From 5b9237f67c499fa4e20bb9bd29c7ce54afe79cb7 Mon Sep 17 00:00:00 2001 From: Andreas Färber Date: Fri, 30 Aug 2013 18:28:37 +0200 Subject: qom: Assert instance size in object_initialize_with_type() This catches objects initializing beyond allocated memory, e.g., when subtypes get extended with instance state of their own. Suggested-by: Peter Maydell Signed-off-by: Andreas Färber --- qom/object.c | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) (limited to 'qom') diff --git a/qom/object.c b/qom/object.c index 1635422c38..e90e3827d9 100644 --- a/qom/object.c +++ b/qom/object.c @@ -311,7 +311,7 @@ static void object_post_init_with_type(Object *obj, TypeImpl *ti) } } -void object_initialize_with_type(void *data, TypeImpl *type) +void object_initialize_with_type(void *data, size_t size, TypeImpl *type) { Object *obj = data; @@ -320,6 +320,7 @@ void object_initialize_with_type(void *data, TypeImpl *type) g_assert(type->instance_size >= sizeof(Object)); g_assert(type->abstract == false); + g_assert(size >= type->instance_size); memset(obj, 0, type->instance_size); obj->class = type->class; @@ -333,7 +334,7 @@ void object_initialize(void *data, size_t size, const char *typename) { TypeImpl *type = type_get_by_name(typename); - object_initialize_with_type(data, type); + object_initialize_with_type(data, size, type); } static inline bool object_property_is_child(ObjectProperty *prop) @@ -424,7 +425,7 @@ Object *object_new_with_type(Type type) type_initialize(type); obj = g_malloc(type->instance_size); - object_initialize_with_type(obj, type); + object_initialize_with_type(obj, type->instance_size, type); obj->free = g_free; return obj; -- cgit v1.2.3-55-g7522