Re: [PATCH] erofs-utils: s3: fix memory leak in s3erofs_create_object_iterator

Yifan Zhao <[email protected]>
Newsgroups org.ozlabs.lists.linux-erofs
Message-ID <[email protected]>
On 4/4/2026 4:27 PM, Nithurshen wrote:
> In s3erofs_create_object_iterator(), if the parsed prefix length
> exceeds S3EROFS_PATH_MAX, the function aborts and returns an
> -EINVAL error pointer. However, the 'iter' structure was already
> allocated via calloc() and left unfreed, causing a memory leak.
>
> This commit adds the missing free(iter) call in the error path to
> prevent leaking memory when excessively long S3 bucket paths are
> provided.
>
> Signed-off-by: Nithurshen <[email protected]>
> ---
>   lib/remotes/s3.c | 4 +++-
>   1 file changed, 3 insertions(+), 1 deletion(-)
>
> diff --git a/lib/remotes/s3.c b/lib/remotes/s3.c
> index 768232a..94b4ffb 100644
> --- a/lib/remotes/s3.c
> +++ b/lib/remotes/s3.c
> @@ -911,8 +911,10 @@ s3erofs_create_object_iterator(struct erofs_s3 *s3, const char *path,
>   		iter->bucket = NULL;
>   		iter->prefix = strdup(path + 1);
>   	} else {
> -		if (++prefix - path > S3EROFS_PATH_MAX)
> +		if (++prefix - path > S3EROFS_PATH_MAX){

missing a space before the brace, otherwise LGTM.

Reviewed-by: Yifan Zhao <[email protected]>

> +			free(iter);
>   			return ERR_PTR(-EINVAL);
> +		}
>   		iter->bucket = strndup(path, prefix - path);
>   		iter->prefix = strdup(prefix);
>   	}
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.