# HG changeset patch # User yamahata@xxxxxxxxxxxxx # Date 1195716044 -32400 # Node ID 7a7a697092bf1fc96ca93204d3a820f2e75439c3 # Parent 05cbf512b82b2665d407395bac73b9cca0c396b4 minor clean up of xc_core. This patch fixes the bug reported as http://bugzilla.xensource.com/bugzilla/show_bug.cgi?id=1062 PATCHNAME: xc_core_minor_clean_up Signed-off-by: Isaku Yamahata diff -r 05cbf512b82b -r 7a7a697092bf tools/libxc/xc_core.c --- a/tools/libxc/xc_core.c Wed Nov 21 14:36:07 2007 +0000 +++ b/tools/libxc/xc_core.c Thu Nov 22 16:20:44 2007 +0900 @@ -107,16 +107,22 @@ xc_core_strtab_get(struct xc_core_strtab uint16_t ret = 0; uint16_t len = strlen(name) + 1; + if ( strtab->current > UINT16_MAX - len ) + { + PERROR("too long string table"); + errno = E2BIG; + return ret; + } + if ( strtab->current + len > strtab->max ) { char *tmp; - if ( strtab->max * 2 < strtab->max ) + if ( strtab->max > UINT16_MAX / 2 ) { PERROR("too long string table"); errno = ENOMEM; return ret; } - tmp = realloc(strtab->strings, strtab->max * 2); if ( tmp == NULL ) @@ -143,8 +149,8 @@ struct xc_core_section_headers { Elf64_Shdr *shdrs; }; -#define SHDR_INIT 16 -#define SHDR_INC 4U +#define SHDR_INIT ((uint16_t)16) +#define SHDR_INC ((uint16_t)4) static struct xc_core_section_headers* xc_core_shdr_init(void) @@ -180,7 +186,7 @@ xc_core_shdr_get(struct xc_core_section_ if ( sheaders->num == sheaders->num_max ) { Elf64_Shdr *shdrs; - if ( sheaders->num_max + SHDR_INC < sheaders->num_max ) + if ( sheaders->num_max > UINT16_MAX - SHDR_INC ) { errno = E2BIG; return NULL; diff -r 05cbf512b82b -r 7a7a697092bf tools/libxc/xc_core_x86.c --- a/tools/libxc/xc_core_x86.c Wed Nov 21 14:36:07 2007 +0000 +++ b/tools/libxc/xc_core_x86.c Thu Nov 22 16:20:44 2007 +0900 @@ -89,7 +89,7 @@ xc_core_arch_map_p2m(int xc_handle, xc_d } live_p2m_frame_list = - xc_map_foreign_batch(xc_handle, dom, PROT_READ, + xc_map_foreign_pages(xc_handle, dom, PROT_READ, live_p2m_frame_list_list, P2M_FLL_ENTRIES); @@ -99,7 +99,7 @@ xc_core_arch_map_p2m(int xc_handle, xc_d goto out; } - *live_p2m = xc_map_foreign_batch(xc_handle, dom, PROT_READ, + *live_p2m = xc_map_foreign_pages(xc_handle, dom, PROT_READ, live_p2m_frame_list, P2M_FL_ENTRIES);