Am 21.09.26 um 20:43 schrieb Eric Farman:
The loop to store pending IRQs uses g_try_realloc() to expand the
buffer being used, but the returned address is stored in a
pointer-to-pointer, thus the check is supposed to be examining
the contents of the pointer, and not the pointer itself.

Define a temporary variable to catch and test the returned pointer.
If it's NULL, return to the caller to perform the free on the
unmodified buffer. If it's not NULL, store it in the caller's
pointer and restart the loop against the new struct.

Cc: [email protected]
Fixes: 3a553fc658 ("s390x/kvm: implement floating-interrupt controller device")
Signed-off-by: Eric Farman <[email protected]>
---
  hw/intc/s390_flic_kvm.c | 6 ++++--
  1 file changed, 4 insertions(+), 2 deletions(-)

diff --git a/hw/intc/s390_flic_kvm.c b/hw/intc/s390_flic_kvm.c
index 5e6d422fba..ebee6bca9c 100644
--- a/hw/intc/s390_flic_kvm.c
+++ b/hw/intc/s390_flic_kvm.c
@@ -254,6 +254,7 @@ static int __get_all_irqs(KVMS390FLICState *flic,
                            void **buf, int len)
  {
      int r;
+    void *realloc = NULL;

Ideally use a different name to avoid shadowing the libc function.  (e.g. 
new_buf)
Other than that

Reviewed-by: Christian Borntraeger <[email protected]>

do {
          /* returns -ENOMEM if buffer is too small and number
@@ -263,10 +264,11 @@ static int __get_all_irqs(KVMS390FLICState *flic,
              break;
          }
          len *= 2;
-        *buf = g_try_realloc(*buf, len);
-        if (!buf) {
+        realloc = g_try_realloc(*buf, len);
+        if (!realloc) {
              return -ENOMEM;
          }
+        *buf = realloc;
      } while (r == -ENOMEM && len <= KVM_S390_FLIC_MAX_BUFFER);
return r;


Reply via email to