conf: forbid negative values in virDomainParseScaledValue

It makes sense for none of the callers to have negative value as an
output and, fortunately, if anyone tried defining domain with negative
memory or any other value parsed by virDomainParseScaledValue(), the
resulting value was 0.  That means we can error out during parsing as
it won't break anything.

Resolves: https://bugzilla.redhat.com/show_bug.cgi?id=1155843

Signed-off-by: Martin Kletzander <mkletzan@redhat.com>
This commit is contained in:
Martin Kletzander
2014-10-29 17:29:40 +01:00
parent 089663aefa
commit 6c9a8a49c7

View File

@@ -6334,28 +6334,34 @@ virDomainParseScaledValue(const char *xpath,
{ {
char *xpath_full = NULL; char *xpath_full = NULL;
char *unit = NULL; char *unit = NULL;
char *bytes_str = NULL;
int ret = -1; int ret = -1;
unsigned long long bytes; unsigned long long bytes;
*val = 0; *val = 0;
if (virAsprintf(&xpath_full, "string(%s)", xpath) < 0) if (virAsprintf(&xpath_full, "string(%s)", xpath) < 0)
goto cleanup; goto cleanup;
ret = virXPathULongLong(xpath_full, ctxt, &bytes);
if (ret < 0) { bytes_str = virXPathString(xpath_full, ctxt);
if (ret == -2) if (!bytes_str) {
virReportError(VIR_ERR_XML_ERROR, if (!required) {
_("could not parse element %s"), ret = 0;
xpath); } else {
else if (required)
virReportError(VIR_ERR_XML_ERROR, virReportError(VIR_ERR_XML_ERROR,
_("missing element %s"), _("missing element %s"),
xpath); xpath);
else }
ret = 0;
goto cleanup; goto cleanup;
} }
VIR_FREE(xpath_full); VIR_FREE(xpath_full);
if (virStrToLong_ullp(bytes_str, NULL, 10, &bytes) < 0) {
virReportError(VIR_ERR_XML_ERROR,
_("Invalid value '%s' for element '%s'"),
bytes_str, xpath);
goto cleanup;
}
if (virAsprintf(&xpath_full, "string(%s/@unit)", xpath) < 0) if (virAsprintf(&xpath_full, "string(%s/@unit)", xpath) < 0)
goto cleanup; goto cleanup;
unit = virXPathString(xpath_full, ctxt); unit = virXPathString(xpath_full, ctxt);
@@ -6366,6 +6372,7 @@ virDomainParseScaledValue(const char *xpath,
*val = bytes; *val = bytes;
ret = 1; ret = 1;
cleanup: cleanup:
VIR_FREE(bytes_str);
VIR_FREE(xpath_full); VIR_FREE(xpath_full);
VIR_FREE(unit); VIR_FREE(unit);
return ret; return ret;