --cc=pbonzini@redhat.com \
    --cc=pjp@fedoraproject.org \
    --cc=qemu-devel@nongnu.org \
    --cc=qemu-ppc@nongnu.org \
    --cc=qemu-s390x@nongnu.org \
    --cc=samuel.thibault@ens-lyon.org \
    --cc=sstabellini@kernel.org \
    --cc=stefanb@linux.ibm.com \
    --cc=xen-devel@lists.xenproject.org \
    --cc=zhangckid@gmail.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.