Cluster-Devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Andrew Price <andy@andrewprice.me.uk>
To: cluster-devel.redhat.com
Subject: [Cluster-devel] [PATCH] hexedit: avoid NULL dereference upon failed	malloc
Date: Fri, 19 Jun 2009 07:11:16 +0100	[thread overview]
Message-ID: <4A3B2C04.7010301@andrewprice.me.uk> (raw)
In-Reply-To: <87ws7ac0ky.fsf@meyering.net>

Hi,

This patch gives a build error:

hexedit.c:1500: error: incompatible type for argument 1 of ?memset?

On 17/06/09 17:00, Jim Meyering wrote:
> If the malloc of more_indir fails, the subsequent deref
> via memset would cause a segfault.
> 
> I chose to avoid that by making more_indir a stack-local.
> If it's 512-byte size is too big for your stack
> requirements, let me know and I'll rewrite to
> use malloc -- though doing it that way (and taking
> care to avoid leaks), would probably end up uglier.
> 
>>From fda0f39b0389088b0ea66216aed21d4f5f1bb604 Mon Sep 17 00:00:00 2001
> From: Jim Meyering <meyering@redhat.com>
> Date: Wed, 17 Jun 2009 16:54:03 +0200
> Subject: [PATCH] hexedit: avoid NULL dereference upon failed malloc
> 
> * gfs2/edit/hexedit.c (display_indirect): Avoid unchecked malloc
> by declaring more_indir on the stack.
> ---
>  gfs2/edit/hexedit.c |   12 +++++-------
>  1 files changed, 5 insertions(+), 7 deletions(-)
> 
> diff --git a/gfs2/edit/hexedit.c b/gfs2/edit/hexedit.c
> index e8c6030..84b4be4 100644
> --- a/gfs2/edit/hexedit.c
> +++ b/gfs2/edit/hexedit.c
> @@ -1477,13 +1477,12 @@ static int display_indirect(struct iinfo *ind, int indblocks, int level, uint64_
>  			file_offset = 0;
>  		if (!termlines && ((level + 1 < di.di_height) ||
>  				   (S_ISDIR(di.di_mode) && !level))) {
> -			struct iinfo *more_indir;
>  			int more_ind;
>  			char *tmpbuf;
>  			
> -			more_indir = malloc(sizeof(struct iinfo));
>  			tmpbuf = malloc(sbd.bsize);
>  			if (tmpbuf) {
> +				struct iinfo more_indir;
>  				lseek(sbd.device_fd,
>  				      ind->ii[pndx].block * sbd.bsize,
>  				      SEEK_SET);
> @@ -1500,18 +1499,17 @@ static int display_indirect(struct iinfo *ind, int indblocks, int level, uint64_
>  				}
>  				memset(more_indir, 0, sizeof(struct iinfo));
>  				if (S_ISDIR(di.di_mode)) {
> -					do_leaf_extended(tmpbuf, more_indir);
> -					display_leaf(more_indir);
> +					do_leaf_extended(tmpbuf, &more_indir);
> +					display_leaf(&more_indir);
>  				} else {
>  					more_ind = do_indirect_extended(tmpbuf,
> -									more_indir);
> -					display_indirect(more_indir,
> +									&more_indir);
> +					display_indirect(&more_indir,
>  							 more_ind, level + 1,
>  							 file_offset);
>  				}
>  				free(tmpbuf);
>  			}
> -			free(more_indir);
>  		}
>  		print_entry_ndx = pndx; /* restore after recursion */
>  		eol(0);



  reply	other threads:[~2009-06-19  6:11 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-06-17 16:00 [Cluster-devel] [PATCH] hexedit: avoid NULL dereference upon failed malloc Jim Meyering
2009-06-19  6:11 ` Andrew Price [this message]
  -- strict thread matches above, loose matches on Subject: below --
2009-06-19  7:40 Jim Meyering
2009-07-02  9:37 ` Steven Whitehouse
2009-07-02 11:05   ` Jim Meyering

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4A3B2C04.7010301@andrewprice.me.uk \
    --to=andy@andrewprice.me.uk \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox