All of lore.kernel.org
 help / color / mirror / Atom feed
From: Paolo Bonzini <pbonzini@redhat.com>
To: qemu-devel@nongnu.org
Cc: Peter Maydell <peter.maydell@linaro.org>
Subject: [PULL 42/48] vl: fix leak of qdict_crumple return value
Date: Thu,  8 Jul 2021 17:17:42 +0200	[thread overview]
Message-ID: <20210708151748.408754-43-pbonzini@redhat.com> (raw)
In-Reply-To: <20210708151748.408754-1-pbonzini@redhat.com>

Coverity reports that qemu_parse_config_group is returning without
unrefing the "crumpled" dictionary in case its top level item is a
list.  But actually the contract with qemu_record_config_group is
the same as for qemu_parse_config_group itself: if those function
need to stash the dictionary they get, they have to take a reference
themselves (currently this is never the case for either function).
Therefore, just add an unconditional qobject_unref(crumpled) to
qemu_parse_config_group.

Reported-by: Peter Maydell <peter.maydell@linaro.org>
Signed-off-by: Paolo Bonzini <pbonzini@redhat.com>
---
 softmmu/vl.c | 13 +++++++++----
 1 file changed, 9 insertions(+), 4 deletions(-)

diff --git a/softmmu/vl.c b/softmmu/vl.c
index 2004d57108..4df1496101 100644
--- a/softmmu/vl.c
+++ b/softmmu/vl.c
@@ -2193,12 +2193,17 @@ static void qemu_parse_config_group(const char *group, QDict *qdict,
     if (!crumpled) {
         return;
     }
-    if (qobject_type(crumpled) != QTYPE_QDICT) {
-        assert(qobject_type(crumpled) == QTYPE_QLIST);
+    switch (qobject_type(crumpled)) {
+    case QTYPE_QDICT:
+        qemu_record_config_group(group, qobject_to(QDict, crumpled), false, errp);
+        break;
+    case QTYPE_QLIST:
         error_setg(errp, "Lists cannot be at top level of a configuration section");
-        return;
+        break;
+    default:
+        g_assert_not_reached();
     }
-    qemu_record_config_group(group, qobject_to(QDict, crumpled), false, errp);
+    qobject_unref(crumpled);
 }
 
 static void qemu_read_default_config_file(Error **errp)
-- 
2.31.1




  parent reply	other threads:[~2021-07-08 15:46 UTC|newest]

Thread overview: 54+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2021-07-08 15:17 [PULL 00/48] Misc patches for QEMU 6.1 soft freeze Paolo Bonzini
2021-07-08 15:17 ` [PULL 01/48] configure: fix libdaxctl options Paolo Bonzini
2021-07-08 15:17 ` [PULL 02/48] configure: fix libpmem configuration option Paolo Bonzini
2021-07-08 15:17 ` [PULL 03/48] meson: fix missing preprocessor symbols Paolo Bonzini
2021-07-08 15:17 ` [PULL 04/48] osdep: fix HAVE_BROKEN_SIZE_MAX case Paolo Bonzini
2021-07-08 15:17 ` [PULL 05/48] modules: add modinfo macros Paolo Bonzini
2021-07-08 15:17 ` [PULL 06/48] modules: collect module meta-data Paolo Bonzini
2021-07-08 15:17 ` [PULL 07/48] modules: generate modinfo.c Paolo Bonzini
2021-07-08 15:17 ` [PULL 08/48] modules: check if all dependencies can be satisfied Paolo Bonzini
2021-07-08 15:17 ` [PULL 09/48] modules: add qxl module annotations Paolo Bonzini
2021-07-08 15:17 ` [PULL 10/48] modules: add virtio-gpu " Paolo Bonzini
2021-07-08 15:17 ` [PULL 11/48] modules: add chardev " Paolo Bonzini
2021-07-08 15:17 ` [PULL 12/48] modules: add audio " Paolo Bonzini
2021-07-08 15:17 ` [PULL 13/48] modules: add usb-redir " Paolo Bonzini
2021-07-08 15:17 ` [PULL 14/48] modules: add ccid " Paolo Bonzini
2021-07-08 15:17 ` [PULL 15/48] modules: add ui " Paolo Bonzini
2021-07-08 15:17 ` [PULL 16/48] modules: add s390x " Paolo Bonzini
2021-07-08 15:17 ` [PULL 17/48] modules: add block " Paolo Bonzini
2021-07-08 15:17 ` [PULL 18/48] modules: use modinfo for dependencies Paolo Bonzini
2021-07-08 15:17 ` [PULL 19/48] modules: use modinfo for qom load Paolo Bonzini
2021-07-08 15:17 ` [PULL 20/48] modules: use modinfo for qemu opts load Paolo Bonzini
2021-07-08 15:17 ` [PULL 21/48] modules: add tracepoints Paolo Bonzini
2021-07-08 15:17 ` [PULL 22/48] modules: check arch and block load on mismatch Paolo Bonzini
2021-07-08 15:17 ` [PULL 23/48] modules: check arch on qom lookup Paolo Bonzini
2021-07-08 15:17 ` [PULL 24/48] modules: target-specific module build infrastructure Paolo Bonzini
2021-07-08 15:17 ` [PULL 25/48] modules: add documentation for module sourcesets Paolo Bonzini
2021-07-08 15:17 ` [PULL 26/48] modules: add module_obj() note to QOM docs Paolo Bonzini
2021-07-08 15:17 ` [PULL 27/48] modules: module.h kerneldoc annotations Paolo Bonzini
2021-07-08 15:17 ` [PULL 28/48] modules: hook up modules.h to docs build Paolo Bonzini
2021-07-08 15:17 ` [PULL 29/48] accel: autoload modules Paolo Bonzini
2021-07-08 15:17 ` [PULL 30/48] accel: add qtest module annotations Paolo Bonzini
2021-07-08 15:17 ` [PULL 31/48] accel: build qtest modular Paolo Bonzini
2021-07-08 15:17 ` [PULL 32/48] accel: add tcg module annotations Paolo Bonzini
2021-07-08 15:17 ` [PULL 33/48] accel: build tcg modular Paolo Bonzini
2021-07-08 15:17 ` [PULL 34/48] monitor: allow register hmp commands Paolo Bonzini
2021-07-08 15:17 ` [PULL 35/48] usb: drop usb_host_dev_is_scsi_storage hook Paolo Bonzini
2021-07-08 15:17 ` [PULL 36/48] monitor/usb: register 'info usbhost' dynamically Paolo Bonzini
2021-07-08 15:17 ` [PULL 37/48] usb: build usb-host as module Paolo Bonzini
2021-07-22 14:10   ` Peter Krempa
2021-07-23  6:18     ` Gerd Hoffmann
2021-07-08 15:17 ` [PULL 38/48] monitor/tcg: move tcg hmp commands to accel/tcg, register them dynamically Paolo Bonzini
2021-07-08 15:17 ` [PULL 39/48] target/i386: Added MSRPM and IOPM size check Paolo Bonzini
2021-07-08 15:17 ` [PULL 40/48] target/i386: Added DR6 and DR7 consistency checks Paolo Bonzini
2021-07-08 15:17 ` [PULL 41/48] target/i386: fix exceptions for MOV to DR Paolo Bonzini
2021-07-08 15:17 ` Paolo Bonzini [this message]
2021-07-08 15:17 ` [PULL 43/48] meson: switch function tests from compilation to linking Paolo Bonzini
2021-07-08 15:17 ` [PULL 44/48] meson: Introduce target-specific Kconfig Paolo Bonzini
2021-07-17 22:59   ` Peter Maydell
2021-07-19 19:15     ` Peter Maydell
2021-07-08 15:17 ` [PULL 45/48] hw/arm: add dependency on OR_IRQ for XLNX_VERSAL Paolo Bonzini
2021-07-08 15:17 ` [PULL 46/48] hw/arm: move CONFIG_V7M out of default-devices Paolo Bonzini
2021-07-08 15:17 ` [PULL 47/48] configs: rename default-configs to configs and reorganise Paolo Bonzini
2021-07-08 15:17 ` [PULL 48/48] configure: allow the selection of alternate config in the build Paolo Bonzini
2021-07-09 15:45 ` [PULL 00/48] Misc patches for QEMU 6.1 soft freeze Peter Maydell

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20210708151748.408754-43-pbonzini@redhat.com \
    --to=pbonzini@redhat.com \
    --cc=peter.maydell@linaro.org \
    --cc=qemu-devel@nongnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.