All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 1/1] multipath: fix memory leak and segfault in reconfigure
@ 2016-02-11 19:30 Germano Percossi
  2016-02-23 15:17 ` Germano Percossi
  2016-04-18 10:42 ` Germano Percossi
  0 siblings, 2 replies; 4+ messages in thread
From: Germano Percossi @ 2016-02-11 19:30 UTC (permalink / raw)
  To: christophe.varoqui; +Cc: dm-devel

Within the reconfigure function, the global pointer conf is
stored in a local variable and then assigned NULL.
If load_config should fail, for any reason, we end up with
a memory leak, as soon as we leave the function, and with
the global pointer conf set to NULL, leading to a segfault
as soon as it is dereferenced.

I tested it by calling a reconfigure and making the first
allocation in load_config fail but any failure in load_config
would do.
From a user perspective the CLI reports "fail".

If something like this should happen there are at least 2 possible
scenarios:

1) If a second immediate reconfigure succeeds, the conf now is fine but
   the leak stays
2) If the previous point does not happen, any command trying to access
   "conf" would fail. On my test box a "show conf" segfaulted.

The fix is simple but in case of failure at least the previous
conf is kept in memory without leaks or segfaluts

Signed-off-by: Germano Percossi <germano.percossi@citrix.com>
---
 multipathd/main.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/multipathd/main.c b/multipathd/main.c
index 04f6d02..f83c849 100644
--- a/multipathd/main.c
+++ b/multipathd/main.c
@@ -1551,6 +1551,8 @@ reconfigure (struct vectors * vecs)
 		configure(vecs, 1);
 		free_config(old);
 		retval = 0;
+	} else {
+		conf = old;
 	}
 
 	running_state = DAEMON_RUNNING;
-- 
1.9.1

^ permalink raw reply related	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2016-04-18 11:12 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-02-11 19:30 [PATCH 1/1] multipath: fix memory leak and segfault in reconfigure Germano Percossi
2016-02-23 15:17 ` Germano Percossi
2016-04-18 10:42 ` Germano Percossi
2016-04-18 11:12   ` Christophe Varoqui

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.