Re: [PATCH] erofs-utils: s3: fix memory leak in s3erofs_create_object_iterator
Yifan Zhao <[email protected]>
| Newsgroups | org.ozlabs.lists.linux-erofs |
|---|---|
| Message-ID | <[email protected]> |
On 4/4/2026 4:27 PM, Nithurshen wrote: > In s3erofs_create_object_iterator(), if the parsed prefix length > exceeds S3EROFS_PATH_MAX, the function aborts and returns an > -EINVAL error pointer. However, the 'iter' structure was already > allocated via calloc() and left unfreed, causing a memory leak. > > This commit adds the missing free(iter) call in the error path to > prevent leaking memory when excessively long S3 bucket paths are > provided. > > Signed-off-by: Nithurshen <[email protected]> > --- > lib/remotes/s3.c | 4 +++- > 1 file changed, 3 insertions(+), 1 deletion(-) > > diff --git a/lib/remotes/s3.c b/lib/remotes/s3.c > index 768232a..94b4ffb 100644 > --- a/lib/remotes/s3.c > +++ b/lib/remotes/s3.c > @@ -911,8 +911,10 @@ s3erofs_create_object_iterator(struct erofs_s3 *s3, const char *path, > iter->bucket = NULL; > iter->prefix = strdup(path + 1); > } else { > - if (++prefix - path > S3EROFS_PATH_MAX) > + if (++prefix - path > S3EROFS_PATH_MAX){ missing a space before the brace, otherwise LGTM. Reviewed-by: Yifan Zhao <[email protected]> > + free(iter); > return ERR_PTR(-EINVAL); > + } > iter->bucket = strndup(path, prefix - path); > iter->prefix = strdup(prefix); > }