esp: check command buffer length before write(CVE-2016-4439)
[qemu/ar7.git] / tests / test-qmp-commands.c
blob5c3edd753a722480a615551335c8b8f852086717
1 #include "qemu/osdep.h"
2 #include <glib.h>
3 #include "qemu-common.h"
4 #include "qapi/qmp/types.h"
5 #include "test-qmp-commands.h"
6 #include "qapi/qmp/dispatch.h"
7 #include "qemu/module.h"
8 #include "qapi/qmp-input-visitor.h"
9 #include "tests/test-qapi-types.h"
10 #include "tests/test-qapi-visit.h"
12 void qmp_user_def_cmd(Error **errp)
16 Empty2 *qmp_user_def_cmd0(Error **errp)
18 return g_new0(Empty2, 1);
21 void qmp_user_def_cmd1(UserDefOne * ud1, Error **errp)
25 UserDefTwo *qmp_user_def_cmd2(UserDefOne *ud1a,
26 bool has_udb1, UserDefOne *ud1b,
27 Error **errp)
29 UserDefTwo *ret;
30 UserDefOne *ud1c = g_malloc0(sizeof(UserDefOne));
31 UserDefOne *ud1d = g_malloc0(sizeof(UserDefOne));
33 ud1c->string = strdup(ud1a->string);
34 ud1c->integer = ud1a->integer;
35 ud1d->string = strdup(has_udb1 ? ud1b->string : "blah0");
36 ud1d->integer = has_udb1 ? ud1b->integer : 0;
38 ret = g_new0(UserDefTwo, 1);
39 ret->string0 = strdup("blah1");
40 ret->dict1 = g_new0(UserDefTwoDict, 1);
41 ret->dict1->string1 = strdup("blah2");
42 ret->dict1->dict2 = g_new0(UserDefTwoDictDict, 1);
43 ret->dict1->dict2->userdef = ud1c;
44 ret->dict1->dict2->string = strdup("blah3");
45 ret->dict1->dict3 = g_new0(UserDefTwoDictDict, 1);
46 ret->dict1->has_dict3 = true;
47 ret->dict1->dict3->userdef = ud1d;
48 ret->dict1->dict3->string = strdup("blah4");
50 return ret;
53 int64_t qmp_guest_get_time(int64_t a, bool has_b, int64_t b, Error **errp)
55 return a + (has_b ? b : 0);
58 QObject *qmp_guest_sync(QObject *arg, Error **errp)
60 return arg;
63 __org_qemu_x_Union1 *qmp___org_qemu_x_command(__org_qemu_x_EnumList *a,
64 __org_qemu_x_StructList *b,
65 __org_qemu_x_Union2 *c,
66 __org_qemu_x_Alt *d,
67 Error **errp)
69 __org_qemu_x_Union1 *ret = g_new0(__org_qemu_x_Union1, 1);
71 ret->type = ORG_QEMU_X_UNION1_KIND___ORG_QEMU_X_BRANCH;
72 ret->u.__org_qemu_x_branch.data = strdup("blah1");
74 /* Also test that 'wchar-t' was munged to 'q_wchar_t' */
75 if (b && b->value && !b->value->has_q_wchar_t) {
76 b->value->q_wchar_t = 1;
78 return ret;
82 /* test commands with no input and no return value */
83 static void test_dispatch_cmd(void)
85 QDict *req = qdict_new();
86 QObject *resp;
88 qdict_put_obj(req, "execute", QOBJECT(qstring_from_str("user_def_cmd")));
90 resp = qmp_dispatch(QOBJECT(req));
91 assert(resp != NULL);
92 assert(!qdict_haskey(qobject_to_qdict(resp), "error"));
94 qobject_decref(resp);
95 QDECREF(req);
98 /* test commands that return an error due to invalid parameters */
99 static void test_dispatch_cmd_error(void)
101 QDict *req = qdict_new();
102 QObject *resp;
104 qdict_put_obj(req, "execute", QOBJECT(qstring_from_str("user_def_cmd2")));
106 resp = qmp_dispatch(QOBJECT(req));
107 assert(resp != NULL);
108 assert(qdict_haskey(qobject_to_qdict(resp), "error"));
110 qobject_decref(resp);
111 QDECREF(req);
114 static QObject *test_qmp_dispatch(QDict *req)
116 QObject *resp_obj;
117 QDict *resp;
118 QObject *ret;
120 resp_obj = qmp_dispatch(QOBJECT(req));
121 assert(resp_obj);
122 resp = qobject_to_qdict(resp_obj);
123 assert(resp && !qdict_haskey(resp, "error"));
124 ret = qdict_get(resp, "return");
125 assert(ret);
126 qobject_incref(ret);
127 qobject_decref(resp_obj);
128 return ret;
131 /* test commands that involve both input parameters and return values */
132 static void test_dispatch_cmd_io(void)
134 QDict *req = qdict_new();
135 QDict *args = qdict_new();
136 QDict *args3 = qdict_new();
137 QDict *ud1a = qdict_new();
138 QDict *ud1b = qdict_new();
139 QDict *ret, *ret_dict, *ret_dict_dict, *ret_dict_dict_userdef;
140 QDict *ret_dict_dict2, *ret_dict_dict2_userdef;
141 QInt *ret3;
143 qdict_put_obj(ud1a, "integer", QOBJECT(qint_from_int(42)));
144 qdict_put_obj(ud1a, "string", QOBJECT(qstring_from_str("hello")));
145 qdict_put_obj(ud1b, "integer", QOBJECT(qint_from_int(422)));
146 qdict_put_obj(ud1b, "string", QOBJECT(qstring_from_str("hello2")));
147 qdict_put_obj(args, "ud1a", QOBJECT(ud1a));
148 qdict_put_obj(args, "ud1b", QOBJECT(ud1b));
149 qdict_put_obj(req, "arguments", QOBJECT(args));
150 qdict_put_obj(req, "execute", QOBJECT(qstring_from_str("user_def_cmd2")));
152 ret = qobject_to_qdict(test_qmp_dispatch(req));
154 assert(!strcmp(qdict_get_str(ret, "string0"), "blah1"));
155 ret_dict = qdict_get_qdict(ret, "dict1");
156 assert(!strcmp(qdict_get_str(ret_dict, "string1"), "blah2"));
157 ret_dict_dict = qdict_get_qdict(ret_dict, "dict2");
158 ret_dict_dict_userdef = qdict_get_qdict(ret_dict_dict, "userdef");
159 assert(qdict_get_int(ret_dict_dict_userdef, "integer") == 42);
160 assert(!strcmp(qdict_get_str(ret_dict_dict_userdef, "string"), "hello"));
161 assert(!strcmp(qdict_get_str(ret_dict_dict, "string"), "blah3"));
162 ret_dict_dict2 = qdict_get_qdict(ret_dict, "dict3");
163 ret_dict_dict2_userdef = qdict_get_qdict(ret_dict_dict2, "userdef");
164 assert(qdict_get_int(ret_dict_dict2_userdef, "integer") == 422);
165 assert(!strcmp(qdict_get_str(ret_dict_dict2_userdef, "string"), "hello2"));
166 assert(!strcmp(qdict_get_str(ret_dict_dict2, "string"), "blah4"));
167 QDECREF(ret);
169 qdict_put(args3, "a", qint_from_int(66));
170 qdict_put(req, "arguments", args3);
171 qdict_put(req, "execute", qstring_from_str("guest-get-time"));
173 ret3 = qobject_to_qint(test_qmp_dispatch(req));
174 assert(qint_get_int(ret3) == 66);
175 QDECREF(ret3);
177 QDECREF(req);
180 /* test generated dealloc functions for generated types */
181 static void test_dealloc_types(void)
183 UserDefOne *ud1test, *ud1a, *ud1b;
184 UserDefOneList *ud1list;
186 ud1test = g_malloc0(sizeof(UserDefOne));
187 ud1test->integer = 42;
188 ud1test->string = g_strdup("hi there 42");
190 qapi_free_UserDefOne(ud1test);
192 ud1a = g_malloc0(sizeof(UserDefOne));
193 ud1a->integer = 43;
194 ud1a->string = g_strdup("hi there 43");
196 ud1b = g_malloc0(sizeof(UserDefOne));
197 ud1b->integer = 44;
198 ud1b->string = g_strdup("hi there 44");
200 ud1list = g_malloc0(sizeof(UserDefOneList));
201 ud1list->value = ud1a;
202 ud1list->next = g_malloc0(sizeof(UserDefOneList));
203 ud1list->next->value = ud1b;
205 qapi_free_UserDefOneList(ud1list);
208 /* test generated deallocation on an object whose construction was prematurely
209 * terminated due to an error */
210 static void test_dealloc_partial(void)
212 static const char text[] = "don't leak me";
214 UserDefTwo *ud2 = NULL;
215 Error *err = NULL;
217 /* create partial object */
219 QDict *ud2_dict;
220 QmpInputVisitor *qiv;
222 ud2_dict = qdict_new();
223 qdict_put_obj(ud2_dict, "string0", QOBJECT(qstring_from_str(text)));
225 qiv = qmp_input_visitor_new(QOBJECT(ud2_dict), true);
226 visit_type_UserDefTwo(qmp_input_get_visitor(qiv), NULL, &ud2, &err);
227 qmp_input_visitor_cleanup(qiv);
228 QDECREF(ud2_dict);
231 /* verify that visit_type_XXX() cleans up properly on error */
232 error_free_or_abort(&err);
233 assert(!ud2);
235 /* Manually create a partial object, leaving ud2->dict1 at NULL */
236 ud2 = g_new0(UserDefTwo, 1);
237 ud2->string0 = g_strdup(text);
239 /* tear down partial object */
240 qapi_free_UserDefTwo(ud2);
244 int main(int argc, char **argv)
246 g_test_init(&argc, &argv, NULL);
248 g_test_add_func("/0.15/dispatch_cmd", test_dispatch_cmd);
249 g_test_add_func("/0.15/dispatch_cmd_error", test_dispatch_cmd_error);
250 g_test_add_func("/0.15/dispatch_cmd_io", test_dispatch_cmd_io);
251 g_test_add_func("/0.15/dealloc_types", test_dealloc_types);
252 g_test_add_func("/0.15/dealloc_partial", test_dealloc_partial);
254 module_call_init(MODULE_INIT_QAPI);
255 g_test_run();
257 return 0;