blob: eb940dfcf97d68e687f406c5bee900c0e08a87c2 (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
|
TCG: 0.966
graphic: 0.872
performance: 0.736
files: 0.714
network: 0.650
device: 0.641
vnc: 0.538
ppc: 0.509
semantic: 0.485
socket: 0.480
kernel: 0.469
risc-v: 0.456
PID: 0.389
boot: 0.361
peripherals: 0.338
i386: 0.330
architecture: 0.288
VMM: 0.288
arm: 0.262
x86: 0.235
KVM: 0.225
register: 0.224
debug: 0.203
permissions: 0.145
mistranslation: 0.118
hypervisor: 0.100
virtual: 0.076
user-level: 0.060
assembly: 0.043
--------------------
TCG: 0.953
kernel: 0.593
files: 0.404
debug: 0.182
x86: 0.147
hypervisor: 0.080
VMM: 0.050
KVM: 0.047
virtual: 0.024
register: 0.019
i386: 0.017
arm: 0.015
risc-v: 0.013
PID: 0.011
ppc: 0.007
network: 0.007
device: 0.005
performance: 0.004
assembly: 0.004
semantic: 0.003
user-level: 0.002
socket: 0.002
vnc: 0.002
peripherals: 0.002
boot: 0.001
architecture: 0.001
graphic: 0.001
permissions: 0.001
mistranslation: 0.000
Unreachable code
Description of problem:
There is always a false condition in the function `alloc_code_gen_buffer_splitwx_memfd` in the file `tcg/region.c`. If `buf_rw == NULL` we go to the mark __fail__:
https://gitlab.com/qemu-project/qemu/-/blob/master/tcg/region.c?ref_type=heads#L580-L583
But the value of `buf_rx` is __`MAP_FAILED`__:
https://gitlab.com/qemu-project/qemu/-/blob/master/tcg/region.c?ref_type=heads#L577
And this line will never be reached:
https://gitlab.com/qemu-project/qemu/-/blob/master/tcg/region.c?ref_type=heads#L601
Found by Linux Verification Center (portal.linuxtesting.ru) with SVACE.
Author A. Voronin.
|