From cbb09e41abf3469265ed1ffa1bd0afafd4213c34 Mon Sep 17 00:00:00 2001 From: TapTap Date: Tue, 8 Sep 2026 18:49:23 +0200 Subject: [PATCH] identity: fix use-after-free in --usermap/--groupmap parse error path identity_parse_map freed the str_dup'd list before logging the offending rule ( points into that buffer), causing an invalid read caught by CI valgrind (MSAN/MSAN-style; the ONLY definite valgrind error in the suite). Log before freeing. valgrind now reports 0 errors / 0 definite leaks in both the parent and the forked wire-roundtrip child. --- src/shared/identity.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/shared/identity.c b/src/shared/identity.c index c0237d5..c9e01b9 100644 --- a/src/shared/identity.c +++ b/src/shared/identity.c @@ -191,8 +191,9 @@ int identity_parse_map(Config* config, const char* value, bool is_group) { for (char* rule = strtok_r(list, ",", &saveptr); rule; rule = strtok_r(NULL, ",", &saveptr)) { char* colon = strchr(rule, ':'); if (!colon || colon == rule) { - free(list); + /* Log before freeing: `rule` points into the str_dup'd list. */ log_message(LOG_LEVEL_ERROR, "%s rules must be FROM:TO (got '%s')", optname, rule); + free(list); return -1; } *colon = '\0';