From patchwork Thu Nov 5 07:08:36 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Patchwork-Submitter: Laurent Vivier X-Patchwork-Id: 318547 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-12.7 required=3.0 tests=BAYES_00, HEADER_FROM_DIFFERENT_DOMAINS, INCLUDES_PATCH, MAILING_LIST_MULTI, SIGNED_OFF_BY, SPF_HELO_NONE,SPF_PASS,URIBL_BLOCKED,USER_AGENT_GIT autolearn=ham autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 869D7C00A89 for ; Thu, 5 Nov 2020 07:11:23 +0000 (UTC) Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail.kernel.org (Postfix) with ESMTPS id F015B20709 for ; Thu, 5 Nov 2020 07:11:22 +0000 (UTC) DMARC-Filter: OpenDMARC Filter v1.3.2 mail.kernel.org F015B20709 Authentication-Results: mail.kernel.org; dmarc=none (p=none dis=none) header.from=vivier.eu Authentication-Results: mail.kernel.org; spf=pass smtp.mailfrom=qemu-devel-bounces+qemu-devel=archiver.kernel.org@nongnu.org Received: from localhost ([::1]:42484 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1kaZQX-0004jP-SR for qemu-devel@archiver.kernel.org; Thu, 05 Nov 2020 02:11:21 -0500 Received: from eggs.gnu.org ([2001:470:142:3::10]:43242) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kaZOA-0000Iu-4D for qemu-devel@nongnu.org; Thu, 05 Nov 2020 02:08:54 -0500 Received: from mout.kundenserver.de ([212.227.126.131]:39399) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1kaZO7-0007Xt-Bc for qemu-devel@nongnu.org; Thu, 05 Nov 2020 02:08:53 -0500 Received: from localhost.localdomain ([82.252.154.198]) by mrelayeu.kundenserver.de (mreue010 [212.227.15.167]) with ESMTPSA (Nemesis) id 1Mdevh-1k0xaM4Bd3-00ZgXB; Thu, 05 Nov 2020 08:08:44 +0100 From: Laurent Vivier To: qemu-devel@nongnu.org Subject: [PULL 3/4] linux-user/syscall: Fix missing target_to_host_timespec64() check Date: Thu, 5 Nov 2020 08:08:36 +0100 Message-Id: <20201105070837.558332-4-laurent@vivier.eu> X-Mailer: git-send-email 2.28.0 In-Reply-To: <20201105070837.558332-1-laurent@vivier.eu> References: <20201105070837.558332-1-laurent@vivier.eu> MIME-Version: 1.0 X-Provags-ID: V03:K1:nhYnG5QhwgCnkzuQyYDBGPnpGnHbLD2aCzUxPzGvcxAA9hBHnLc 1BVFVSyTnA2o2zrt+UFHT5kxmWKjq+YOMtn5PalhNKNYI5H0bAfJvPyvxjHMikw2YSgZUJv dC6evrnDQEUdP9esuwmupIUu6Erp6W3jShSJaWv3SLizRvNbdDZqeHBpyUxAGOKgqtNYYi9 JN3Z8vsEBR6c19BHePxXw== X-UI-Out-Filterresults: notjunk:1; V03:K0:NjR5CYtZrgc=:h/NQVx6aOYhj9RRh/Ak9tW C2eJg+9li8qdgLR0Owd4791s9yB5YDDpNW1egIU7XLB++sbjGq5cSGQH/NOSrx64YOtdxEXbL 6+P0okAqI+DN++AgRwEYaYeOiOm5CPwloiaE/4rIf9SP3BuLHMwXWOvha1fYXDBu8YNg7vPl2 CsGRSLaENcJH1K0McqplyMSTHFFMPPh13ZiHaPNh6N9D2xklF8u/nOnlT/v7xc+FTGxmMl9f0 wI9pVOnh7el+JRi4bqQISTJBG8/i3YKcGjpVPnthyl0Og0lsr3GX36/6yzm1twZ6B4UQZSe2s bp+TsvPe4uChB4xiGu3FYYHJS4gD1jAvB3LmMU5g9bJZv+fsenJ3syJjjDT42+9JlUnh9KacA 6diFg+5EQE0pcg0YwajTkEILoZMCzRqaJdQAy/H3tfLVNPDfcokyjq5Yc/tEGbTmbZ4u2EY+S Z2EgwBqrUA== Received-SPF: none client-ip=212.227.126.131; envelope-from=laurent@vivier.eu; helo=mout.kundenserver.de X-detected-operating-system: by eggs.gnu.org: First seen = 2020/11/05 02:08:48 X-ACL-Warn: Detected OS = Linux 2.2.x-3.x [generic] [fuzzy] X-Spam_score_int: -18 X-Spam_score: -1.9 X-Spam_bar: - X-Spam_report: (-1.9 / 5.0 requ) BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001 autolearn=ham autolearn_force=no X-Spam_action: no action X-BeenThere: qemu-devel@nongnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Cc: Alistair Francis , Laurent Vivier , =?utf-8?q?Philippe_Mathieu-Daud=C3=A9?= Errors-To: qemu-devel-bounces+qemu-devel=archiver.kernel.org@nongnu.org Sender: "Qemu-devel" From: Alistair Francis Coverity pointed out (CID 1432339) that target_to_host_timespec64() can fail with -TARGET_EFAULT but we never check the return value. This patch checks the return value and handles the error. Signed-off-by: Alistair Francis Reviewed-by: Philippe Mathieu-Daudé Message-Id: Signed-off-by: Laurent Vivier --- linux-user/syscall.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/linux-user/syscall.c b/linux-user/syscall.c index 6fef8181e738..3160a9ba06bd 100644 --- a/linux-user/syscall.c +++ b/linux-user/syscall.c @@ -7592,7 +7592,9 @@ static int do_futex_time64(target_ulong uaddr, int op, int val, target_ulong tim case FUTEX_WAIT_BITSET: if (timeout) { pts = &ts; - target_to_host_timespec64(pts, timeout); + if (target_to_host_timespec64(pts, timeout)) { + return -TARGET_EFAULT; + } } else { pts = NULL; }