qxl-render: add sanity check
authorGerd Hoffmann <kraxel@redhat.com>
Tue, 10 Jun 2014 11:51:12 +0000 (13:51 +0200)
committerGerd Hoffmann <kraxel@redhat.com>
Fri, 13 Jun 2014 10:34:57 +0000 (12:34 +0200)
Verify dirty rectangle is completely within the primary surface,
just ignore it in case it isn't.

Signed-off-by: Gerd Hoffmann <kraxel@redhat.com>
hw/display/qxl-render.c

index 84f1367..cc2c2b1 100644 (file)
@@ -138,6 +138,12 @@ static void qxl_render_update_area_unlocked(PCIQXLDevice *qxl)
         if (qemu_spice_rect_is_empty(qxl->dirty+i)) {
             break;
         }
+        if (qxl->dirty[i].left > qxl->dirty[i].right ||
+            qxl->dirty[i].top > qxl->dirty[i].bottom ||
+            qxl->dirty[i].right > qxl->guest_primary.surface.width ||
+            qxl->dirty[i].bottom > qxl->guest_primary.surface.height) {
+            continue;
+        }
         qxl_blit(qxl, qxl->dirty+i);
         dpy_gfx_update(vga->con,
                        qxl->dirty[i].left, qxl->dirty[i].top,