The Samba-Bugzilla – Attachment 16813 Details for
Bug 14836
Python ldb.msg_diff() memory handling failure
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Requests
|
Help
|
New Account
|
Log In
[x]
|
Forgot Password
Login:
[x]
[patch]
patch from master backported to 4.15 (only)
ldb-msg.diff.patch (text/plain), 5.82 KB, created by
Andrew Bartlett
on 2021-09-24 02:19:43 UTC
(
hide
)
Description:
patch from master backported to 4.15 (only)
Filename:
MIME Type:
Creator:
Andrew Bartlett
Created:
2021-09-24 02:19:43 UTC
Size:
5.82 KB
patch
obsolete
>From cb03b97a4a1f89e6f9a6b38cdb35240c802fb3fb Mon Sep 17 00:00:00 2001 >From: Joseph Sutton <josephsutton@catalyst.net.nz> >Date: Mon, 13 Sep 2021 11:34:56 +1200 >Subject: [PATCH 1/3] pytest:segfault: Add test for ldb.msg_diff() > >BUG: https://bugzilla.samba.org/show_bug.cgi?id=14642 >BUG: https://bugzilla.samba.org/show_bug.cgi?id=14836 > >Signed-off-by: Joseph Sutton <josephsutton@catalyst.net.nz> >Reviewed-by: Andrew Bartlett <abartlet@samba.org> >Reviewed-by: Douglas Bagnall <douglas.bagnall@catalyst.net.nz> >(cherry picked from commit a99a76722d6046a5d63032e3d2bb3f791da948a6) >--- > python/samba/tests/segfault.py | 12 ++++++++++++ > selftest/knownfail.d/python-segfaults | 1 + > 2 files changed, 13 insertions(+) > >diff --git a/python/samba/tests/segfault.py b/python/samba/tests/segfault.py >index 11d3b3134f4..c316bdd5785 100644 >--- a/python/samba/tests/segfault.py >+++ b/python/samba/tests/segfault.py >@@ -210,3 +210,15 @@ class SegfaultTests(samba.tests.TestCase): > rec = TXTRecord(["a", "b", "c"]) > rec.wType = dnsp.DNS_TYPE_A > rec.data >+ >+ @no_gdb_backtrace >+ @segfault_detector >+ def test_ldb_msg_diff(self): >+ samdb = self.get_samdb() >+ >+ msg = ldb.Message() >+ msg.dn = ldb.Dn(samdb, '') >+ diff = samdb.msg_diff(msg, msg) >+ >+ del msg >+ diff.dn >diff --git a/selftest/knownfail.d/python-segfaults b/selftest/knownfail.d/python-segfaults >index d129dab7d47..da21b68b425 100644 >--- a/selftest/knownfail.d/python-segfaults >+++ b/selftest/knownfail.d/python-segfaults >@@ -1,3 +1,4 @@ > samba.tests.segfault.samba.tests.segfault.SegfaultTests.test_net_replicate_init__3 > samba.tests.segfault.samba.tests.segfault.SegfaultTests.test_dnsp_string_list > samba.tests.segfault.samba.tests.segfault.SegfaultTests.test_dns_record >+samba.tests.segfault.samba.tests.segfault.SegfaultTests.test_ldb_msg_diff >-- >2.25.1 > > >From 157485f5a5366fe1a0944556c2d682211fcd18f8 Mon Sep 17 00:00:00 2001 >From: Joseph Sutton <josephsutton@catalyst.net.nz> >Date: Tue, 14 Sep 2021 11:08:41 +1200 >Subject: [PATCH 2/3] ldb_msg: Don't fail in ldb_msg_copy() if source DN is > NULL > >BUG: https://bugzilla.samba.org/show_bug.cgi?id=14642 >BUG: https://bugzilla.samba.org/show_bug.cgi?id=14836 > >Signed-off-by: Joseph Sutton <josephsutton@catalyst.net.nz> >Reviewed-by: Andrew Bartlett <abartlet@samba.org> >Reviewed-by: Douglas Bagnall <douglas.bagnall@catalyst.net.nz> >(cherry picked from commit c2bbe774ce03661666a1f48922a9ab681ef4f64b) >--- > lib/ldb/common/ldb_msg.c | 6 ++++-- > 1 file changed, 4 insertions(+), 2 deletions(-) > >diff --git a/lib/ldb/common/ldb_msg.c b/lib/ldb/common/ldb_msg.c >index 0179c35659b..57dfc5a04c2 100644 >--- a/lib/ldb/common/ldb_msg.c >+++ b/lib/ldb/common/ldb_msg.c >@@ -876,8 +876,10 @@ struct ldb_message *ldb_msg_copy(TALLOC_CTX *mem_ctx, > msg2 = ldb_msg_copy_shallow(mem_ctx, msg); > if (msg2 == NULL) return NULL; > >- msg2->dn = ldb_dn_copy(msg2, msg2->dn); >- if (msg2->dn == NULL) goto failed; >+ if (msg2->dn != NULL) { >+ msg2->dn = ldb_dn_copy(msg2, msg2->dn); >+ if (msg2->dn == NULL) goto failed; >+ } > > for (i=0;i<msg2->num_elements;i++) { > struct ldb_message_element *el = &msg2->elements[i]; >-- >2.25.1 > > >From 93a00ef342c6cb7c1cb7c928d5376e880b004015 Mon Sep 17 00:00:00 2001 >From: Joseph Sutton <josephsutton@catalyst.net.nz> >Date: Mon, 13 Sep 2021 11:15:17 +1200 >Subject: [PATCH 3/3] pyldb: Avoid use-after-free in msg_diff() > >Make a deep copy of the message elements in msg_diff() so that if either >of the input messages are deallocated early, the result does not refer >to non-existing elements. > >BUG: https://bugzilla.samba.org/show_bug.cgi?id=14642 >BUG: https://bugzilla.samba.org/show_bug.cgi?id=14836 > >Signed-off-by: Joseph Sutton <josephsutton@catalyst.net.nz> >Reviewed-by: Andrew Bartlett <abartlet@samba.org> >Reviewed-by: Douglas Bagnall <douglas.bagnall@catalyst.net.nz> >(cherry picked from commit 19a2af02f57d99db8ed3c6b028c3abdf4b553700) >--- > lib/ldb/pyldb.c | 18 ++++++++++++++++-- > selftest/knownfail.d/python-segfaults | 1 - > 2 files changed, 16 insertions(+), 3 deletions(-) > >diff --git a/lib/ldb/pyldb.c b/lib/ldb/pyldb.c >index dadea2a7d6e..c264f361c40 100644 >--- a/lib/ldb/pyldb.c >+++ b/lib/ldb/pyldb.c >@@ -1804,6 +1804,7 @@ static PyObject *py_ldb_msg_diff(PyLdbObject *self, PyObject *args) > struct ldb_message *diff; > struct ldb_context *ldb; > PyObject *py_ret; >+ TALLOC_CTX *mem_ctx = NULL; > > if (!PyArg_ParseTuple(args, "OO", &py_msg_old, &py_msg_new)) > return NULL; >@@ -1818,19 +1819,32 @@ static PyObject *py_ldb_msg_diff(PyLdbObject *self, PyObject *args) > return NULL; > } > >+ mem_ctx = talloc_new(NULL); >+ if (mem_ctx == NULL) { >+ PyErr_NoMemory(); >+ return NULL; >+ } >+ > ldb = pyldb_Ldb_AS_LDBCONTEXT(self); >- ldb_ret = ldb_msg_difference(ldb, ldb, >+ ldb_ret = ldb_msg_difference(ldb, mem_ctx, > pyldb_Message_AsMessage(py_msg_old), > pyldb_Message_AsMessage(py_msg_new), > &diff); > if (ldb_ret != LDB_SUCCESS) { >+ talloc_free(mem_ctx); > PyErr_SetString(PyExc_RuntimeError, "Failed to generate the Ldb Message diff"); > return NULL; > } > >+ diff = ldb_msg_copy(mem_ctx, diff); >+ if (diff == NULL) { >+ PyErr_NoMemory(); >+ return NULL; >+ } >+ > py_ret = PyLdbMessage_FromMessage(diff); > >- talloc_unlink(ldb, diff); >+ talloc_free(mem_ctx); > > return py_ret; > } >diff --git a/selftest/knownfail.d/python-segfaults b/selftest/knownfail.d/python-segfaults >index da21b68b425..d129dab7d47 100644 >--- a/selftest/knownfail.d/python-segfaults >+++ b/selftest/knownfail.d/python-segfaults >@@ -1,4 +1,3 @@ > samba.tests.segfault.samba.tests.segfault.SegfaultTests.test_net_replicate_init__3 > samba.tests.segfault.samba.tests.segfault.SegfaultTests.test_dnsp_string_list > samba.tests.segfault.samba.tests.segfault.SegfaultTests.test_dns_record >-samba.tests.segfault.samba.tests.segfault.SegfaultTests.test_ldb_msg_diff >-- >2.25.1 >
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Flags:
dbagnall
:
review+
Actions:
View
Attachments on
bug 14836
: 16813 |
16814