提交 88bbd3fb 编写于 作者: P Philippe Mathieu-Daudé 提交者: Peter Maydell

hw/arm/sysbus-fdt: Replace error_setg(&error_fatal) by error_report() + exit()

Use error_report() + exit() instead of error_setg(&error_fatal),
as suggested by the "qapi/error.h" documentation:

   Please don't error_setg(&error_fatal, ...), use error_report() and
   exit(), because that's more obvious.

This fixes CID 1352173:
    "Passing null pointer dt_name to qemu_fdt_node_path, which dereferences it."

And this also fixes:

    hw/arm/sysbus-fdt.c:322:9: warning: Array access (from variable 'node_path') results in a null pointer dereference
        if (node_path[1]) {
            ^~~~~~~~~~~~

Fixes: Coverity CID 1352173 (Dereference after null check)
Suggested-by: NEric Blake <eblake@redhat.com>
Signed-off-by: NPhilippe Mathieu-Daudé <f4bug@amsat.org>
Reviewed-by: NEric Auger <eric.auger@redhat.com>
Message-id: 20180625165749.3910-3-f4bug@amsat.org
Signed-off-by: NPeter Maydell <peter.maydell@linaro.org>
上级 329b7291
...@@ -92,16 +92,20 @@ static void copy_properties_from_host(HostProperty *props, int nb_props, ...@@ -92,16 +92,20 @@ static void copy_properties_from_host(HostProperty *props, int nb_props,
r = qemu_fdt_getprop(host_fdt, node_path, r = qemu_fdt_getprop(host_fdt, node_path,
props[i].name, props[i].name,
&prop_len, &prop_len,
props[i].optional ? &err : &error_fatal); &err);
if (r) { if (r) {
qemu_fdt_setprop(guest_fdt, nodename, qemu_fdt_setprop(guest_fdt, nodename,
props[i].name, r, prop_len); props[i].name, r, prop_len);
} else { } else {
if (prop_len != -FDT_ERR_NOTFOUND) { if (props[i].optional && prop_len == -FDT_ERR_NOTFOUND) {
/* optional property not returned although property exists */ /* optional property does not exist */
error_report_err(err);
} else {
error_free(err); error_free(err);
} else {
error_report_err(err);
}
if (!props[i].optional) {
/* mandatory property not found: bail out */
exit(1);
} }
} }
} }
...@@ -138,9 +142,9 @@ static void fdt_build_clock_node(void *host_fdt, void *guest_fdt, ...@@ -138,9 +142,9 @@ static void fdt_build_clock_node(void *host_fdt, void *guest_fdt,
node_offset = fdt_node_offset_by_phandle(host_fdt, host_phandle); node_offset = fdt_node_offset_by_phandle(host_fdt, host_phandle);
if (node_offset <= 0) { if (node_offset <= 0) {
error_setg(&error_fatal, error_report("not able to locate clock handle %d in host device tree",
"not able to locate clock handle %d in host device tree", host_phandle);
host_phandle); exit(1);
} }
node_path = g_malloc(path_len); node_path = g_malloc(path_len);
while ((ret = fdt_get_path(host_fdt, node_offset, node_path, path_len)) while ((ret = fdt_get_path(host_fdt, node_offset, node_path, path_len))
...@@ -149,16 +153,16 @@ static void fdt_build_clock_node(void *host_fdt, void *guest_fdt, ...@@ -149,16 +153,16 @@ static void fdt_build_clock_node(void *host_fdt, void *guest_fdt,
node_path = g_realloc(node_path, path_len); node_path = g_realloc(node_path, path_len);
} }
if (ret < 0) { if (ret < 0) {
error_setg(&error_fatal, error_report("not able to retrieve node path for clock handle %d",
"not able to retrieve node path for clock handle %d", host_phandle);
host_phandle); exit(1);
} }
r = qemu_fdt_getprop(host_fdt, node_path, "compatible", &prop_len, r = qemu_fdt_getprop(host_fdt, node_path, "compatible", &prop_len,
&error_fatal); &error_fatal);
if (strcmp(r, "fixed-clock")) { if (strcmp(r, "fixed-clock")) {
error_setg(&error_fatal, error_report("clock handle %d is not a fixed clock", host_phandle);
"clock handle %d is not a fixed clock", host_phandle); exit(1);
} }
nodename = strrchr(node_path, '/'); nodename = strrchr(node_path, '/');
...@@ -301,34 +305,37 @@ static int add_amd_xgbe_fdt_node(SysBusDevice *sbdev, void *opaque) ...@@ -301,34 +305,37 @@ static int add_amd_xgbe_fdt_node(SysBusDevice *sbdev, void *opaque)
dt_name = sysfs_to_dt_name(vbasedev->name); dt_name = sysfs_to_dt_name(vbasedev->name);
if (!dt_name) { if (!dt_name) {
error_setg(&error_fatal, "%s incorrect sysfs device name %s", error_report("%s incorrect sysfs device name %s",
__func__, vbasedev->name); __func__, vbasedev->name);
exit(1);
} }
node_path = qemu_fdt_node_path(host_fdt, dt_name, vdev->compat, node_path = qemu_fdt_node_path(host_fdt, dt_name, vdev->compat,
&error_fatal); &error_fatal);
if (!node_path || !node_path[0]) { if (!node_path || !node_path[0]) {
error_setg(&error_fatal, "%s unable to retrieve node path for %s/%s", error_report("%s unable to retrieve node path for %s/%s",
__func__, dt_name, vdev->compat); __func__, dt_name, vdev->compat);
exit(1);
} }
if (node_path[1]) { if (node_path[1]) {
error_setg(&error_fatal, "%s more than one node matching %s/%s!", error_report("%s more than one node matching %s/%s!",
__func__, dt_name, vdev->compat); __func__, dt_name, vdev->compat);
exit(1);
} }
g_free(dt_name); g_free(dt_name);
if (vbasedev->num_regions != 5) { if (vbasedev->num_regions != 5) {
error_setg(&error_fatal, "%s Does the host dt node combine XGBE/PHY?", error_report("%s Does the host dt node combine XGBE/PHY?", __func__);
__func__); exit(1);
} }
/* generate nodes for DMA_CLK and PTP_CLK */ /* generate nodes for DMA_CLK and PTP_CLK */
r = qemu_fdt_getprop(host_fdt, node_path[0], "clocks", r = qemu_fdt_getprop(host_fdt, node_path[0], "clocks",
&prop_len, &error_fatal); &prop_len, &error_fatal);
if (prop_len != 8) { if (prop_len != 8) {
error_setg(&error_fatal, "%s clocks property should contain 2 handles", error_report("%s clocks property should contain 2 handles", __func__);
__func__); exit(1);
} }
host_clock_phandles = (uint32_t *)r; host_clock_phandles = (uint32_t *)r;
guest_clock_phandles[0] = qemu_fdt_alloc_phandle(guest_fdt); guest_clock_phandles[0] = qemu_fdt_alloc_phandle(guest_fdt);
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册