diff options
author | Stefan Hajnoczi <stefanha@redhat.com> | 2012-11-26 13:10:12 +0100 |
---|---|---|
committer | Doug Goldstein <cardoe@cardoe.com> | 2012-12-13 15:31:59 -0600 |
commit | edcf61fbcf0e6613e36c3968fc8a018b5f8ad803 (patch) | |
tree | fb938fbecf90babc47ef3c521436d13e3598a9a7 | |
parent | qom: fix refcount of non-heap-allocated objects (diff) | |
download | qemu-kvm-edcf61fbcf0e6613e36c3968fc8a018b5f8ad803.tar.gz qemu-kvm-edcf61fbcf0e6613e36c3968fc8a018b5f8ad803.tar.bz2 qemu-kvm-edcf61fbcf0e6613e36c3968fc8a018b5f8ad803.zip |
qapi: handle visitor->type_size() in QapiDeallocVisitor
visit_type_size() requires either visitor->type_size() or
visitor_uint64() to be implemented, otherwise a NULL function pointer is
invoked.
It is possible to trigger this crash as follows:
$ qemu-system-x86_64 -netdev tap,sndbuf=0,id=netdev0 \
-device virtio-blk-pci,netdev=netdev0
The 'sndbuf' option has type "size".
Reviewed-by: Andreas Färber <afaerber@suse.de>
Reviewed-by: Michael Roth <mdroth@linux.vnet.ibm.com>
Signed-off-by: Stefan Hajnoczi <stefanha@redhat.com>
Signed-off-by: Anthony Liguori <aliguori@us.ibm.com>
(cherry picked from commit 0c26f2eca40d6c65ea9edc62a10e510dc7f65cc8)
Signed-off-by: Michael Roth <mdroth@linux.vnet.ibm.com>
(cherry picked from commit 54c6c5a35d8bd57b320bbba8b85604018004bd13)
-rw-r--r-- | qapi/qapi-dealloc-visitor.c | 6 |
1 files changed, 6 insertions, 0 deletions
diff --git a/qapi/qapi-dealloc-visitor.c b/qapi/qapi-dealloc-visitor.c index a15452373..a07b171b8 100644 --- a/qapi/qapi-dealloc-visitor.c +++ b/qapi/qapi-dealloc-visitor.c @@ -132,6 +132,11 @@ static void qapi_dealloc_type_number(Visitor *v, double *obj, const char *name, { } +static void qapi_dealloc_type_size(Visitor *v, size_t *obj, const char *name, + Error **errp) +{ +} + static void qapi_dealloc_type_enum(Visitor *v, int *obj, const char *strings[], const char *kind, const char *name, Error **errp) @@ -164,6 +169,7 @@ QapiDeallocVisitor *qapi_dealloc_visitor_new(void) v->visitor.type_bool = qapi_dealloc_type_bool; v->visitor.type_str = qapi_dealloc_type_str; v->visitor.type_number = qapi_dealloc_type_number; + v->visitor.type_size = qapi_dealloc_type_size; QTAILQ_INIT(&v->stack); |