mirror of
https://git.proxmox.com/git/qemu
synced 2025-06-15 20:07:23 +00:00
qapi: handle visitor->type_size() in QapiDeallocVisitor
visit_type_size() requires either visitor->type_size() or visitor_uint64() to be implemented, otherwise a NULL function pointer is invoked. It is possible to trigger this crash as follows: $ qemu-system-x86_64 -netdev tap,sndbuf=0,id=netdev0 \ -device virtio-blk-pci,netdev=netdev0 The 'sndbuf' option has type "size". Reviewed-by: Andreas Färber <afaerber@suse.de> Reviewed-by: Michael Roth <mdroth@linux.vnet.ibm.com> Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com> Signed-off-by: Anthony Liguori <aliguori@us.ibm.com>
This commit is contained in:
parent
e1e54f3fbe
commit
0c26f2eca4
@ -132,6 +132,11 @@ static void qapi_dealloc_type_number(Visitor *v, double *obj, const char *name,
|
|||||||
{
|
{
|
||||||
}
|
}
|
||||||
|
|
||||||
|
static void qapi_dealloc_type_size(Visitor *v, size_t *obj, const char *name,
|
||||||
|
Error **errp)
|
||||||
|
{
|
||||||
|
}
|
||||||
|
|
||||||
static void qapi_dealloc_type_enum(Visitor *v, int *obj, const char *strings[],
|
static void qapi_dealloc_type_enum(Visitor *v, int *obj, const char *strings[],
|
||||||
const char *kind, const char *name,
|
const char *kind, const char *name,
|
||||||
Error **errp)
|
Error **errp)
|
||||||
@ -164,6 +169,7 @@ QapiDeallocVisitor *qapi_dealloc_visitor_new(void)
|
|||||||
v->visitor.type_bool = qapi_dealloc_type_bool;
|
v->visitor.type_bool = qapi_dealloc_type_bool;
|
||||||
v->visitor.type_str = qapi_dealloc_type_str;
|
v->visitor.type_str = qapi_dealloc_type_str;
|
||||||
v->visitor.type_number = qapi_dealloc_type_number;
|
v->visitor.type_number = qapi_dealloc_type_number;
|
||||||
|
v->visitor.type_size = qapi_dealloc_type_size;
|
||||||
|
|
||||||
QTAILQ_INIT(&v->stack);
|
QTAILQ_INIT(&v->stack);
|
||||||
|
|
||||||
|
Loading…
Reference in New Issue
Block a user