mirror of
https://gitlab.torproject.org/tpo/core/tor.git
synced 2024-12-06 19:41:15 +01:00
Add one other BUG check to try to fix/solve 21369.
Teor thinks that this connection_dirserv_add_dir_bytes_to_outbuf() might be the problem, if the "remaining" calculation underflows. So I'm adding a couple of checks there, and improving the casts.
This commit is contained in:
+8
-2
@@ -3629,8 +3629,14 @@ connection_dirserv_add_dir_bytes_to_outbuf(dir_connection_t *conn)
|
||||
if (bytes < 8192)
|
||||
bytes = 8192;
|
||||
remaining = conn->cached_dir->dir_z_len - conn->cached_dir_offset;
|
||||
if (bytes > remaining)
|
||||
if (BUG(remaining < 0)) {
|
||||
remaining = 0;
|
||||
}
|
||||
if (bytes > remaining) {
|
||||
bytes = (ssize_t) remaining;
|
||||
if (BUG(bytes < 0))
|
||||
return -1;
|
||||
}
|
||||
|
||||
if (conn->zlib_state) {
|
||||
connection_write_to_buf_zlib(
|
||||
@@ -3641,7 +3647,7 @@ connection_dirserv_add_dir_bytes_to_outbuf(dir_connection_t *conn)
|
||||
bytes, TO_CONN(conn));
|
||||
}
|
||||
conn->cached_dir_offset += bytes;
|
||||
if (conn->cached_dir_offset == (int)conn->cached_dir->dir_z_len) {
|
||||
if (conn->cached_dir_offset >= (off_t)conn->cached_dir->dir_z_len) {
|
||||
/* We just wrote the last one; finish up. */
|
||||
connection_dirserv_finish_spooling(conn);
|
||||
cached_dir_decref(conn->cached_dir);
|
||||
|
||||
Reference in New Issue
Block a user