|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [Xen-devel] [PATCH 1/3] libxlu_cfg: reject unknown characters following '\'
When dequoting config strings in xlu__cfgl_dequote(), unknown
characters following a '\', and the '\' itself, are discarded.
E.g. a disk configuration string containing
rbd:pool/image:mon_host=192.168.0.100\:6789
would be dequoted as
rbd:pool/image:mon_host=192.168.0.1006789
Instead of discarding the '\' and unknown character, reject the
string and set error to EINVAL.
---
tools/libxl/libxlu_cfg.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/tools/libxl/libxlu_cfg.c b/tools/libxl/libxlu_cfg.c
index 1d70909..f8e0bc7 100644
--- a/tools/libxl/libxlu_cfg.c
+++ b/tools/libxl/libxlu_cfg.c
@@ -533,6 +533,11 @@ char *xlu__cfgl_dequote(CfgParseContext *ctx, const char
*src) {
NUMERIC_CHAR(2,2,16,"hex");
} else if (nc>='0' && nc<='7') {
NUMERIC_CHAR(1,3,10,"octal");
+ } else {
+ xlu__cfgl_lexicalerror(ctx, "invalid character after backlash "
+ "in quoted string");
+ ctx->err= EINVAL;
+ goto x;
}
assert(p <= src+len-1);
} else {
--
1.8.0.1
_______________________________________________
Xen-devel mailing list
Xen-devel@xxxxxxxxxxxxx
http://lists.xen.org/xen-devel
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |