- remote_driver: Restore special behavior of remoteDomainGetBlockIoTune() (RHEL-22800) - conf: Introduce dynamicMemslots attribute for virtio-mem (RHEL-15316) - qemu_capabilities: Add QEMU_CAPS_DEVICE_VIRTIO_MEM_PCI_DYNAMIC_MEMSLOTS capability (RHEL-15316) - qemu_validate: Check capability for virtio-mem dynamicMemslots (RHEL-15316) - qemu_command: Generate cmd line for virtio-mem dynamicMemslots (RHEL-15316) - qemu_snapshot: fix detection if non-leaf snapshot isn't in active chain (RHEL-23212) - qemu_snapshot: create: refactor external snapshot detection (RHEL-22797) - qemu_snapshot: create: don't require disk-only flag for offline external snapshot (RHEL-22797) - remoteDispatchAuthPolkit: Fix lock ordering deadlock if client closes connection during auth (RHEL-20337) - util: virtportallocator: Add VIR_DEBUG statements for port allocations and release (RHEL-21543) - qemu: migration: Properly handle reservation of manually specified NBD port (RHEL-21543) - qemuMigrationDstStartNBDServer: Refactor cleanup (RHEL-21543) - virPCIVPDResourceIsValidTextValue: Adjust comment to reflect actual code (RHEL-22314) - util: pcivpd: Refactor virPCIVPDResourceIsValidTextValue (RHEL-22314) - virNodeDeviceCapVPDFormatCustom*: Escape unsanitized strings (RHEL-22314) - virNodeDeviceCapVPDFormat: Properly escape system-originated strings (RHEL-22314) - schema: nodedev: Adjust allowed characters in 'vpdFieldValueFormat' (RHEL-22314) - tests: Test the previously mishandled PCI VPD characters (RHEL-22314) - Don't overwrite error message from 'virXPathNodeSet' (RHEL-22314) - tests: virpcivpdtest: Remove 'testVirPCIVPDReadVPDBytes' case (RHEL-22314) - util: virpcivpd: Unexport 'virPCIVPDReadVPDBytes' (RHEL-22314) - util: pcivpd: Unexport virPCIVPDParseVPDLargeResourceFields (RHEL-22314) - tests: virpcivpd: Remove 'testVirPCIVPDParseVPDStringResource' case (RHEL-22314) - util: virpcivpd: Unexport 'virPCIVPDParseVPDLargeResourceString' (RHEL-22314) - virPCIVPDResourceGetKeywordPrefix: Fix logging (RHEL-22314) - util: virpcivpd: Remove return value from virPCIVPDResourceCustomUpsertValue (RHEL-22314) - conf: virNodeDeviceCapVPDParse*: Remove pointless NULL checks (RHEL-22314) - virpcivpdtest: testPCIVPDResourceBasic: Remove tests for uninitialized 'ro'/'rw' section (RHEL-22314) - util: virPCIVPDResourceUpdateKeyword: Remove impossible checks (RHEL-22314) - conf: node_device: Refactor 'virNodeDeviceCapVPDParseCustomFields' to fix error reporting (RHEL-22314) - virNodeDeviceCapVPDParseXML: Fix error reporting (RHEL-22314) - util: virpcivpd: Remove return value from virPCIVPDResourceUpdateKeyword (RHEL-22314) - virPCIDeviceHasVPD: Refactor "debug" messages (RHEL-22314) - virPCIDeviceGetVPD: Fix multiple error handling bugs (RHEL-22314) - virPCIDeviceGetVPD: Handle errors in callers (RHEL-22314) - virPCIVPDReadVPDBytes: Refactor error handling (RHEL-22314) - virPCIVPDParseVPDLargeResourceString: Properly report errors (RHEL-22314) - virPCIVPDParseVPDLargeResourceFields: Merge logic conditions (RHEL-22314) - virPCIVPDParseVPDLargeResourceFields: Remove impossible 'default' switch case (RHEL-22314) - virPCIVPDParseVPDLargeResourceFields: Refactor processing of read data (RHEL-22314) - virPCIVPDParseVPDLargeResourceFields: Refactor return logic (RHEL-22314) - virPCIVPDParseVPDLargeResourceFields: Report proper errors (RHEL-22314) - virPCIVPDParse: Do reasonable error reporting (RHEL-22314) - virt-admin: Add warning when connection to default daemon fails (RHEL-23170) Resolves: RHEL-15316, RHEL-20337, RHEL-21543, RHEL-22314, RHEL-22797 Resolves: RHEL-22800, RHEL-23170, RHEL-23212
95 lines
3.9 KiB
Diff
95 lines
3.9 KiB
Diff
From dd11b0a672feb5932548aa72c4db859889401587 Mon Sep 17 00:00:00 2001
|
|
Message-ID: <dd11b0a672feb5932548aa72c4db859889401587.1707394627.git.jdenemar@redhat.com>
|
|
From: Peter Krempa <pkrempa@redhat.com>
|
|
Date: Tue, 30 Jan 2024 17:11:37 +0100
|
|
Subject: [PATCH] virNodeDeviceCapVPDFormat: Properly escape system-originated
|
|
strings
|
|
MIME-Version: 1.0
|
|
Content-Type: text/plain; charset=UTF-8
|
|
Content-Transfer-Encoding: 8bit
|
|
|
|
Similarly to previous commit other specific fields which come from the
|
|
system data and aren't sanitized enough to be safe for XML were also
|
|
formatted via virBufferAsprintf.
|
|
|
|
Other static and safe strings used virBufferEscapeString instead of
|
|
virBufferAddLit.
|
|
|
|
Signed-off-by: Peter Krempa <pkrempa@redhat.com>
|
|
Reviewed-by: Ján Tomko <jtomko@redhat.com>
|
|
(cherry picked from commit 2ccac1e42f34404e3a5af22671a31fa1dca94e94)
|
|
|
|
https://issues.redhat.com/browse/RHEL-22314 [9.4.0]
|
|
https://issues.redhat.com/browse/RHEL-22400 [9.3.z]
|
|
https://issues.redhat.com/browse/RHEL-22399 [9.2.z]
|
|
---
|
|
src/conf/node_device_conf.c | 32 +++++++++++++-------------------
|
|
1 file changed, 13 insertions(+), 19 deletions(-)
|
|
|
|
diff --git a/src/conf/node_device_conf.c b/src/conf/node_device_conf.c
|
|
index 87c046e571..95de77abe9 100644
|
|
--- a/src/conf/node_device_conf.c
|
|
+++ b/src/conf/node_device_conf.c
|
|
@@ -270,14 +270,6 @@ virNodeDeviceCapVPDFormatCustomSystemField(virPCIVPDResourceCustom *field, virBu
|
|
virNodeDeviceCapVPDFormatCustomField(buf, "system_field", field);
|
|
}
|
|
|
|
-static inline void
|
|
-virNodeDeviceCapVPDFormatRegularField(virBuffer *buf, const char *keyword, const char *value)
|
|
-{
|
|
- if (keyword == NULL || value == NULL)
|
|
- return;
|
|
-
|
|
- virBufferAsprintf(buf, "<%s>%s</%s>\n", keyword, value, keyword);
|
|
-}
|
|
|
|
static void
|
|
virNodeDeviceCapVPDFormat(virBuffer *buf, virPCIVPDResource *res)
|
|
@@ -290,31 +282,33 @@ virNodeDeviceCapVPDFormat(virBuffer *buf, virPCIVPDResource *res)
|
|
virBufferEscapeString(buf, "<name>%s</name>\n", res->name);
|
|
|
|
if (res->ro != NULL) {
|
|
- virBufferEscapeString(buf, "<fields access='%s'>\n", "readonly");
|
|
-
|
|
+ virBufferAddLit(buf, "<fields access='readonly'>\n");
|
|
virBufferAdjustIndent(buf, 2);
|
|
- virNodeDeviceCapVPDFormatRegularField(buf, "change_level", res->ro->change_level);
|
|
- virNodeDeviceCapVPDFormatRegularField(buf, "manufacture_id", res->ro->manufacture_id);
|
|
- virNodeDeviceCapVPDFormatRegularField(buf, "part_number", res->ro->part_number);
|
|
- virNodeDeviceCapVPDFormatRegularField(buf, "serial_number", res->ro->serial_number);
|
|
+
|
|
+ virBufferEscapeString(buf, "<change_level>%s</change_level>\n", res->ro->change_level);
|
|
+ virBufferEscapeString(buf, "<manufacture_id>%s</manufacture_id>\n", res->ro->manufacture_id);
|
|
+ virBufferEscapeString(buf, "<part_number>%s</part_number>\n", res->ro->part_number);
|
|
+ virBufferEscapeString(buf, "<serial_number>%s</serial_number>\n", res->ro->serial_number);
|
|
+
|
|
g_ptr_array_foreach(res->ro->vendor_specific,
|
|
(GFunc)virNodeDeviceCapVPDFormatCustomVendorField, buf);
|
|
- virBufferAdjustIndent(buf, -2);
|
|
|
|
+ virBufferAdjustIndent(buf, -2);
|
|
virBufferAddLit(buf, "</fields>\n");
|
|
}
|
|
|
|
if (res->rw != NULL) {
|
|
- virBufferEscapeString(buf, "<fields access='%s'>\n", "readwrite");
|
|
-
|
|
+ virBufferAddLit(buf, "<fields access='readwrite'>\n");
|
|
virBufferAdjustIndent(buf, 2);
|
|
- virNodeDeviceCapVPDFormatRegularField(buf, "asset_tag", res->rw->asset_tag);
|
|
+
|
|
+ virBufferEscapeString(buf, "<asset_tag>%s</asset_tag>\n", res->rw->asset_tag);
|
|
+
|
|
g_ptr_array_foreach(res->rw->vendor_specific,
|
|
(GFunc)virNodeDeviceCapVPDFormatCustomVendorField, buf);
|
|
g_ptr_array_foreach(res->rw->system_specific,
|
|
(GFunc)virNodeDeviceCapVPDFormatCustomSystemField, buf);
|
|
- virBufferAdjustIndent(buf, -2);
|
|
|
|
+ virBufferAdjustIndent(buf, -2);
|
|
virBufferAddLit(buf, "</fields>\n");
|
|
}
|
|
|
|
--
|
|
2.43.0
|