OSDN Git Service

semihosting: Fix handling of buffer in TARGET_SYS_TMPNAM
authorPeter Maydell <peter.maydell@linaro.org>
Mon, 25 Jul 2022 14:05:16 +0000 (15:05 +0100)
committerAlex Bennée <alex.bennee@linaro.org>
Fri, 29 Jul 2022 08:48:01 +0000 (09:48 +0100)
commit9b1268f55ceb0d9390a051cad299b3021dfa9896
treeb98e804a30e5ab6677c062284b1af70634de01ad
parentfed49cdf6a721d76f9ac1cf76fd05b3fbd8b4892
semihosting: Fix handling of buffer in TARGET_SYS_TMPNAM

The TARGET_SYS_TMPNAM implementation has two bugs spotted by
Coverity:
 * confusion about whether 'len' has the length of the string
   including or excluding the terminating NUL means we
   lock_user() len bytes of memory but memcpy() len + 1 bytes
 * In the error-exit cases we forget to free() the buffer
   that asprintf() returned to us

Resolves: Coverity CID 14902851490289
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
Reviewed-by: Richard Henderson <richard.henderson@linaro.org>
Message-Id: <20220719121110.225657-5-peter.maydell@linaro.org>
Signed-off-by: Alex Bennée <alex.bennee@linaro.org>
Message-Id: <20220725140520.515340-10-alex.bennee@linaro.org>
semihosting/arm-compat-semi.c