git/list[1] front-page[2] threads[3] people[4] search[5] about
 

[PATCH v2 2/4] help.c::exclude_cmds: realloc() before copy, plug a leak

From
Tay Ray Chuan <rctay89@gmail.com>
Date
Jul 25, 2012, 16:16 UTC
Message-ID
<1343232982-10540-3-git-send-email-rctay89@gmail.com>
In-Reply-To
<1343232982-10540-2-git-send-email-rctay89@gmail.com>

Copying with structural assignment may not take into account that the LHS struct has sufficient memory, especially since the cmdname->name member is nonfixed in size. Be unambiguous about it by realloc()'ing it to be of sufficient size.

Additionally, free the unused cmdnames, which are no longer accessible anyway.

Signed-off-by: Tay Ray Chuan <rctay89@gmail.com>
---
 help.c | 20 ++++++++++++++++++--
 1 file changed, 18 insertions(+), 2 deletions(-)
diff --git a/help.c b/help.c
index 6991492..dfb2e9d 100644
--- a/help.c
+++ b/help.c
@@ -20,6 +20,17 @@ void add_cmdname(struct cmdnames *cmds, const char *name, int len)
 	cmds->names[cmds->cnt++] = ent;
 }
 
+static void copy_cmdname(struct cmdname **dest, struct cmdname *src)
+{
+	struct cmdname *ent = xrealloc(*dest, sizeof(*ent) + src->len + 1);
+
+	ent->len = src->len;
+	memcpy(ent->name, src->name, src->len);
+	ent->name[src->len] = 0;
+
+	*dest = ent;
+}
+
 static void clean_cmdnames(struct cmdnames *cmds)
 {
 	int i;
@@ -58,20 +69,25 @@ void exclude_cmds(struct cmdnames *cmds, struct cmdnames *excludes)
 {
 	int ci, cj, ei;
 	int cmp;
+	int last_cj;
 
 	ci = cj = ei = 0;
 	while (ci < cmds->cnt && ei < excludes->cnt) {
 		cmp = strcmp(cmds->names[ci]->name, excludes->names[ei]->name);
 		if (cmp < 0)
-			cmds->names[cj++] = cmds->names[ci++];
+			copy_cmdname(&cmds->names[cj++], cmds->names[ci++]);
 		else if (cmp == 0)
 			ci++, ei++;
 		else if (cmp > 0)
 			ei++;
 	}
+	last_cj = cj;
 
 	while (ci < cmds->cnt)
-		cmds->names[cj++] = cmds->names[ci++];
+		copy_cmdname(&cmds->names[cj++], cmds->names[ci++]);
+
+	while (last_cj < cmds->cnt)
+		free(cmds->names[last_cj++]);
 
 	cmds->cnt = cj;
 }
-- 
1.7.11.1.116.g8228a23
Previous: Tay Ray ChuanNext: Tay Ray Chuan
Message 18 of 37 in “allow recovery from command name typos”
  1. 0/4 allow recovery from command name typosTay Ray Chuan, May 6, 2012
  2. 1/4 help.c::uniq: plug a leakTay Ray Chuan, May 6, 2012
  3. 2/4 help.c::exclude_cmds: plug a leakTay Ray Chuan, May 6, 2012
  4. 3/4 help.c: plug a leak when help.autocorrect is setTay Ray Chuan, May 6, 2012
  5. 4/4 allow recovery from command name typosTay Ray Chuan, May 6, 2012
  6. Jeff KingMay 6, 2012
  7. Tay Ray ChuanMay 6, 2012
  8. Thomas RastMay 7, 2012
  9. Tay Ray ChuanMay 7, 2012
  10. Junio C HamanoMay 7, 2012
  11. Tay Ray ChuanMay 9, 2012
  12. Junio C HamanoMay 9, 2012
  13. Jeff KingMay 6, 2012
  14. Tay Ray ChuanMay 6, 2012
  15. Jeff KingMay 7, 2012
  16. 0/4 allow recovery from command name typosTay Ray Chuan, Jul 25, 2012
  17. 1/4 help.c::uniq: plug a leakTay Ray Chuan, Jul 25, 2012
  18. 2/4 help.c::exclude_cmds: realloc() before copy, plug a leakTay Ray Chuan, Jul 25, 2012
  19. 3/4 help.c: plug leaks with(out) help.autocorrectTay Ray Chuan, Jul 25, 2012
  20. 4/4 allow recovery from command name typosTay Ray Chuan, Jul 25, 2012
  21. Junio C HamanoJul 25, 2012
  22. Tay Ray ChuanJul 26, 2012
  23. Jeff KingJul 26, 2012
  24. Junio C HamanoJul 26, 2012
  25. Jeff KingJul 26, 2012
  26. Junio C HamanoJul 26, 2012
  27. Junio C HamanoJul 25, 2012
  28. Junio C HamanoJul 25, 2012
  29. 0/2 allow recovery from command name typosTay Ray Chuan, Aug 5, 2012
  30. 1/2 add interface for /dev/tty interactionTay Ray Chuan, Aug 5, 2012
  31. 2/2 allow recovery from command name typosTay Ray Chuan, Aug 5, 2012
  32. Junio C HamanoAug 6, 2012
  33. Junio C HamanoAug 5, 2012
  34. Jeff KingAug 6, 2012
  35. Jeff KingAug 6, 2012
  36. Junio C HamanoAug 6, 2012
  37. Tay Ray ChuanMay 6, 2012

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.