|
|
dc245c |
iscsi_reconnect: Fix a use-after-free
|
|
|
dc245c |
|
|
|
dc245c |
Message-id: <1383729402-27559-2-git-send-email-pbonzini@redhat.com>
|
|
|
dc245c |
Patchwork-id: 55496
|
|
|
dc245c |
O-Subject: [PATCH 01/11] iscsi_reconnect: Fix a use-after-free
|
|
|
dc245c |
Bugzilla: 1026820
|
|
|
dc245c |
RH-Acked-by: Miroslav Rezanina <mrezanin@redhat.com>
|
|
|
dc245c |
RH-Acked-by: Orit Wasserman <owasserm@redhat.com>
|
|
|
dc245c |
RH-Acked-by: Stefan Hajnoczi <stefanha@redhat.com>
|
|
|
dc245c |
|
|
|
dc245c |
From: Bart Van Assche <bvanassche@acm.org>
|
|
|
dc245c |
|
|
|
dc245c |
This patch fixes the following Valgrind complaint:
|
|
|
dc245c |
|
|
|
dc245c |
Invalid read of size 4
|
|
|
dc245c |
at 0x524A858: iscsi_reconnect (connect.c:378)
|
|
|
dc245c |
by 0x5258794: iscsi_service (socket.c:707)
|
|
|
dc245c |
by 0x52599C4: event_loop (sync.c:67)
|
|
|
dc245c |
by 0x525AFD7: iscsi_reserve6_sync (sync.c:1096)
|
|
|
dc245c |
by 0x40A40A: reserve6 (iscsi-support.c:3291)
|
|
|
dc245c |
by 0x422C95: test_reserve6_target_warm_reset (test_reserve6_target_warm_reset.c:39)
|
|
|
dc245c |
by 0x503B05F: ??? (in /usr/lib/libcunit.so.1.0.1)
|
|
|
dc245c |
by 0x503B375: ??? (in /usr/lib/libcunit.so.1.0.1)
|
|
|
dc245c |
by 0x503B69F: CU_run_all_tests (in /usr/lib/libcunit.so.1.0.1)
|
|
|
dc245c |
by 0x403171: main (iscsi-test-cu.c:1258)
|
|
|
dc245c |
Address 0x6443958 is 3,032 bytes inside a block of size 4,120 free'd
|
|
|
dc245c |
at 0x4C2B83A: free (vg_replace_malloc.c:468)
|
|
|
dc245c |
by 0x524A846: iscsi_reconnect (connect.c:374)
|
|
|
dc245c |
by 0x5258794: iscsi_service (socket.c:707)
|
|
|
dc245c |
by 0x52599C4: event_loop (sync.c:67)
|
|
|
dc245c |
by 0x525AFD7: iscsi_reserve6_sync (sync.c:1096)
|
|
|
dc245c |
by 0x40A40A: reserve6 (iscsi-support.c:3291)
|
|
|
dc245c |
by 0x422C95: test_reserve6_target_warm_reset (test_reserve6_target_warm_reset.c:39)
|
|
|
dc245c |
by 0x503B05F: ??? (in /usr/lib/libcunit.so.1.0.1)
|
|
|
dc245c |
by 0x503B375: ??? (in /usr/lib/libcunit.so.1.0.1)
|
|
|
dc245c |
by 0x503B69F: CU_run_all_tests (in /usr/lib/libcunit.so.1.0.1)
|
|
|
dc245c |
by 0x403171: main (iscsi-test-cu.c:1258)
|
|
|
dc245c |
|
|
|
dc245c |
Signed-off-by: Bart Van Assche <bvanassche@acm.org>
|
|
|
dc245c |
(cherry picked from commit 4653cd8df4c14f4eea37b6ce66277330774dd3d5)
|
|
|
dc245c |
---
|
|
|
dc245c |
lib/connect.c | 4 ++--
|
|
|
dc245c |
1 file changed, 2 insertions(+), 2 deletions(-)
|
|
|
dc245c |
diff --git a/lib/connect.c b/lib/connect.c
|
|
|
dc245c |
index bcb9d3b..0d4c957 100644
|
|
|
dc245c |
--- a/lib/connect.c
|
|
|
dc245c |
+++ b/lib/connect.c
|
|
|
dc245c |
@@ -356,13 +356,13 @@ try_again:
|
|
|
dc245c |
iscsi->mallocs+=old_iscsi->mallocs;
|
|
|
dc245c |
iscsi->frees+=old_iscsi->frees;
|
|
|
dc245c |
|
|
|
dc245c |
+ ISCSI_LOG(iscsi, 2, "reconnect was successful");
|
|
|
dc245c |
+
|
|
|
dc245c |
memcpy(old_iscsi, iscsi, sizeof(struct iscsi_context));
|
|
|
dc245c |
- memset(iscsi, 0, sizeof(struct iscsi_context));
|
|
|
dc245c |
free(iscsi);
|
|
|
dc245c |
|
|
|
dc245c |
old_iscsi->is_reconnecting = 0;
|
|
|
dc245c |
old_iscsi->last_reconnect = time(NULL);
|
|
|
dc245c |
- ISCSI_LOG(iscsi, 2, "reconnect was successful");
|
|
|
dc245c |
|
|
|
dc245c |
return 0;
|
|
|
dc245c |
}
|