Project homepage Mailing List  Warmcat.com  API Docs  Github Mirror 
    npro  
 Modern all-safe Rust Network Protocol library supporting h1, h2, h3, ws, wt sans-IO and with socket IO + tls
git clone https://npro.rs/repo/npro
 
root / scripts / usr-local-svc-method-sai_builder-Solaris
Author[]google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.c...> 2025-08-14 13:13 UTC
Committer[]Andy Green <andy@warmcat.com> 2025-08-14 19:49 UTC
Tree37a458ae216609d986e8c940c49a8881161c6a5e   Raw Patch
 
Fix task list corruption in builder task assignment
Fix task list corruption in builder task assignment

The `pss->issue_task_owner` list could become corrupted when two or more
tasks were assigned to the same builder in quick succession. This was
because the same `pss->alloc_task` buffer was being reused for multiple
tasks, leading to a single task object being added to the same list
multiple times, which corrupted the list's internal pointers.

This change fixes the issue by creating a deep copy of the task object
using `malloc` before adding it to the `issue_task_owner` list. This
ensures that each task on the list is a unique object.

The deallocation logic in `sais_ws_json_tx_builder` has been updated to
`free` the `malloc`'d task object and its associated `lwsac` resources
correctly, both in the success and error paths, preventing memory leaks.

diff --git a/src/server/s-task.c b/src/server/s-task.c index 1d2bff4..e5a4332 100644 --- a/src/server/s-task.c +++ b/src/server/s-task.c @@ -775,9 +775,10 @@ int sais_allocate_task(struct vhd *vhd, struct pss *pss, sai_plat_t *cb, const char *platform_name) { + const sai_task_t *task_template; char esc1[96], esc2[96]; lws_dll2_owner_t o; - sai_task_t *task; + sai_task_t *task = NULL; int n; if (cb->ongoing >= cb->instances) @@ -787,10 +788,17 @@ sais_allocate_task(struct vhd *vhd, struct pss *pss, sai_plat_t *cb, * Look for a task for this platform, on any event that needs building */ - task = (sai_task_t *)sais_task_pending(vhd, pss, platform_name); - if (!task) + task_template = sais_task_pending(vhd, pss, platform_name); + if (!task_template) return 1; + task = malloc(sizeof(sai_task_t)); + if (!task) { + lwsac_free(&pss->ac_alloc_task); + return -1; + } + *task = *task_template; + lwsl_notice("%s: %s: task found %s\n", __func__, platform_name, cb->name); /* yes, we will offer it to him */ @@ -843,6 +851,8 @@ sais_allocate_task(struct vhd *vhd, struct pss *pss, sai_plat_t *cb, return 0; bail: + if (task) + free(task); lwsac_free(&pss->a.ac); lwsac_free(&pss->ac_alloc_task); diff --git a/src/server/s-ws-builder.c b/src/server/s-ws-builder.c index 7bd2f01..c2dddc1 100644 --- a/src/server/s-ws-builder.c +++ b/src/server/s-ws-builder.c @@ -1110,13 +1110,17 @@ sais_ws_json_tx_builder(struct vhd *vhd, struct pss *pss, uint8_t *buf, js = lws_struct_json_serialize_create(lsm_schema_map_ta, LWS_ARRAY_SIZE(lsm_schema_map_ta), 0, task); - if (!js) + if (!js) { + lwsac_free(&task->ac_task_container); + free(task); return 1; + } n = (int)lws_struct_json_serialize(js, p, lws_ptr_diff_size_t(end, p), &w); lws_struct_json_serialize_destroy(&js); pss->one_event = NULL; lwsac_free(&task->ac_task_container); + free(task); first = 1;
Page fetched 0s ago, creation time: 3ms (vhost etag hits: 0%, cache hits: 0%)