Skip to content
This repository has been archived by the owner on Jun 23, 2022. It is now read-only.

fix(asan): heap-use-after-free in rpc_read_stream #738

Merged
merged 1 commit into from
Jan 26, 2021
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 6 additions & 5 deletions include/dsn/cpp/rpc_stream.h
Original file line number Diff line number Diff line change
Expand Up @@ -48,12 +48,13 @@ class rpc_read_stream : public binary_reader
void set_read_msg(message_ex *msg)
{
_msg = msg;
if (nullptr != _msg) {
::dsn::blob bb;
bool r = ((::dsn::message_ex *)_msg)->read_next(bb);
dassert(r, "read msg must have one segment of buffer ready");

::dsn::blob bb;
bool r = ((::dsn::message_ex *)_msg)->read_next(bb);
dassert(r, "read msg must have one segment of buffer ready");

init(std::move(bb));
init(std::move(bb));
}
}

~rpc_read_stream()
Expand Down
3 changes: 3 additions & 0 deletions src/runtime/rpc/thrift_message_parser.cpp
Original file line number Diff line number Diff line change
Expand Up @@ -111,6 +111,9 @@ static message_ex *create_message_from_request_blob(const blob &body_data)
if (dsn_hdr->context.u.is_request != 1) {
derror("invalid message type: %d", mtype);
delete msg;
/// set set rpc_read_stream::_msg to nullptr,
/// to avoid the dstor to call read_commit of _msg, which is deleted here.
stream.set_read_msg(nullptr);
return nullptr;
}
dsn_hdr->context.u.serialize_format = DSF_THRIFT_BINARY; // always serialize in thrift binary
Expand Down