From patchwork Sun Jul 5 10:24:24 2009 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: "Michael S. Tsirkin" X-Patchwork-Id: 34117 Received: from vger.kernel.org (vger.kernel.org [209.132.176.167]) by demeter.kernel.org (8.14.2/8.14.2) with ESMTP id n65AP8fR012047 for ; Sun, 5 Jul 2009 10:25:08 GMT Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1752918AbZGEKZD (ORCPT ); Sun, 5 Jul 2009 06:25:03 -0400 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1752920AbZGEKZC (ORCPT ); Sun, 5 Jul 2009 06:25:02 -0400 Received: from mx2.redhat.com ([66.187.237.31]:48019 "EHLO mx2.redhat.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752905AbZGEKZB (ORCPT ); Sun, 5 Jul 2009 06:25:01 -0400 Received: from int-mx2.corp.redhat.com (int-mx2.corp.redhat.com [172.16.27.26]) by mx2.redhat.com (8.13.8/8.13.8) with ESMTP id n65AP4Xd031147; Sun, 5 Jul 2009 06:25:04 -0400 Received: from ns3.rdu.redhat.com (ns3.rdu.redhat.com [10.11.255.199]) by int-mx2.corp.redhat.com (8.13.1/8.13.1) with ESMTP id n65AP3fk031614; Sun, 5 Jul 2009 06:25:03 -0400 Received: from redhat.com (vpn-6-125.tlv.redhat.com [10.35.6.125]) by ns3.rdu.redhat.com (8.13.8/8.13.8) with ESMTP id n65AOx5s000871; Sun, 5 Jul 2009 06:24:59 -0400 Date: Sun, 5 Jul 2009 13:24:24 +0300 From: "Michael S. Tsirkin" To: qemu-devel@nongnu.org, avi@redhat.com, kvm@vger.kernel.org, aliguori@us.ibm.com, kwolf@redhat.com Subject: [PATCHv3 1/3] qemu/msi: fix segfault in msix_save Message-ID: <20090705102423.GA3833@redhat.com> References: MIME-Version: 1.0 Content-Disposition: inline In-Reply-To: User-Agent: Mutt/1.5.19 (2009-01-05) X-Scanned-By: MIMEDefang 2.58 on 172.16.27.26 Sender: kvm-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: kvm@vger.kernel.org This fixes segfault reported by Kevin Wolf, and simplifies the code in msix_save. Reported-by: Kevin Wolf Signed-off-by: Michael S. Tsirkin --- hw/msix.c | 12 +++++++----- 1 files changed, 7 insertions(+), 5 deletions(-) diff --git a/hw/msix.c b/hw/msix.c index 4ab6da6..98c62a5 100644 --- a/hw/msix.c +++ b/hw/msix.c @@ -284,11 +284,13 @@ int msix_uninit(PCIDevice *dev) void msix_save(PCIDevice *dev, QEMUFile *f) { - unsigned nentries = (pci_get_word(dev->config + PCI_MSIX_FLAGS) & - PCI_MSIX_FLAGS_QSIZE) + 1; - qemu_put_buffer(f, dev->msix_table_page, nentries * MSIX_ENTRY_SIZE); - qemu_put_buffer(f, dev->msix_table_page + MSIX_PAGE_PENDING, - (nentries + 7) / 8); + unsigned n = dev->msix_entries_nr; + + if (!dev->cap_present & QEMU_PCI_CAP_MSIX) + return; + + qemu_put_buffer(f, dev->msix_table_page, n * MSIX_ENTRY_SIZE); + qemu_put_buffer(f, dev->msix_table_page + MSIX_PAGE_PENDING, (n + 7) / 8); } /* Should be called after restoring the config space. */