[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[PULL 01/17] ui: Check numeric part of expire_password argument @time pr
From: |
Markus Armbruster |
Subject: |
[PULL 01/17] ui: Check numeric part of expire_password argument @time properly |
Date: |
Thu, 19 Jan 2023 14:26:57 +0100 |
When argument @time isn't 'now' or 'never', we parse it as an integer,
optionally prefixed with '+'. If parsing fails, we silently assume
zero. Report an error and fail instead.
While there, use qemu_strtou64() instead of strtoull() so
checkpatch.pl won't complain.
Aside: encoding numbers in strings is bad QMP practice.
Signed-off-by: Markus Armbruster <armbru@redhat.com>
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
Message-Id: <20230109190321.1056914-2-armbru@redhat.com>
---
monitor/qmp-cmds.c | 17 +++++++++++++++--
1 file changed, 15 insertions(+), 2 deletions(-)
diff --git a/monitor/qmp-cmds.c b/monitor/qmp-cmds.c
index 2932b3f3a5..a1695b6c96 100644
--- a/monitor/qmp-cmds.c
+++ b/monitor/qmp-cmds.c
@@ -201,15 +201,28 @@ void qmp_expire_password(ExpirePasswordOptions *opts,
Error **errp)
time_t when;
int rc;
const char *whenstr = opts->time;
+ const char *numstr = NULL;
+ uint64_t num;
if (strcmp(whenstr, "now") == 0) {
when = 0;
} else if (strcmp(whenstr, "never") == 0) {
when = TIME_MAX;
} else if (whenstr[0] == '+') {
- when = time(NULL) + strtoull(whenstr+1, NULL, 10);
+ when = time(NULL);
+ numstr = whenstr + 1;
} else {
- when = strtoull(whenstr, NULL, 10);
+ when = 0;
+ numstr = whenstr;
+ }
+
+ if (numstr) {
+ if (qemu_strtou64(numstr, NULL, 10, &num) < 0) {
+ error_setg(errp, "Parameter 'time' doesn't take value '%s'",
+ whenstr);
+ return;
+ }
+ when += num;
}
if (opts->protocol == DISPLAY_PROTOCOL_SPICE) {
--
2.39.0
- [PULL 10/17] ui: Factor out qmp_add_client() parts and move to ui/ui-qmp-cmds.c, (continued)
- [PULL 10/17] ui: Factor out qmp_add_client() parts and move to ui/ui-qmp-cmds.c, Markus Armbruster, 2023/01/19
- [PULL 02/17] ui: Fix silent truncation of numeric keys in HMP sendkey, Markus Armbruster, 2023/01/19
- [PULL 11/17] ui: Move HMP commands from monitor to new ui/ui-hmp-cmds.c, Markus Armbruster, 2023/01/19
- [PULL 14/17] ui: Reduce nesting in hmp_change_vnc() slightly, Markus Armbruster, 2023/01/19
- [PULL 13/17] ui: Factor out hmp_change_vnc(), and move to ui/ui-hmp-cmds.c, Markus Armbruster, 2023/01/19
- [PULL 17/17] ui: Simplify control flow in qemu_mouse_set(), Markus Armbruster, 2023/01/19
- [PULL 07/17] ui/spice: Give hmp_info_spice()'s channel_names[] static linkage, Markus Armbruster, 2023/01/19
- [PULL 08/17] ui: Clean up a few things checkpatch.pl would flag later on, Markus Armbruster, 2023/01/19
- [PULL 12/17] ui: Improve "change vnc" error reporting, Markus Armbruster, 2023/01/19
- [PULL 06/17] ui/spice: QXLInterface method set_mm_time() is now dead, drop, Markus Armbruster, 2023/01/19
- [PULL 01/17] ui: Check numeric part of expire_password argument @time properly,
Markus Armbruster <=
- Re: [PULL 00/17] Monitor patches for 2023-01-19, Peter Maydell, 2023/01/20