vici: Don't pass stack variable to thread cleanup handler

The variable seems to get overwritten during cleanup, causing a
segmentation fault because either the pointer and/or the length is
invalid.
This commit is contained in:
Tobias Brunner
2025-05-19 17:19:20 +02:00
parent 367e782054
commit 8d3855ba31
+15 -4
View File
@@ -480,6 +480,15 @@ static bool do_read(private_vici_socket_t *this, entry_t *entry,
return TRUE;
}
/**
* Clear the given chunk and free it
*/
static void destroy_request_chunk(chunk_t *chunk)
{
chunk_clear(chunk);
free(chunk);
}
/**
* Callback processing incoming requests in strict order
*/
@@ -487,7 +496,7 @@ CALLBACK(process_queue, job_requeue_t,
entry_selector_t *sel)
{
entry_t *entry;
chunk_t chunk;
chunk_t *chunk;
bool found;
u_int id;
@@ -499,7 +508,8 @@ CALLBACK(process_queue, job_requeue_t,
break;
}
found = array_remove(entry->queue, ARRAY_HEAD, &chunk);
INIT(chunk);
found = array_remove(entry->queue, ARRAY_HEAD, chunk);
if (!found)
{
entry->has_processor = FALSE;
@@ -508,11 +518,12 @@ CALLBACK(process_queue, job_requeue_t,
put_entry(sel->this, entry, TRUE, FALSE);
if (!found)
{
free(chunk);
break;
}
thread_cleanup_push((void*)chunk_clear, &chunk);
sel->this->inbound(sel->this->user, id, chunk);
thread_cleanup_push((void*)destroy_request_chunk, chunk);
sel->this->inbound(sel->this->user, id, *chunk);
thread_cleanup_pop(TRUE);
}
return JOB_REQUEUE_NONE;