qemu/hw/9pfs
Greg Kurz d3d74d6fe0 virtio-9p: handle handle_9p_output() error
A broken guest may send a request without providing buffers for the reply
or for the request itself, and virtqueue_pop() will return an element with
either in_num == 0 or out_num == 0.

All 9P requests are expected to start with the following 7-byte header:

            uint32_t size_le;
            uint8_t id;
            uint16_t tag_le;

If iov_to_buf() fails to return these 7 bytes, then something is wrong in
the guest.

In both cases, it is wrong to crash QEMU, since the root cause lies in the
guest.

This patch hence does the following:
- keep the check of in_num since pdu_complete() assumes it has enough
  space to store the reply and we will send something broken to the guest
- let iov_to_buf() handle out_num == 0, since it will return 0 just like
  if the guest had provided an zero-sized buffer.
- call virtio_error() to inform the guest that the device is now broken,
  instead of aborting
- detach the request from the virtqueue and free it

Signed-off-by: Greg Kurz <groug@kaod.org>
Reviewed-by: Stefan Hajnoczi <stefanha@redhat.com>
Reviewed-by: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
2016-10-10 01:16:59 +03:00
..
9p-handle.c 9p: switch back to readdir() 2016-06-06 11:52:34 +02:00
9p-local.c 9pfs: introduce v9fs_path_sprintf() helper 2016-09-16 08:56:15 +02:00
9p-posix-acl.c 9pfs: Clean up includes 2016-01-29 15:07:23 +00:00
9p-proxy.c 9pfs: introduce v9fs_path_sprintf() helper 2016-09-16 08:56:15 +02:00
9p-proxy.h Clean up ill-advised or unusual header guards 2016-07-12 16:20:46 +02:00
9p-synth.c 9p: synth: drop v9fs_ prefix 2016-07-01 14:38:54 +02:00
9p-synth.h Clean up header guards that don't match their file name 2016-07-12 16:19:16 +02:00
9p-xattr-user.c 9pfs: Clean up includes 2016-01-29 15:07:23 +00:00
9p-xattr.c 9pfs: Clean up includes 2016-01-29 15:07:23 +00:00
9p-xattr.h Clean up ill-advised or unusual header guards 2016-07-12 16:20:46 +02:00
9p.c 9pfs: fix potential segfault during walk 2016-09-19 11:39:48 +02:00
9p.h 9pfs: introduce v9fs_path_sprintf() helper 2016-09-16 08:56:15 +02:00
codir.c 9p: switch back to readdir() 2016-06-06 11:52:34 +02:00
cofile.c 9p/fsdev: remove obsolete references to virtio 2016-06-06 11:52:34 +02:00
cofs.c 9p/fsdev: remove obsolete references to virtio 2016-06-06 11:52:34 +02:00
coth.c coroutine: move entry argument to qemu_coroutine_create 2016-07-13 13:26:02 +02:00
coth.h Clean up ill-advised or unusual header guards 2016-07-12 16:20:46 +02:00
coxattr.c 9p/fsdev: remove obsolete references to virtio 2016-06-06 11:52:34 +02:00
Makefile.objs 9pfs: rename virtio-9p.c to 9p.c 2016-01-08 15:32:13 +05:30
trace-events trace-events: fix first line comment in trace-events 2016-08-12 10:36:01 +01:00
virtio-9p-device.c virtio-9p: handle handle_9p_output() error 2016-10-10 01:16:59 +03:00
virtio-9p.h Clean up ill-advised or unusual header guards 2016-07-12 16:20:46 +02:00