c401cc
From 8c0076570062f8e37517b8264d21e9cac32e505a Mon Sep 17 00:00:00 2001
c401cc
Message-Id: <8c0076570062f8e37517b8264d21e9cac32e505a.1389183249.git.jdenemar@redhat.com>
c401cc
From: Peter Krempa <pkrempa@redhat.com>
c401cc
Date: Mon, 6 Jan 2014 17:02:28 +0100
c401cc
Subject: [PATCH] qemu: range check numa memory placement mode
c401cc
c401cc
https://bugzilla.redhat.com/show_bug.cgi?id=1047234
c401cc
c401cc
Add a range check for supported numa memory placement modes provided by
c401cc
the user before setting them in the domain definition. Without the check
c401cc
the user is able to provide a (yet) unknown mode which is then stored in
c401cc
the domain definition. This potentially causes a NULL dereference when
c401cc
the defintion is formatted into the XML.
c401cc
c401cc
To reproduce run:
c401cc
 virsh numatune DOMNAME --mode 6 --nodeset 0
c401cc
c401cc
The XML will then contain:
c401cc
  <numatune>
c401cc
      <memory mode='(null)' nodeset='0'/>
c401cc
  </numatune>
c401cc
c401cc
With this fix, the command fails:
c401cc
 error: Unable to change numa parameters
c401cc
 error: invalid argument: unsupported numa_mode: '6'
c401cc
c401cc
(cherry picked from commit 6e7490c734a538983f9c5ae680cdb36edbaffe65)
c401cc
c401cc
Signed-off-by: Jiri Denemark <jdenemar@redhat.com>
c401cc
---
c401cc
 src/qemu/qemu_driver.c | 8 ++++++++
c401cc
 1 file changed, 8 insertions(+)
c401cc
c401cc
diff --git a/src/qemu/qemu_driver.c b/src/qemu/qemu_driver.c
c401cc
index 215ac1b..8539b40 100644
c401cc
--- a/src/qemu/qemu_driver.c
c401cc
+++ b/src/qemu/qemu_driver.c
c401cc
@@ -8546,6 +8546,14 @@ qemuDomainSetNumaParameters(virDomainPtr dom,
c401cc
         if (STREQ(param->field, VIR_DOMAIN_NUMA_MODE)) {
c401cc
             int mode = param->value.i;
c401cc
 
c401cc
+            if (mode >= VIR_NUMA_TUNE_MEM_PLACEMENT_MODE_LAST ||
c401cc
+                mode < VIR_NUMA_TUNE_MEM_PLACEMENT_MODE_DEFAULT)
c401cc
+            {
c401cc
+                virReportError(VIR_ERR_INVALID_ARG,
c401cc
+                               _("unsupported numa_mode: '%d'"), mode);
c401cc
+                goto cleanup;
c401cc
+            }
c401cc
+
c401cc
             if ((flags & VIR_DOMAIN_AFFECT_LIVE) &&
c401cc
                 vm->def->numatune.memory.mode != mode) {
c401cc
                 virReportError(VIR_ERR_OPERATION_INVALID, "%s",
c401cc
-- 
c401cc
1.8.5.2
c401cc