Commit 8999e8d
Fix double-free in parseDirectoryEntries on malformed dir entries
Directory entries registered both an outer errdefer and an inner defer
against the same full_name allocation. When the recursive parse hit an
error (e.g. Truncated), both fired and freed the same pointer twice,
causing SIGABRT/SIGSEGV on malformed CPT archives. Found by validate's
--test-coverage stress run (exit 134 on corrupted sample.cpt).
Fix: hoist the defer/errdefer into the specific branch that owns the
allocation. Dir entries use a single defer (success continue and error
unwind both free exactly once); file entries use errdefer (ownership
transfers to the accumulator on successful append).
Regression test crafts a minimal archive with a non-empty directory
name whose recursive child is truncated, which std.testing.allocator
detects as a double-free under the unfixed code.1 parent e4d328e commit 8999e8d
2 files changed
Lines changed: 37 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
215 | 215 | | |
216 | 216 | | |
217 | 217 | | |
218 | | - | |
219 | 218 | | |
220 | 219 | | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
221 | 224 | | |
222 | 225 | | |
223 | 226 | | |
224 | | - | |
225 | 227 | | |
226 | 228 | | |
227 | 229 | | |
228 | 230 | | |
229 | 231 | | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
230 | 236 | | |
231 | 237 | | |
232 | 238 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
381 | 381 | | |
382 | 382 | | |
383 | 383 | | |
| 384 | + | |
| 385 | + | |
| 386 | + | |
| 387 | + | |
| 388 | + | |
| 389 | + | |
| 390 | + | |
| 391 | + | |
| 392 | + | |
| 393 | + | |
| 394 | + | |
| 395 | + | |
| 396 | + | |
| 397 | + | |
| 398 | + | |
| 399 | + | |
| 400 | + | |
| 401 | + | |
| 402 | + | |
| 403 | + | |
| 404 | + | |
| 405 | + | |
| 406 | + | |
| 407 | + | |
| 408 | + | |
| 409 | + | |
| 410 | + | |
| 411 | + | |
| 412 | + | |
0 commit comments