[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH v2 2/3] xenbus/store: guard against NULL payload in StoreParseWatchEvent


  • To: david ambu <david.preetham@xxxxxxxxxx>, win-pv-devel@xxxxxxxxxxxxxxxxxxxx
  • From: Tu Dinh <ngoc-tu.dinh@xxxxxxxxxx>
  • Date: Mon, 14 Sep 2026 14:08:58 +0200
  • Authentication-results: eu.smtp.expurgate.cloud; dkim=pass header.s=selector1 header.d=vates.tech header.i="@vates.tech" header.h="From:Subject:Date:Message-ID:To:MIME-Version:Content-Type:In-Reply-To:References:Feedback-ID"
  • Delivery-date: Mon, 14 Sep 2026 12:09:04 +0000
  • Feedback-id: default:8631fc262581453bbf619ec5b2062170:Sweego
  • List-id: Developer list for the Windows PV Drivers subproject <win-pv-devel.lists.xenproject.org>

On 14/09/2026 12:18, david ambu wrote:
> Add NULL and zero-length check at the start of StoreParseWatchEvent
> to avoid dereferencing a NULL Data pointer.
> 
> Assisted-by: ClaudeCode:claude-sonnet-4-6
> Signed-off-by: david ambu <david.preetham@xxxxxxxxxx>

Reviewed-by: Tu Dinh <ngoc-tu.dinh@xxxxxxxxxx>

NB: For future updates to patchsets, please send them separately as a 
new thread rather than in reply to an existing patchset.

Thanks,

> ---
>   src/xenbus/store.c | 18 ++++++++++++------
>   1 file changed, 12 insertions(+), 6 deletions(-)
> 
> diff --git a/src/xenbus/store.c b/src/xenbus/store.c
> index d1b396b..bd9067e 100644
> --- a/src/xenbus/store.c
> +++ b/src/xenbus/store.c
> @@ -623,21 +623,24 @@ StoreParseWatchEvent(
>   {
>       PSTR            End;
>   
> +    if (Data == NULL || Length == 0)
> +        goto fail1;
> +
>       *Path = Data;
> -    while (*Data != '\0' && Length != 0) {
> +    while (Length != 0 && *Data != '\0') {
>           Data++;
>           --Length;
>       }
>   
>       if (Length != TOKEN_LENGTH + 1)
> -        goto fail1;
> +        goto fail2;
>   
>       // Skip over the NUL
>       Data++;
>       --Length;
>   
>       if (Data[Length - 1] != '\0')
> -        goto fail2;
> +        goto fail3;
>   
>       if (strncmp(Data, "TOK|", 4) != 0) {
>           Warning("UNRECOGNIZED PRE-AMBLE: %02X%02X%02X%02X\n",
> @@ -646,23 +649,26 @@ StoreParseWatchEvent(
>                   Data[2],
>                   Data[3]);
>   
> -        goto fail3;
> +        goto fail4;
>       }
>   
>       Data += 4;
>       *Caller = (PVOID)(ULONG_PTR)_strtoui64(Data, &End, 16);
>   
>       if (*End != '|')
> -        goto fail4;
> +        goto fail5;
>   
>       Data = End + 1;
>       *Id = (USHORT)strtoul(Data, &End, 16);
>   
>       if (*End != '\0')
> -        goto fail5;
> +        goto fail6;
>   
>       return STATUS_SUCCESS;
>   
> +fail6:
> +    Error("fail6\n");
> +
>   fail5:
>       Error("fail5\n");
>   



--
Ngoc Tu Dinh | Vates XCP-ng Developer

XCP-ng & Xen Orchestra - Vates solutions

web: https://vates.tech

 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.