eda6aa8e7f
qemuAgentGetVCPUs() dfc69235-CVE-2013-4153.patch - CVE-2013-4154: Prevent crash of libvirtd without guest agent configuration 96518d43-CVE-2013-4154.patch bnc#830498 OBS-URL: https://build.opensuse.org/package/show/Virtualization/libvirt?expand=0&rev=286
86 lines
3.5 KiB
Diff
86 lines
3.5 KiB
Diff
commit 96518d4316b711c72205117f8d5c967d5127bbb6
|
|
Author: Alex Jia <ajia@redhat.com>
|
|
Date: Tue Jul 16 17:30:20 2013 +0800
|
|
|
|
qemu: Prevent crash of libvirtd without guest agent configuration
|
|
|
|
If users haven't configured guest agent then qemuAgentCommand() will
|
|
dereference a NULL 'mon' pointer, which causes crash of libvirtd when
|
|
using agent based cpu (un)plug.
|
|
|
|
With the patch, when the qemu-ga service isn't running in the guest,
|
|
a expected error "error: Guest agent is not responding: Guest agent
|
|
not available for now" will be raised, and the error "error: argument
|
|
unsupported: QEMU guest agent is not configured" is raised when the
|
|
guest hasn't configured guest agent.
|
|
|
|
GDB backtrace:
|
|
|
|
(gdb) bt
|
|
#0 virNetServerFatalSignal (sig=11, siginfo=<value optimized out>, context=<value optimized out>) at rpc/virnetserver.c:326
|
|
#1 <signal handler called>
|
|
#2 qemuAgentCommand (mon=0x0, cmd=0x7f39300017b0, reply=0x7f394b090910, seconds=-2) at qemu/qemu_agent.c:975
|
|
#3 0x00007f39429507f6 in qemuAgentGetVCPUs (mon=0x0, info=0x7f394b0909b8) at qemu/qemu_agent.c:1475
|
|
#4 0x00007f39429d9857 in qemuDomainGetVcpusFlags (dom=<value optimized out>, flags=9) at qemu/qemu_driver.c:4849
|
|
#5 0x00007f3957dffd8d in virDomainGetVcpusFlags (domain=0x7f39300009c0, flags=8) at libvirt.c:9843
|
|
|
|
How to reproduce?
|
|
|
|
# To start a guest without guest agent configuration
|
|
# then run the following cmdline
|
|
|
|
# virsh vcpucount foobar --guest
|
|
error: End of file while reading data: Input/output error
|
|
error: One or more references were leaked after disconnect from the hypervisor
|
|
error: Failed to reconnect to the hypervisor
|
|
|
|
RHBZ: https://bugzilla.redhat.com/show_bug.cgi?id=984821
|
|
|
|
Signed-off-by: Alex Jia <ajia@redhat.com>
|
|
Signed-off-by: Peter Krempa <pkrempa@redhat.com>
|
|
|
|
Index: libvirt-1.1.0/src/qemu/qemu_driver.c
|
|
===================================================================
|
|
--- libvirt-1.1.0.orig/src/qemu/qemu_driver.c
|
|
+++ libvirt-1.1.0/src/qemu/qemu_driver.c
|
|
@@ -3963,6 +3963,19 @@ qemuDomainSetVcpusFlags(virDomainPtr dom
|
|
goto endjob;
|
|
}
|
|
|
|
+ if (priv->agentError) {
|
|
+ virReportError(VIR_ERR_AGENT_UNRESPONSIVE, "%s",
|
|
+ _("QEMU guest agent is not "
|
|
+ "available due to an error"));
|
|
+ goto endjob;
|
|
+ }
|
|
+
|
|
+ if (!priv->agent) {
|
|
+ virReportError(VIR_ERR_ARGUMENT_UNSUPPORTED, "%s",
|
|
+ _("QEMU guest agent is not configured"));
|
|
+ goto endjob;
|
|
+ }
|
|
+
|
|
qemuDomainObjEnterAgent(vm);
|
|
ncpuinfo = qemuAgentGetVCPUs(priv->agent, &cpuinfo);
|
|
qemuDomainObjExitAgent(vm);
|
|
@@ -4685,6 +4698,19 @@ qemuDomainGetVcpusFlags(virDomainPtr dom
|
|
if (qemuDomainObjBeginJob(driver, vm, QEMU_JOB_QUERY) < 0)
|
|
goto cleanup;
|
|
|
|
+ if (priv->agentError) {
|
|
+ virReportError(VIR_ERR_AGENT_UNRESPONSIVE, "%s",
|
|
+ _("QEMU guest agent is not "
|
|
+ "available due to an error"));
|
|
+ goto endjob;
|
|
+ }
|
|
+
|
|
+ if (!priv->agent) {
|
|
+ virReportError(VIR_ERR_ARGUMENT_UNSUPPORTED, "%s",
|
|
+ _("QEMU guest agent is not configured"));
|
|
+ goto endjob;
|
|
+ }
|
|
+
|
|
if (!virDomainObjIsActive(vm)) {
|
|
virReportError(VIR_ERR_OPERATION_INVALID, "%s",
|
|
_("domain is not running"));
|