qapi: protect against NULL QObject in qmp_input_get_object
[sdk/emulator/qemu.git] / qapi / qmp-input-visitor.c
1 /*
2  * Input Visitor
3  *
4  * Copyright IBM, Corp. 2011
5  *
6  * Authors:
7  *  Anthony Liguori   <aliguori@us.ibm.com>
8  *
9  * This work is licensed under the terms of the GNU LGPL, version 2.1 or later.
10  * See the COPYING.LIB file in the top-level directory.
11  *
12  */
13
14 #include "qmp-input-visitor.h"
15 #include "qemu-queue.h"
16 #include "qemu-common.h"
17 #include "qemu-objects.h"
18 #include "qerror.h"
19
20 #define QIV_STACK_SIZE 1024
21
22 typedef struct StackObject
23 {
24     const QObject *obj;
25     const  QListEntry *entry;
26 } StackObject;
27
28 struct QmpInputVisitor
29 {
30     Visitor visitor;
31     QObject *obj;
32     StackObject stack[QIV_STACK_SIZE];
33     int nb_stack;
34 };
35
36 static QmpInputVisitor *to_qiv(Visitor *v)
37 {
38     return container_of(v, QmpInputVisitor, visitor);
39 }
40
41 static const QObject *qmp_input_get_object(QmpInputVisitor *qiv,
42                                            const char *name)
43 {
44     const QObject *qobj;
45
46     if (qiv->nb_stack == 0) {
47         qobj = qiv->obj;
48     } else {
49         qobj = qiv->stack[qiv->nb_stack - 1].obj;
50     }
51
52     if (qobj) {
53         if (name && qobject_type(qobj) == QTYPE_QDICT) {
54             return qdict_get(qobject_to_qdict(qobj), name);
55         } else if (qiv->nb_stack > 0 && qobject_type(qobj) == QTYPE_QLIST) {
56             return qlist_entry_obj(qiv->stack[qiv->nb_stack - 1].entry);
57         }
58     }
59
60     return qobj;
61 }
62
63 static void qmp_input_push(QmpInputVisitor *qiv, const QObject *obj, Error **errp)
64 {
65     qiv->stack[qiv->nb_stack].obj = obj;
66     if (qobject_type(obj) == QTYPE_QLIST) {
67         qiv->stack[qiv->nb_stack].entry = qlist_first(qobject_to_qlist(obj));
68     }
69     qiv->nb_stack++;
70
71     if (qiv->nb_stack >= QIV_STACK_SIZE) {
72         error_set(errp, QERR_BUFFER_OVERRUN);
73         return;
74     }
75 }
76
77 static void qmp_input_pop(QmpInputVisitor *qiv, Error **errp)
78 {
79     qiv->nb_stack--;
80     if (qiv->nb_stack < 0) {
81         error_set(errp, QERR_BUFFER_OVERRUN);
82         return;
83     }
84 }
85
86 static void qmp_input_start_struct(Visitor *v, void **obj, const char *kind,
87                                    const char *name, size_t size, Error **errp)
88 {
89     QmpInputVisitor *qiv = to_qiv(v);
90     const QObject *qobj = qmp_input_get_object(qiv, name);
91
92     if (!qobj || qobject_type(qobj) != QTYPE_QDICT) {
93         error_set(errp, QERR_INVALID_PARAMETER_TYPE, name ? name : "null",
94                   "QDict");
95         return;
96     }
97
98     qmp_input_push(qiv, qobj, errp);
99     if (error_is_set(errp)) {
100         return;
101     }
102
103     if (obj) {
104         *obj = g_malloc0(size);
105     }
106 }
107
108 static void qmp_input_end_struct(Visitor *v, Error **errp)
109 {
110     QmpInputVisitor *qiv = to_qiv(v);
111
112     qmp_input_pop(qiv, errp);
113 }
114
115 static void qmp_input_start_list(Visitor *v, const char *name, Error **errp)
116 {
117     QmpInputVisitor *qiv = to_qiv(v);
118     const QObject *qobj = qmp_input_get_object(qiv, name);
119
120     if (!qobj || qobject_type(qobj) != QTYPE_QLIST) {
121         error_set(errp, QERR_INVALID_PARAMETER_TYPE, name ? name : "null",
122                   "list");
123         return;
124     }
125
126     qmp_input_push(qiv, qobj, errp);
127 }
128
129 static GenericList *qmp_input_next_list(Visitor *v, GenericList **list,
130                                         Error **errp)
131 {
132     QmpInputVisitor *qiv = to_qiv(v);
133     GenericList *entry;
134     StackObject *so = &qiv->stack[qiv->nb_stack - 1];
135
136     if (so->entry == NULL) {
137         return NULL;
138     }
139
140     entry = g_malloc0(sizeof(*entry));
141     if (*list) {
142         so->entry = qlist_next(so->entry);
143         if (so->entry == NULL) {
144             g_free(entry);
145             return NULL;
146         }
147         (*list)->next = entry;
148     }
149
150     return entry;
151 }
152
153 static void qmp_input_end_list(Visitor *v, Error **errp)
154 {
155     QmpInputVisitor *qiv = to_qiv(v);
156
157     qmp_input_pop(qiv, errp);
158 }
159
160 static void qmp_input_type_int(Visitor *v, int64_t *obj, const char *name,
161                                Error **errp)
162 {
163     QmpInputVisitor *qiv = to_qiv(v);
164     const QObject *qobj = qmp_input_get_object(qiv, name);
165
166     if (!qobj || qobject_type(qobj) != QTYPE_QINT) {
167         error_set(errp, QERR_INVALID_PARAMETER_TYPE, name ? name : "null",
168                   "integer");
169         return;
170     }
171
172     *obj = qint_get_int(qobject_to_qint(qobj));
173 }
174
175 static void qmp_input_type_bool(Visitor *v, bool *obj, const char *name,
176                                 Error **errp)
177 {
178     QmpInputVisitor *qiv = to_qiv(v);
179     const QObject *qobj = qmp_input_get_object(qiv, name);
180
181     if (!qobj || qobject_type(qobj) != QTYPE_QBOOL) {
182         error_set(errp, QERR_INVALID_PARAMETER_TYPE, name ? name : "null",
183                   "boolean");
184         return;
185     }
186
187     *obj = qbool_get_int(qobject_to_qbool(qobj));
188 }
189
190 static void qmp_input_type_str(Visitor *v, char **obj, const char *name,
191                                Error **errp)
192 {
193     QmpInputVisitor *qiv = to_qiv(v);
194     const QObject *qobj = qmp_input_get_object(qiv, name);
195
196     if (!qobj || qobject_type(qobj) != QTYPE_QSTRING) {
197         error_set(errp, QERR_INVALID_PARAMETER_TYPE, name ? name : "null",
198                   "string");
199         return;
200     }
201
202     *obj = g_strdup(qstring_get_str(qobject_to_qstring(qobj)));
203 }
204
205 static void qmp_input_type_number(Visitor *v, double *obj, const char *name,
206                                   Error **errp)
207 {
208     QmpInputVisitor *qiv = to_qiv(v);
209     const QObject *qobj = qmp_input_get_object(qiv, name);
210
211     if (!qobj || qobject_type(qobj) != QTYPE_QFLOAT) {
212         error_set(errp, QERR_INVALID_PARAMETER_TYPE, name ? name : "null",
213                   "double");
214         return;
215     }
216
217     *obj = qfloat_get_double(qobject_to_qfloat(qobj));
218 }
219
220 static void qmp_input_type_enum(Visitor *v, int *obj, const char *strings[],
221                                 const char *kind, const char *name,
222                                 Error **errp)
223 {
224     int64_t value = 0;
225     char *enum_str;
226
227     assert(strings);
228
229     qmp_input_type_str(v, &enum_str, name, errp);
230     if (error_is_set(errp)) {
231         return;
232     }
233
234     while (strings[value] != NULL) {
235         if (strcmp(strings[value], enum_str) == 0) {
236             break;
237         }
238         value++;
239     }
240
241     if (strings[value] == NULL) {
242         error_set(errp, QERR_INVALID_PARAMETER, name ? name : "null");
243         g_free(enum_str);
244         return;
245     }
246
247     g_free(enum_str);
248     *obj = value;
249 }
250
251 static void qmp_input_start_optional(Visitor *v, bool *present,
252                                      const char *name, Error **errp)
253 {
254     QmpInputVisitor *qiv = to_qiv(v);
255     const QObject *qobj = qmp_input_get_object(qiv, name);
256
257     if (!qobj) {
258         *present = false;
259         return;
260     }
261
262     *present = true;
263 }
264
265 static void qmp_input_end_optional(Visitor *v, Error **errp)
266 {
267 }
268
269 Visitor *qmp_input_get_visitor(QmpInputVisitor *v)
270 {
271     return &v->visitor;
272 }
273
274 void qmp_input_visitor_cleanup(QmpInputVisitor *v)
275 {
276     qobject_decref(v->obj);
277     g_free(v);
278 }
279
280 QmpInputVisitor *qmp_input_visitor_new(QObject *obj)
281 {
282     QmpInputVisitor *v;
283
284     v = g_malloc0(sizeof(*v));
285
286     v->visitor.start_struct = qmp_input_start_struct;
287     v->visitor.end_struct = qmp_input_end_struct;
288     v->visitor.start_list = qmp_input_start_list;
289     v->visitor.next_list = qmp_input_next_list;
290     v->visitor.end_list = qmp_input_end_list;
291     v->visitor.type_enum = qmp_input_type_enum;
292     v->visitor.type_int = qmp_input_type_int;
293     v->visitor.type_bool = qmp_input_type_bool;
294     v->visitor.type_str = qmp_input_type_str;
295     v->visitor.type_number = qmp_input_type_number;
296     v->visitor.start_optional = qmp_input_start_optional;
297     v->visitor.end_optional = qmp_input_end_optional;
298
299     v->obj = obj;
300     qobject_incref(v->obj);
301
302     return v;
303 }