virtfs-proxy: Fix possible overflow
authorShannon Zhao <zhaoshenglong@huawei.com>
Sat, 14 Mar 2015 02:00:16 +0000 (10:00 +0800)
committerAneesh Kumar K.V <aneesh.kumar@linux.vnet.ibm.com>
Mon, 16 Mar 2015 07:59:12 +0000 (13:29 +0530)
It's detected by coverity. The socket name specified
should fit in the sockadd_un.sun_path. If not abort.

Signed-off-by: Shannon Zhao <zhaoshenglong@huawei.com>
Signed-off-by: Shannon Zhao <shannon.zhao@linaro.org>
Signed-off-by: Aneesh Kumar K.V <aneesh.kumar@linux.vnet.ibm.com>
fsdev/virtfs-proxy-helper.c
hw/9pfs/virtio-9p-proxy.c

index bf2e5f33312160172942e3e44106251a74692777..13fe032543bc185d22d84118ef8736d726bd46a0 100644 (file)
@@ -738,6 +738,7 @@ static int proxy_socket(const char *path, uid_t uid, gid_t gid)
         return -1;
     }
 
+    g_assert(strlen(path) < sizeof(proxy.sun_path));
     sock = socket(AF_UNIX, SOCK_STREAM, 0);
     if (sock < 0) {
         do_perror("socket");
index 6bb191ee6ab8d830a72affc887f078ea835e108d..71b6198bbd22ee1f6ba6e39a2d04759bfba85a69 100644 (file)
@@ -1100,6 +1100,10 @@ static int connect_namedsocket(const char *path)
     int sockfd, size;
     struct sockaddr_un helper;
 
+    if (strlen(path) >= sizeof(helper.sun_path)) {
+        fprintf(stderr, "Socket name too large\n");
+        return -1;
+    }
     sockfd = socket(AF_UNIX, SOCK_STREAM, 0);
     if (sockfd < 0) {
         fprintf(stderr, "failed to create socket: %s\n", strerror(errno));