From patchwork Tue Jul 1 08:48:52 2014 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Stefan Hajnoczi X-Patchwork-Id: 32885 Return-Path: X-Original-To: linaro@patches.linaro.org Delivered-To: linaro@patches.linaro.org Received: from mail-pa0-f71.google.com (mail-pa0-f71.google.com [209.85.220.71]) by ip-10-151-82-157.ec2.internal (Postfix) with ESMTPS id 5AA1D20672 for ; Tue, 1 Jul 2014 10:19:15 +0000 (UTC) Received: by mail-pa0-f71.google.com with SMTP id eu11sf50971836pac.2 for ; Tue, 01 Jul 2014 03:19:14 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:delivered-to:from:to:date :message-id:in-reply-to:references:cc:subject:precedence:list-id :list-unsubscribe:list-archive:list-post:list-help:list-subscribe :errors-to:sender:x-original-sender :x-original-authentication-results:mailing-list; bh=eyTDaI9pnI8MwwynNNZIQ6CN4GaDZ9fCOh4DJjigRYA=; b=cocEreqx9scD/UuwFSxf8+nKbV7d7G5dlMdc3wqlpGJ/GkuCy41qEH42LoyoPBeL+k ylXU4iV/+gZnJ5anJMpE9IfsvYN9Muq6vhvVf5tU3T/5IRNQV53FNmbTnd3cXCeFonYb BVePo+0QJDbe35yXE7RKE4xCiefWs/qiTh4KtIXNtUBwHh2nzXUBmKjx9YSfIwdnrKao JLf3rBcq2tznkCedkOeqajmx7sjM3/hc1aNsS1XMv4M5gU7lkjx9TkjcaPolHiOUx98/ Y01PsqFSiUrdCg9WfR4S1Mtu0e4IyiwQacsprU94axxmzvYDM/yYnzXndNwq2/qsTjpc 1thA== X-Gm-Message-State: ALoCoQmsAPbcHOTPLSX26xwCFWhr0sjagIG/9m708KWE0WSnm7VN8x5Wg9TUIF9HbNySxv8Uu2WD X-Received: by 10.66.165.165 with SMTP id yz5mr26425357pab.37.1404209954584; Tue, 01 Jul 2014 03:19:14 -0700 (PDT) MIME-Version: 1.0 X-BeenThere: patchwork-forward@linaro.org Received: by 10.140.27.171 with SMTP id 40ls1391163qgx.9.gmail; Tue, 01 Jul 2014 03:19:14 -0700 (PDT) X-Received: by 10.220.69.4 with SMTP id x4mr14515vci.74.1404209954479; Tue, 01 Jul 2014 03:19:14 -0700 (PDT) Received: from mail-ve0-f174.google.com (mail-ve0-f174.google.com [209.85.128.174]) by mx.google.com with ESMTPS id y17si11195269vdg.107.2014.07.01.03.19.14 for (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Tue, 01 Jul 2014 03:19:14 -0700 (PDT) Received-SPF: pass (google.com: domain of patch+caf_=patchwork-forward=linaro.org@linaro.org designates 209.85.128.174 as permitted sender) client-ip=209.85.128.174; Received: by mail-ve0-f174.google.com with SMTP id jx11so9388624veb.19 for ; Tue, 01 Jul 2014 03:19:14 -0700 (PDT) X-Received: by 10.221.26.10 with SMTP id rk10mr43478455vcb.0.1404209954362; Tue, 01 Jul 2014 03:19:14 -0700 (PDT) X-Forwarded-To: patchwork-forward@linaro.org X-Forwarded-For: patch@linaro.org patchwork-forward@linaro.org Delivered-To: patch@linaro.org Received: by 10.221.37.5 with SMTP id tc5csp204059vcb; Tue, 1 Jul 2014 03:19:14 -0700 (PDT) X-Received: by 10.224.172.10 with SMTP id j10mr60618768qaz.46.1404209953897; Tue, 01 Jul 2014 03:19:13 -0700 (PDT) Received: from lists.gnu.org (lists.gnu.org. [2001:4830:134:3::11]) by mx.google.com with ESMTPS id g6si2142663qgg.20.2014.07.01.03.19.13 for (version=TLSv1 cipher=RC4-SHA bits=128/128); Tue, 01 Jul 2014 03:19:13 -0700 (PDT) Received-SPF: pass (google.com: domain of qemu-devel-bounces+patch=linaro.org@nongnu.org designates 2001:4830:134:3::11 as permitted sender) client-ip=2001:4830:134:3::11; Received: from localhost ([::1]:40067 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1X1twr-0008S4-IG for patch@linaro.org; Tue, 01 Jul 2014 05:01:57 -0400 Received: from eggs.gnu.org ([2001:4830:134:3::10]:51824) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1X1tlC-0008Qb-Nf for qemu-devel@nongnu.org; Tue, 01 Jul 2014 04:49:59 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1X1tl7-0006Kh-3x for qemu-devel@nongnu.org; Tue, 01 Jul 2014 04:49:54 -0400 Received: from mx1.redhat.com ([209.132.183.28]:1564) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1X1tl6-0006KP-S4 for qemu-devel@nongnu.org; Tue, 01 Jul 2014 04:49:49 -0400 Received: from int-mx13.intmail.prod.int.phx2.redhat.com (int-mx13.intmail.prod.int.phx2.redhat.com [10.5.11.26]) by mx1.redhat.com (8.14.4/8.14.4) with ESMTP id s618nkFG008319 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK); Tue, 1 Jul 2014 04:49:46 -0400 Received: from localhost (ovpn-112-49.ams2.redhat.com [10.36.112.49]) by int-mx13.intmail.prod.int.phx2.redhat.com (8.14.4/8.14.4) with ESMTP id s618njpu001491; Tue, 1 Jul 2014 04:49:46 -0400 From: Stefan Hajnoczi To: Date: Tue, 1 Jul 2014 10:48:52 +0200 Message-Id: <1404204537-5082-20-git-send-email-stefanha@redhat.com> In-Reply-To: <1404204537-5082-1-git-send-email-stefanha@redhat.com> References: <1404204537-5082-1-git-send-email-stefanha@redhat.com> X-Scanned-By: MIMEDefang 2.68 on 10.5.11.26 X-detected-operating-system: by eggs.gnu.org: GNU/Linux 3.x X-Received-From: 209.132.183.28 Cc: Peter Maydell , Stefan Hajnoczi Subject: [Qemu-devel] [PULL for-2.1 19/24] block/cow: Avoid use of uninitialized cow_bs in error path X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.14 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: , List-Help: , List-Subscribe: , Errors-To: qemu-devel-bounces+patch=linaro.org@nongnu.org Sender: qemu-devel-bounces+patch=linaro.org@nongnu.org X-Removed-Original-Auth: Dkim didn't pass. X-Original-Sender: patch@linaro.org X-Original-Authentication-Results: mx.google.com; spf=pass (google.com: domain of patch+caf_=patchwork-forward=linaro.org@linaro.org designates 209.85.128.174 as permitted sender) smtp.mail=patch+caf_=patchwork-forward=linaro.org@linaro.org Mailing-list: list patchwork-forward@linaro.org; contact patchwork-forward+owners@linaro.org X-Google-Group-Id: 836684582541 From: Peter Maydell Commit 25814e8987 introduced an error-exit code path which does a "goto exit" before the cow_bs variable is initialized, meaning we would call bdrv_unref() on an uninitialized variable and likely segfault. Fix this by moving the NULL-initialization to the top of the function and making the exit code path handle the case where it is NULL. Signed-off-by: Peter Maydell Reviewed-by: Eric Blake Signed-off-by: Stefan Hajnoczi --- block/cow.c | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/block/cow.c b/block/cow.c index 8f81ee6..6ee4833 100644 --- a/block/cow.c +++ b/block/cow.c @@ -332,7 +332,7 @@ static int cow_create(const char *filename, QemuOpts *opts, Error **errp) char *image_filename = NULL; Error *local_err = NULL; int ret; - BlockDriverState *cow_bs; + BlockDriverState *cow_bs = NULL; /* Read out options */ image_sectors = qemu_opt_get_size_del(opts, BLOCK_OPT_SIZE, 0) / 512; @@ -344,7 +344,6 @@ static int cow_create(const char *filename, QemuOpts *opts, Error **errp) goto exit; } - cow_bs = NULL; ret = bdrv_open(&cow_bs, filename, NULL, NULL, BDRV_O_RDWR | BDRV_O_PROTOCOL, NULL, &local_err); if (ret < 0) { @@ -383,7 +382,9 @@ static int cow_create(const char *filename, QemuOpts *opts, Error **errp) exit: g_free(image_filename); - bdrv_unref(cow_bs); + if (cow_bs) { + bdrv_unref(cow_bs); + } return ret; }