Repository navigation
reserve room for nul terminator in checkPathList result buffer - #1300
netliomax25-code wants to merge 1 commit into
Conversation
There was a problem hiding this comment.
Pull request overview
Fixes a heap buffer overflow in the launcher’s path-list handling by ensuring checkPathList() allocates space for the trailing NUL terminator when building its recombined result string.
Changes:
- Adjust
checkPathList()result buffer allocation to include space for the terminating NUL.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| size_t bufferLength = _tcslen(pathList); | ||
|
|
||
| result = malloc(bufferLength * sizeof(_TCHAR)); | ||
| result = malloc((bufferLength + 1) * sizeof(_TCHAR)); |
There was a problem hiding this comment.
Good point. Folded the + 1 into bufferLength so the variable now tracks the actual allocation size, and the realloc branch already uses bufferLength * sizeof(_TCHAR), so capacity reasoning stays consistent throughout. Re-ran the /a:/b case and a couple multi-segment lists under ASan and there's no overflow.
a0c49b4 to
09f5dcc
Compare
09f5dcc to
a92a76c
Compare
|
Added the missing Signed-off-by and force-pushed, so the ECA check should clear now. The Code Analysis job looks like it's failing on a releng step that re-tags the native binaries ( |
a92a76c to
143ddb5
Compare
|
Amended the commit so the author and sign-off match my Eclipse account identity and re-pushed, but the ECA check is still red, so the remaining piece is the agreement on my Eclipse Foundation account rather than the commit metadata. Getting that signed on my end; the patch itself is unchanged. |
143ddb5 to
5b97045
Compare
|
Rebased onto current master and re-pushed. The ECA account is signed now, so the eclipsefdn/eca check went green on this push (it had been stuck on a stale evaluation from before the agreement was on file). The still-red checks look unrelated to this one-line launcher fix: Configuration Admin TCK and Code Analysis are also failing on master and on other open PRs right now, and the Jenkins pr-head run shows as aborted rather than a real failure. The GitHub Build Linux/Windows/MacOS jobs and CodeQL are green. Happy to rebase again if you'd like a fresh run once master's TCK is back to green. |
|
any update? |
|
@netliomax25-code code change looks harmless to me on its own (so even if +1 would not bee needed here). But builds are failing (maybe infrastructure?) I would suggest that you rebase on latest master and we see if that fixes the problem. If no one else plans to object I would then say we can just merge the PR as it is minimal and looks viable to me even though it seems not really possible to test it directly (what might be why you get less response here). |
Signed-off-by: Kartik Kenchi <netliomax25@gmail.com>
5b97045 to
492681b
Compare
|
Rebased onto current master (now sitting on top of 8294c6b) and force-pushed, so there should be a fresh run. On it not really being testable directly, that is fair, there is no harness for the launcher C sources in-tree. What I ran out-of-tree:
If it comes back red on something unrelated I can re-push later. |
|
Results are in, and the rebase did clear the earlier build failures:
Nothing in the diff changed, it is still the one-line allocation size. |
Found this with ASan while exercising the launcher's .ee path-list handling. checkPathList sizes result as malloc(strlen(pathList)) but the recombined string also needs the trailing nul (plus the separators it reinserts), so a value like /a:/b writes one _TCHAR past the allocation. concatPaths just below already does length + 1; the same applies here.