Pablo Greco 48fc63
From 8f77b455f768d1f95971cedd8d4903f249f683bf Mon Sep 17 00:00:00 2001
Pablo Greco 48fc63
From: Riccardo Schirone <rschiron@redhat.com>
Pablo Greco 48fc63
Date: Mon, 4 Feb 2019 14:29:28 +0100
Pablo Greco 48fc63
Subject: [PATCH] Allocate temporary strings to hold dbus paths on the heap
Pablo Greco 48fc63
Pablo Greco 48fc63
Paths are limited to BUS_PATH_SIZE_MAX but the maximum size is anyway too big
Pablo Greco 48fc63
to be allocated on the stack, so let's switch to the heap where there is a
Pablo Greco 48fc63
clear way to understand if the allocation fails.
Pablo Greco 48fc63
Pablo Greco 48fc63
Resolves: #1667871
Pablo Greco 48fc63
---
Pablo Greco 48fc63
 src/libsystemd/sd-bus/bus-objects.c | 58 +++++++++++++++++++++++------
Pablo Greco 48fc63
 1 file changed, 46 insertions(+), 12 deletions(-)
Pablo Greco 48fc63
Pablo Greco 48fc63
diff --git a/src/libsystemd/sd-bus/bus-objects.c b/src/libsystemd/sd-bus/bus-objects.c
Pablo Greco 48fc63
index fc6c223283..8df73bdf4c 100644
Pablo Greco 48fc63
--- a/src/libsystemd/sd-bus/bus-objects.c
Pablo Greco 48fc63
+++ b/src/libsystemd/sd-bus/bus-objects.c
Pablo Greco 48fc63
@@ -1104,7 +1104,8 @@ static int object_manager_serialize_path_and_fallbacks(
Pablo Greco 48fc63
                 const char *path,
Pablo Greco 48fc63
                 sd_bus_error *error) {
Pablo Greco 48fc63
 
Pablo Greco 48fc63
-        char *prefix;
Pablo Greco 48fc63
+        _cleanup_free_ char *prefix = NULL;
Pablo Greco 48fc63
+        size_t pl;
Pablo Greco 48fc63
         int r;
Pablo Greco 48fc63
 
Pablo Greco 48fc63
         assert(bus);
Pablo Greco 48fc63
@@ -1120,7 +1121,12 @@ static int object_manager_serialize_path_and_fallbacks(
Pablo Greco 48fc63
                 return 0;
Pablo Greco 48fc63
 
Pablo Greco 48fc63
         /* Second, add fallback vtables registered for any of the prefixes */
Pablo Greco 48fc63
-        prefix = alloca(strlen(path) + 1);
Pablo Greco 48fc63
+        pl = strlen(path);
Pablo Greco 48fc63
+        assert(pl <= BUS_PATH_SIZE_MAX);
Pablo Greco 48fc63
+        prefix = new(char, pl + 1);
Pablo Greco 48fc63
+        if (!prefix)
Pablo Greco 48fc63
+                return -ENOMEM;
Pablo Greco 48fc63
+
Pablo Greco 48fc63
         OBJECT_PATH_FOREACH_PREFIX(prefix, path) {
Pablo Greco 48fc63
                 r = object_manager_serialize_path(bus, reply, prefix, path, true, error);
Pablo Greco 48fc63
                 if (r < 0)
Pablo Greco 48fc63
@@ -1316,6 +1322,7 @@ static int object_find_and_run(
Pablo Greco 48fc63
 }
Pablo Greco 48fc63
 
Pablo Greco 48fc63
 int bus_process_object(sd_bus *bus, sd_bus_message *m) {
Pablo Greco 48fc63
+        _cleanup_free_ char *prefix = NULL;
Pablo Greco 48fc63
         int r;
Pablo Greco 48fc63
         size_t pl;
Pablo Greco 48fc63
         bool found_object = false;
Pablo Greco 48fc63
@@ -1340,9 +1347,12 @@ int bus_process_object(sd_bus *bus, sd_bus_message *m) {
Pablo Greco 48fc63
         assert(m->member);
Pablo Greco 48fc63
 
Pablo Greco 48fc63
         pl = strlen(m->path);
Pablo Greco 48fc63
-        do {
Pablo Greco 48fc63
-                char prefix[pl+1];
Pablo Greco 48fc63
+        assert(pl <= BUS_PATH_SIZE_MAX);
Pablo Greco 48fc63
+        prefix = new(char, pl + 1);
Pablo Greco 48fc63
+        if (!prefix)
Pablo Greco 48fc63
+                return -ENOMEM;
Pablo Greco 48fc63
 
Pablo Greco 48fc63
+        do {
Pablo Greco 48fc63
                 bus->nodes_modified = false;
Pablo Greco 48fc63
 
Pablo Greco 48fc63
                 r = object_find_and_run(bus, m, m->path, false, &found_object);
Pablo Greco 48fc63
@@ -2044,9 +2054,10 @@ _public_ int sd_bus_emit_properties_changed_strv(
Pablo Greco 48fc63
                 const char *interface,
Pablo Greco 48fc63
                 char **names) {
Pablo Greco 48fc63
 
Pablo Greco 48fc63
+        _cleanup_free_ char *prefix = NULL;
Pablo Greco 48fc63
         BUS_DONT_DESTROY(bus);
Pablo Greco 48fc63
         bool found_interface = false;
Pablo Greco 48fc63
-        char *prefix;
Pablo Greco 48fc63
+        size_t pl;
Pablo Greco 48fc63
         int r;
Pablo Greco 48fc63
 
Pablo Greco 48fc63
         assert_return(bus, -EINVAL);
Pablo Greco 48fc63
@@ -2064,6 +2075,12 @@ _public_ int sd_bus_emit_properties_changed_strv(
Pablo Greco 48fc63
         if (names && names[0] == NULL)
Pablo Greco 48fc63
                 return 0;
Pablo Greco 48fc63
 
Pablo Greco 48fc63
+        pl = strlen(path);
Pablo Greco 48fc63
+        assert(pl <= BUS_PATH_SIZE_MAX);
Pablo Greco 48fc63
+        prefix = new(char, pl + 1);
Pablo Greco 48fc63
+        if (!prefix)
Pablo Greco 48fc63
+                return -ENOMEM;
Pablo Greco 48fc63
+
Pablo Greco 48fc63
         do {
Pablo Greco 48fc63
                 bus->nodes_modified = false;
Pablo Greco 48fc63
 
Pablo Greco 48fc63
@@ -2073,7 +2090,6 @@ _public_ int sd_bus_emit_properties_changed_strv(
Pablo Greco 48fc63
                 if (bus->nodes_modified)
Pablo Greco 48fc63
                         continue;
Pablo Greco 48fc63
 
Pablo Greco 48fc63
-                prefix = alloca(strlen(path) + 1);
Pablo Greco 48fc63
                 OBJECT_PATH_FOREACH_PREFIX(prefix, path) {
Pablo Greco 48fc63
                         r = emit_properties_changed_on_interface(bus, prefix, path, interface, true, &found_interface, names);
Pablo Greco 48fc63
                         if (r != 0)
Pablo Greco 48fc63
@@ -2204,7 +2220,8 @@ static int object_added_append_all_prefix(
Pablo Greco 48fc63
 
Pablo Greco 48fc63
 static int object_added_append_all(sd_bus *bus, sd_bus_message *m, const char *path) {
Pablo Greco 48fc63
         _cleanup_set_free_ Set *s = NULL;
Pablo Greco 48fc63
-        char *prefix;
Pablo Greco 48fc63
+        _cleanup_free_ char *prefix = NULL;
Pablo Greco 48fc63
+        size_t pl;
Pablo Greco 48fc63
         int r;
Pablo Greco 48fc63
 
Pablo Greco 48fc63
         assert(bus);
Pablo Greco 48fc63
@@ -2249,7 +2266,12 @@ static int object_added_append_all(sd_bus *bus, sd_bus_message *m, const char *p
Pablo Greco 48fc63
         if (bus->nodes_modified)
Pablo Greco 48fc63
                 return 0;
Pablo Greco 48fc63
 
Pablo Greco 48fc63
-        prefix = alloca(strlen(path) + 1);
Pablo Greco 48fc63
+        pl = strlen(path);
Pablo Greco 48fc63
+        assert(pl <= BUS_PATH_SIZE_MAX);
Pablo Greco 48fc63
+        prefix = new(char, pl + 1);
Pablo Greco 48fc63
+        if (!prefix)
Pablo Greco 48fc63
+                return -ENOMEM;
Pablo Greco 48fc63
+
Pablo Greco 48fc63
         OBJECT_PATH_FOREACH_PREFIX(prefix, path) {
Pablo Greco 48fc63
                 r = object_added_append_all_prefix(bus, m, s, prefix, path, true);
Pablo Greco 48fc63
                 if (r < 0)
Pablo Greco 48fc63
@@ -2380,7 +2402,8 @@ static int object_removed_append_all_prefix(
Pablo Greco 48fc63
 
Pablo Greco 48fc63
 static int object_removed_append_all(sd_bus *bus, sd_bus_message *m, const char *path) {
Pablo Greco 48fc63
         _cleanup_set_free_ Set *s = NULL;
Pablo Greco 48fc63
-        char *prefix;
Pablo Greco 48fc63
+        _cleanup_free_ char *prefix = NULL;
Pablo Greco 48fc63
+        size_t pl;
Pablo Greco 48fc63
         int r;
Pablo Greco 48fc63
 
Pablo Greco 48fc63
         assert(bus);
Pablo Greco 48fc63
@@ -2412,7 +2435,12 @@ static int object_removed_append_all(sd_bus *bus, sd_bus_message *m, const char
Pablo Greco 48fc63
         if (bus->nodes_modified)
Pablo Greco 48fc63
                 return 0;
Pablo Greco 48fc63
 
Pablo Greco 48fc63
-        prefix = alloca(strlen(path) + 1);
Pablo Greco 48fc63
+        pl = strlen(path);
Pablo Greco 48fc63
+        assert(pl <= BUS_PATH_SIZE_MAX);
Pablo Greco 48fc63
+        prefix = new(char, pl + 1);
Pablo Greco 48fc63
+        if (!prefix)
Pablo Greco 48fc63
+                return -ENOMEM;
Pablo Greco 48fc63
+
Pablo Greco 48fc63
         OBJECT_PATH_FOREACH_PREFIX(prefix, path) {
Pablo Greco 48fc63
                 r = object_removed_append_all_prefix(bus, m, s, prefix, path, true);
Pablo Greco 48fc63
                 if (r < 0)
Pablo Greco 48fc63
@@ -2554,7 +2582,8 @@ static int interfaces_added_append_one(
Pablo Greco 48fc63
                 const char *path,
Pablo Greco 48fc63
                 const char *interface) {
Pablo Greco 48fc63
 
Pablo Greco 48fc63
-        char *prefix;
Pablo Greco 48fc63
+        _cleanup_free_ char *prefix = NULL;
Pablo Greco 48fc63
+        size_t pl;
Pablo Greco 48fc63
         int r;
Pablo Greco 48fc63
 
Pablo Greco 48fc63
         assert(bus);
Pablo Greco 48fc63
@@ -2568,7 +2597,12 @@ static int interfaces_added_append_one(
Pablo Greco 48fc63
         if (bus->nodes_modified)
Pablo Greco 48fc63
                 return 0;
Pablo Greco 48fc63
 
Pablo Greco 48fc63
-        prefix = alloca(strlen(path) + 1);
Pablo Greco 48fc63
+        pl = strlen(path);
Pablo Greco 48fc63
+        assert(pl <= BUS_PATH_SIZE_MAX);
Pablo Greco 48fc63
+        prefix = new(char, pl + 1);
Pablo Greco 48fc63
+        if (!prefix)
Pablo Greco 48fc63
+                return -ENOMEM;
Pablo Greco 48fc63
+
Pablo Greco 48fc63
         OBJECT_PATH_FOREACH_PREFIX(prefix, path) {
Pablo Greco 48fc63
                 r = interfaces_added_append_one_prefix(bus, m, prefix, path, interface, true);
Pablo Greco 48fc63
                 if (r != 0)