Re: [PATCH] virtio: make virtio_add_queue() queue_size an unsigned int
Peter Maydell <[email protected]>
| Newsgroups | gmane.comp.emulators.qemu |
|---|---|
| Message-ID | <CAFEAcA-mn4x9MJ1dVra1jP_5taJJQHwYz-khKXzm8RCeYnaELg@mail.gmail.com> |
On Thu, 30 Jul 2026 at 16:36, Stefan Hajnoczi <[email protected]> wrote: > > virtio_add_queue()'s queue_size argument is a signed int. Coverity is > unhappy when that type is used as an argument to g_new0(): > > *** CID 1664271: Error handling issues (NEGATIVE_RETURNS) > /builds/qemu-project/qemu/hw/virtio/virtio.c: 2595 in virtio_add_queue() > 2589 } > 2590 > 2591 vdev->vq[i].vring.num = queue_size; > 2592 vdev->vq[i].vring.num_default = queue_size; > 2593 vdev->vq[i].vring.align = VIRTIO_PCI_VRING_ALIGN; > 2594 vdev->vq[i].handle_output = handle_output; > >>> CID 1664271: Error handling issues (NEGATIVE_RETURNS) > >>> "__n" is passed to a parameter that cannot be negative. > 2595 vdev->vq[i].used_elems = g_new0(VirtQueueElement, queue_size); Though note that the reason Coverity thinks this value can be negative is not because the function might be passed a negative value, but because it incorrectly thinks that int override = object_property_get_int(OBJECT(qbus->parent), VIRTIO_QUEUE_SIZE_OVERRIDE, &error_abort); can return a negative number. (It can't because of the error_abort and because the property is a UINT16 one.) It might be a good idea to enforce the VIRTQUEUE_MAX_SIZE bounds check on the queue size we get from the override property. Since I think that can be set by the end-user (though probably it won't be in practice) ideally we would not abort() on a bad property value, but that's awkward to do at this point... thanks -- PMM