identity: fix use-after-free in --usermap/--groupmap parse error path
CI / lint (push) Successful in 48s
CI / sanitizers (undefined) (push) Successful in 53s
CI / sanitizers (address) (push) Successful in 53s
CI / fuzz-build (push) Successful in 18s
CI / coverage (push) Successful in 42s
CI / valgrind (push) Successful in 37s
CI / build-and-test (push) Successful in 4m37s
CI / lint (push) Successful in 48s
CI / sanitizers (undefined) (push) Successful in 53s
CI / sanitizers (address) (push) Successful in 53s
CI / fuzz-build (push) Successful in 18s
CI / coverage (push) Successful in 42s
CI / valgrind (push) Successful in 37s
CI / build-and-test (push) Successful in 4m37s
identity_parse_map freed the str_dup'd list before logging the offending rule ( points into that buffer), causing an invalid read caught by CI valgrind (MSAN/MSAN-style; the ONLY definite valgrind error in the suite). Log before freeing. valgrind now reports 0 errors / 0 definite leaks in both the parent and the forked wire-roundtrip child.
This commit is contained in:
@@ -191,8 +191,9 @@ int identity_parse_map(Config* config, const char* value, bool is_group) {
|
|||||||
for (char* rule = strtok_r(list, ",", &saveptr); rule; rule = strtok_r(NULL, ",", &saveptr)) {
|
for (char* rule = strtok_r(list, ",", &saveptr); rule; rule = strtok_r(NULL, ",", &saveptr)) {
|
||||||
char* colon = strchr(rule, ':');
|
char* colon = strchr(rule, ':');
|
||||||
if (!colon || colon == rule) {
|
if (!colon || colon == rule) {
|
||||||
free(list);
|
/* Log before freeing: `rule` points into the str_dup'd list. */
|
||||||
log_message(LOG_LEVEL_ERROR, "%s rules must be FROM:TO (got '%s')", optname, rule);
|
log_message(LOG_LEVEL_ERROR, "%s rules must be FROM:TO (got '%s')", optname, rule);
|
||||||
|
free(list);
|
||||||
return -1;
|
return -1;
|
||||||
}
|
}
|
||||||
*colon = '\0';
|
*colon = '\0';
|
||||||
|
|||||||
Reference in New Issue
Block a user