neil / rpms / udisks2

Forked from rpms/udisks2 a year ago
Clone
7b1f2e
From d205057296957d6064825252a3d3377e809d6fed Mon Sep 17 00:00:00 2001
7b1f2e
From: Tomas Bzatek <tbzatek@redhat.com>
7b1f2e
Date: Wed, 6 Oct 2021 17:12:13 +0200
7b1f2e
Subject: [PATCH] udiskslinuxmountoptions: Do not free static daemon resources
7b1f2e
7b1f2e
The GResource instance returned from udisks_daemon_resources_get_resource()
7b1f2e
that calls g_static_resource_get_resource() internally is marked as
7b1f2e
'(transfer none)' and should not be freed. In fact that causes double
7b1f2e
free inside the g_static_resource_fini() atexit handler leading
7b1f2e
to memory corruption causing random failures of further atexit
7b1f2e
handlers such as cryptsetup and openssl destructors.
7b1f2e
7b1f2e
 Invalid read of size 4
7b1f2e
    at 0x4BB03A4: g_resource_unref (gresource.c:527)
7b1f2e
    by 0x4BB2150: g_static_resource_fini (gresource.c:1449)
7b1f2e
    by 0x4010ADB: _dl_fini (dl-fini.c:139)
7b1f2e
    by 0x4EF0DF4: __run_exit_handlers (exit.c:113)
7b1f2e
    by 0x4EF0F6F: exit (exit.c:143)
7b1f2e
    by 0x4ED9566: __libc_start_call_main (libc_start_call_main.h:74)
7b1f2e
    by 0x4ED960B: __libc_start_main@@GLIBC_2.34 (libc-start.c:409)
7b1f2e
    by 0x128774: (below main) (in udisks/src/.libs/udisksd)
7b1f2e
  Address 0x5cc5fc0 is 0 bytes inside a block of size 16 free'd
7b1f2e
    at 0x48430E4: free (vg_replace_malloc.c:755)
7b1f2e
    by 0x4DB10BC: g_free (gmem.c:199)
7b1f2e
    by 0x4BB2148: g_static_resource_fini (gresource.c:1448)
7b1f2e
    by 0x4010ADB: _dl_fini (dl-fini.c:139)
7b1f2e
    by 0x4EF0DF4: __run_exit_handlers (exit.c:113)
7b1f2e
    by 0x4EF0F6F: exit (exit.c:143)
7b1f2e
    by 0x4ED9566: __libc_start_call_main (libc_start_call_main.h:74)
7b1f2e
    by 0x4ED960B: __libc_start_main@@GLIBC_2.34 (libc-start.c:409)
7b1f2e
    by 0x128774: (below main) (in udisks/src/.libs/udisksd)
7b1f2e
  Block was alloc'd at
7b1f2e
    at 0x484086F: malloc (vg_replace_malloc.c:380)
7b1f2e
    by 0x4DB47A8: g_malloc (gmem.c:106)
7b1f2e
    by 0x4BB19C7: UnknownInlinedFun (gresource.c:545)
7b1f2e
    by 0x4BB19C7: g_resource_new_from_data (gresource.c:613)
7b1f2e
    by 0x4BB1A88: register_lazy_static_resources_unlocked (gresource.c:1374)
7b1f2e
    by 0x4BB218C: UnknownInlinedFun (gresource.c:1393)
7b1f2e
    by 0x4BB218C: UnknownInlinedFun (gresource.c:1387)
7b1f2e
    by 0x4BB218C: g_static_resource_get_resource (gresource.c:1472)
7b1f2e
    by 0x14F6A3: UnknownInlinedFun (udisks-daemon-resources.c:284)
7b1f2e
    by 0x14F6A3: udisks_linux_mount_options_get_builtin (udiskslinuxmountoptions.c:612)
7b1f2e
    by 0x12CC6E: udisks_daemon_constructed (udisksdaemon.c:441)
7b1f2e
    by 0x4D1ED96: g_object_new_internal (gobject.c:1985)
7b1f2e
    by 0x4D20227: g_object_new_valist (gobject.c:2288)
7b1f2e
    by 0x4D2075C: g_object_new (gobject.c:1788)
7b1f2e
    by 0x129A5F: udisks_daemon_new (udisksdaemon.c:619)
7b1f2e
    by 0x129AD5: on_bus_acquired (main.c:63)
7b1f2e
    by 0x4C35C95: connection_get_cb.lto_priv.0 (gdbusnameowning.c:504)
7b1f2e
    by 0x4BD3F99: g_task_return_now (gtask.c:1219)
7b1f2e
    by 0x4BD419A: UnknownInlinedFun (gtask.c:1289)
7b1f2e
    by 0x4BD419A: g_task_return (gtask.c:1245)
7b1f2e
    by 0x4C31D51: bus_get_async_initable_cb (gdbusconnection.c:7433)
7b1f2e
    by 0x4BD3F99: g_task_return_now (gtask.c:1219)
7b1f2e
    by 0x4BD3FDC: complete_in_idle_cb (gtask.c:1233)
7b1f2e
    by 0x4DA852A: g_idle_dispatch (gmain.c:5897)
7b1f2e
    by 0x4DAC33E: UnknownInlinedFun (gmain.c:3381)
7b1f2e
    by 0x4DAC33E: g_main_context_dispatch (gmain.c:4099)
7b1f2e
---
7b1f2e
 src/udiskslinuxmountoptions.c | 1 -
7b1f2e
 1 file changed, 1 deletion(-)
7b1f2e
7b1f2e
diff --git a/src/udiskslinuxmountoptions.c b/src/udiskslinuxmountoptions.c
7b1f2e
index 7729d4015..819c9ba96 100644
7b1f2e
--- a/src/udiskslinuxmountoptions.c
7b1f2e
+++ b/src/udiskslinuxmountoptions.c
7b1f2e
@@ -614,7 +614,6 @@ udisks_linux_mount_options_get_builtin (void)
7b1f2e
                                                "/org/freedesktop/UDisks2/data/builtin_mount_options.conf",
7b1f2e
                                                G_RESOURCE_LOOKUP_FLAGS_NONE,
7b1f2e
                                                &error);
7b1f2e
-  g_resource_unref (daemon_resource);
7b1f2e
 
7b1f2e
   if (builtin_opts_bytes == NULL)
7b1f2e
     {