Re: [PATCH] nproc: Verify the cgroup path isn't truncated.

Collin Funk <[email protected]>
Newsgroups gmane.comp.lib.gnulib.bugs
Message-ID <[email protected]>
Collin Funk <[email protected]> writes:

> -      if ((fp = fopen (cpu_max_file, "r"))
> +      if (0 <= n && n < sizeof cpu_max_file
> +          && (fp = fopen (cpu_max_file, "r"))

Oops. Coverity noticed that if the first expression is true, then FP
won't be set to NULL or a newly opened file causing fclose to be called
twice on the same file.

I pushed the attached patch to fix that.

Collin
0001-nproc-Don-t-call-fclose-twice-regr.-today.patch (text/x-patch, 1.8 KB)
From 4bc1b5d165226c1a2c58f13fe1a5c94ccdaf26c8 Mon Sep 17 00:00:00 2001
Message-ID: <4bc1b5d165226c1a2c58f13fe1a5c94ccdaf26c8.1786939933.git.collin.funk1@gmail.com>
From: Collin Funk <[email protected]>
Date: Sun, 16 Aug 2026 21:08:23 -0700
Subject: [PATCH] nproc: Don't call fclose twice (regr. today).

Problem found by Coverity (CID 1700233).

* lib/nproc.c (get_cgroup2_cpu_quota): Set FP to NULL if fopen does not
get called.
---
 ChangeLog   | 7 +++++++
 lib/nproc.c | 9 +++++----
 2 files changed, 12 insertions(+), 4 deletions(-)

diff --git a/ChangeLog b/ChangeLog
index 8a9ecfb0a5..89895173a0 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -1,3 +1,10 @@
+2026-08-16  Collin Funk  <[email protected]>
+
+	nproc: Don't call fclose twice (regr. today).
+	Problem found by Coverity (CID 1700233).
+	* lib/nproc.c (get_cgroup2_cpu_quota): Set FP to NULL if fopen does not
+	get called.
+
 2026-08-16  Bruno Haible  <[email protected]>
 
 	tests: Avoid some test failures with the clang UBSAN.
diff --git a/lib/nproc.c b/lib/nproc.c
index e3dfeaa16d..821a913c3a 100644
--- a/lib/nproc.c
+++ b/lib/nproc.c
@@ -440,10 +440,11 @@ get_cgroup2_cpu_quota (void)
       int n = snprintf (cpu_max_file, sizeof (cpu_max_file),
                         "%s%s/cpu.max", mount, cgroup);
 
-      if (0 <= n && n < sizeof cpu_max_file
-          && (fp = fopen (cpu_max_file, "r"))
-          && getline (&quota_str, &quota_size, fp) != -1
-          && strncmp (quota_str, "max", 3) != 0)
+      if (n < 0 || sizeof cpu_max_file <= n)
+        fp = NULL;
+      else if ((fp = fopen (cpu_max_file, "r"))
+               && getline (&quota_str, &quota_size, fp) != -1
+               && strncmp (quota_str, "max", 3) != 0)
         {
           long quota, period;
           if (sscanf (quota_str, "%ld %ld", &quota, &period) == 2 && period)
-- 
2.55.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.