]> rtime.felk.cvut.cz Git - lisovros/qemu_apohw.git/commitdiff
linux-user: make bogus negative iovec lengths fail EINVAL
authorPeter Maydell <peter.maydell@linaro.org>
Fri, 8 Feb 2013 07:58:41 +0000 (07:58 +0000)
committerMichael Roth <mdroth@linux.vnet.ibm.com>
Tue, 2 Apr 2013 21:23:52 +0000 (16:23 -0500)
If the guest passes us a bogus negative length for an iovec, fail
EINVAL rather than proceeding blindly forward. This fixes some of
the error cases tests for readv and writev in the LTP.

Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Richard Henderson <rth@twiddle.net>
Signed-off-by: Riku Voipio <riku.voipio@linaro.org>
(cherry picked from commit dfae8e00f8ddeedcda24bd28f71d4fd2a9f988b8)

Signed-off-by: Michael Roth <mdroth@linux.vnet.ibm.com>
linux-user/syscall.c

index 7bc5ba9acff90f6ce1b087f1f13c868f08506a68..b682357629ffdef3268a810df942d7acd8221f5b 100644 (file)
@@ -1776,7 +1776,7 @@ static struct iovec *lock_iovec(int type, abi_ulong target_addr,
         errno = 0;
         return NULL;
     }
-    if (count > IOV_MAX) {
+    if (count < 0 || count > IOV_MAX) {
         errno = EINVAL;
         return NULL;
     }