Skip to content
Snippets Groups Projects
  • Daniel P. Berrangé's avatar
    4c956bd8
    ui: avoid sign extension using client width/height · 4c956bd8
    Daniel P. Berrangé authored
    
    Pixman returns a signed int for the image width/height, but the VNC
    protocol only permits a unsigned int16. Effective framebuffer size
    is determined by the guest, limited by the video RAM size, so the
    dimensions are unlikely to exceed the range of an unsigned int16,
    but this is not currently validated.
    
    With the current use of 'int' for client width/height, the calculation
    of offsets in vnc_update_throttle_offset() suffers from integer size
    promotion and sign extension, causing coverity warnings
    
    *** CID 1385147:  Integer handling issues  (SIGN_EXTENSION)
    /ui/vnc.c: 979 in vnc_update_throttle_offset()
    973      * than that the client would already suffering awful audio
    974      * glitches, so dropping samples is no worse really).
    975      */
    976     static void vnc_update_throttle_offset(VncState *vs)
    977     {
    978         size_t offset =
    >>>     CID 1385147:  Integer handling issues  (SIGN_EXTENSION)
    >>>     Suspicious implicit sign extension:
        "vs->client_pf.bytes_per_pixel" with type "unsigned char" (8 bits,
        unsigned) is promoted in "vs->client_width * vs->client_height *
        vs->client_pf.bytes_per_pixel" to type "int" (32 bits, signed), then
        sign-extended to type "unsigned long" (64 bits, unsigned).  If
        "vs->client_width * vs->client_height * vs->client_pf.bytes_per_pixel"
        is greater than 0x7FFFFFFF, the upper bits of the result will all be 1.
    979             vs->client_width * vs->client_height * vs->client_pf.bytes_per_pixel;
    
    Change client_width / client_height to be a size_t to avoid sign
    extension and integer promotion. Then validate that dimensions are in
    range wrt the RFB protocol u16 limits.
    
    Signed-off-by: default avatarDaniel P. Berrange <berrange@redhat.com>
    Message-id: 20180118155254.17053-1-berrange@redhat.com
    Signed-off-by: default avatarGerd Hoffmann <kraxel@redhat.com>
    4c956bd8
    History
    ui: avoid sign extension using client width/height
    Daniel P. Berrangé authored
    
    Pixman returns a signed int for the image width/height, but the VNC
    protocol only permits a unsigned int16. Effective framebuffer size
    is determined by the guest, limited by the video RAM size, so the
    dimensions are unlikely to exceed the range of an unsigned int16,
    but this is not currently validated.
    
    With the current use of 'int' for client width/height, the calculation
    of offsets in vnc_update_throttle_offset() suffers from integer size
    promotion and sign extension, causing coverity warnings
    
    *** CID 1385147:  Integer handling issues  (SIGN_EXTENSION)
    /ui/vnc.c: 979 in vnc_update_throttle_offset()
    973      * than that the client would already suffering awful audio
    974      * glitches, so dropping samples is no worse really).
    975      */
    976     static void vnc_update_throttle_offset(VncState *vs)
    977     {
    978         size_t offset =
    >>>     CID 1385147:  Integer handling issues  (SIGN_EXTENSION)
    >>>     Suspicious implicit sign extension:
        "vs->client_pf.bytes_per_pixel" with type "unsigned char" (8 bits,
        unsigned) is promoted in "vs->client_width * vs->client_height *
        vs->client_pf.bytes_per_pixel" to type "int" (32 bits, signed), then
        sign-extended to type "unsigned long" (64 bits, unsigned).  If
        "vs->client_width * vs->client_height * vs->client_pf.bytes_per_pixel"
        is greater than 0x7FFFFFFF, the upper bits of the result will all be 1.
    979             vs->client_width * vs->client_height * vs->client_pf.bytes_per_pixel;
    
    Change client_width / client_height to be a size_t to avoid sign
    extension and integer promotion. Then validate that dimensions are in
    range wrt the RFB protocol u16 limits.
    
    Signed-off-by: default avatarDaniel P. Berrange <berrange@redhat.com>
    Message-id: 20180118155254.17053-1-berrange@redhat.com
    Signed-off-by: default avatarGerd Hoffmann <kraxel@redhat.com>