From ee1d8dc4805e0aabfbda4c8b34e12d2071333a51 Mon Sep 17 00:00:00 2001 From: Nick Mathewson Date: Fri, 28 Dec 2012 22:57:00 -0500 Subject: [PATCH 1/2] Fix a leak-on-error case in 0.2.4 spotted by coverity This one hits if the snprintf() fails when we're writing our IPv6 exit policy. It's new in 0.2.4.7-alpha. Part of bug 7816. --- changes/bug7816.024 | 4 ++++ src/or/router.c | 1 + 2 files changed, 5 insertions(+) create mode 100644 changes/bug7816.024 diff --git a/changes/bug7816.024 b/changes/bug7816.024 new file mode 100644 index 0000000000..6ed6b74858 --- /dev/null +++ b/changes/bug7816.024 @@ -0,0 +1,4 @@ + o Minor bugfixes: + - Avoid leaking IPv6 policy content if we fail to format it into + a router descriptor. Spotted by Coverity. Fixes part of 7816; + bugfix on 0.2.4.7-alpha. diff --git a/src/or/router.c b/src/or/router.c index c7380cb444..e892ce0997 100644 --- a/src/or/router.c +++ b/src/or/router.c @@ -2190,6 +2190,7 @@ router_dump_router_to_string(char *s, size_t maxlen, routerinfo_t *router, "ipv6-policy %s\n", p6); if (result<0) { log_warn(LD_BUG,"Descriptor printf of policy ran out of room"); + tor_free(p6); return -1; } written += result; From f272ee6a20ec0df491bed485a0eea4ae2f82e40c Mon Sep 17 00:00:00 2001 From: Nick Mathewson Date: Fri, 28 Dec 2012 23:04:44 -0500 Subject: [PATCH 2/2] Fix an impossible-in-normal-operation leaks in dirvote Spotted by coverity; partial fix for 7816; bugfix on 0.2.0.5-alpha. --- changes/bug7816.024 | 4 ++++ src/or/dirvote.c | 20 +++++++++++--------- 2 files changed, 15 insertions(+), 9 deletions(-) diff --git a/changes/bug7816.024 b/changes/bug7816.024 index 6ed6b74858..b5d55f5d6d 100644 --- a/changes/bug7816.024 +++ b/changes/bug7816.024 @@ -2,3 +2,7 @@ - Avoid leaking IPv6 policy content if we fail to format it into a router descriptor. Spotted by Coverity. Fixes part of 7816; bugfix on 0.2.4.7-alpha. + + - Avoid leaking memory if we fail to compute a consensus signature + or we generated a consensus we couldn't parse. Spotted by Coverity. + Fixes part of 7816; bugfix on 0.2.0.5-alpha. diff --git a/src/or/dirvote.c b/src/or/dirvote.c index 1b9af0f731..72ae09741f 100644 --- a/src/or/dirvote.c +++ b/src/or/dirvote.c @@ -2139,7 +2139,7 @@ networkstatus_compute_consensus(smartlist_t *votes, digest, digest_len, legacy_signing_key)) { log_warn(LD_BUG, "Couldn't sign consensus networkstatus."); - return NULL; /* This leaks, but it should never happen. */ + goto done; } smartlist_add(chunks, tor_strdup(sigbuf)); } @@ -2147,13 +2147,6 @@ networkstatus_compute_consensus(smartlist_t *votes, result = smartlist_join_strings(chunks, "", 0, NULL); - tor_free(client_versions); - tor_free(server_versions); - SMARTLIST_FOREACH(flags, char *, cp, tor_free(cp)); - smartlist_free(flags); - SMARTLIST_FOREACH(chunks, char *, cp, tor_free(cp)); - smartlist_free(chunks); - { networkstatus_t *c; if (!(c = networkstatus_parse_vote_from_string(result, NULL, @@ -2161,7 +2154,7 @@ networkstatus_compute_consensus(smartlist_t *votes, log_err(LD_BUG, "Generated a networkstatus consensus we couldn't " "parse."); tor_free(result); - return NULL; + goto done; } // Verify balancing parameters if (consensus_method >= MIN_METHOD_FOR_BW_WEIGHTS && added_weights) { @@ -2170,6 +2163,15 @@ networkstatus_compute_consensus(smartlist_t *votes, networkstatus_vote_free(c); } + done: + + tor_free(client_versions); + tor_free(server_versions); + SMARTLIST_FOREACH(flags, char *, cp, tor_free(cp)); + smartlist_free(flags); + SMARTLIST_FOREACH(chunks, char *, cp, tor_free(cp)); + smartlist_free(chunks); + return result; }