libnl/lib
Torsten Hilbrich 4035e5b5e8 link: fix regression in link message parser
In a simple test program that queries the source IP for a given
destination address I get a crash in the call to rtnl_link_alloc_cache.

Here is the stack trace (created with version 3.2.4):

Program received signal SIGSEGV, Segmentation fault.
0xb7eb7553 in strlen () from /lib/libc.so.6
(gdb) bt
#0  0xb7eb7553 in strlen () from /lib/libc.so.6
#1  0xb7eb7285 in strdup () from /lib/libc.so.6
#2  0xb7fcc305 in nla_strdup (nla=0x0) at attr.c:1033
#3  0xb7f9c173 in link_msg_parser (ops=0xb7fc2940, who=0x804b330, n=0x804c3e8, pp=0xbffffbf8) at route/link.c:486
#4  0xb7fcd485 in nl_cache_parse (ops=0xb7fc2940, who=0x804b330, nlh=0x804c3e8, params=0xbffffbf8) at cache.c:724
#5  0xb7fcd547 in update_msg_parser (msg=0x804b328, arg=0xbffffbb8) at cache.c:531
#6  0xb7fd1f25 in nl_cb_call (cb=<optimized out>, msg=<optimized out>, type=<optimized out>) at ../include/netlink-local.h:126
#7  recvmsgs (cb=<optimized out>, sk=<optimized out>) at nl.c:729
#8  nl_recvmsgs (sk=0x804b2d0, cb=0x804b368) at nl.c:780
#9  0xb7fcd5fd in __cache_pickup (sk=0x804b2d0, cache=<optimized out>, param=0xbffffbf8) at cache.c:560
#10 0xb7fcd83f in nl_cache_pickup (sk=0x804b2d0, cache=0x804b308) at cache.c:593
#11 0xb7fcd8c8 in nl_cache_refill (sk=0x804b2d0, cache=0x804b308) at cache.c:780
#12 0xb7f9d1fc in rtnl_link_alloc_cache (sk=0x804b2d0, family=4, result=0xbffffcd4) at route/link.c:868
#13 0x08048fd0 in libnl_init (data=<optimized out>) at helper_route.c:60
#14 iproute_get_source (destination=0xbffffeff "127.0.0.1",
    source=0xbffffd0f "\b\004c\370\267\364_\370\267\260\224\004\b8\375\377\277e\024\347\267\320\016\377\267\273\224\004\b\364_\370\267\260\224\004\b", source_size=17)
    at helper_route.c:105
#15 0x08048e6a in main (argc=2, argv=0xbffffde4) at ip_route_get.c:25

The attached patch (against 3.2.4) solves the problem, fixing something that
looks like a typo. The bug is still present in current Git master.
2012-01-12 13:15:31 +01:00
..
cli rename sch -> qdisc 2011-03-21 16:47:42 +01:00
fib_lookup Updated link documentation 2011-07-28 16:23:57 +02:00
genl genl: genl_ctrl_grp_by_name: fix retval in case group id not found 2011-08-31 12:35:56 +02:00
netfilter rename nl_send_auto_complete() -> nl_send_auto(), nl_auto_complete -> nl_complete_msg() 2010-11-18 14:13:49 +01:00
route link: fix regression in link message parser 2012-01-12 13:15:31 +01:00
.gitignore Build separate libraries for each netilnk family 2008-05-15 18:01:50 +02:00
addr.c nl_addr_cmp(): handle prefix length during address comparison 2012-01-12 10:18:35 +01:00
attr.c Omit empty nested attributes 2011-03-23 13:39:18 +01:00
cache.c Make some functions and global variables static 2011-08-11 14:49:51 +02:00
cache_mngr.c avoid dangling co_major_cache reference to NL_AUTO_PROVIDE caches 2012-01-11 12:31:40 +01:00
cache_mngt.c Provide silent variation of nl_cache_require() 2011-05-11 09:33:29 +02:00
data.c restructure module documentation order 2008-12-10 18:12:30 +01:00
error.c Support for NLM_F_INTR 2011-07-14 10:51:49 +02:00
handlers.c restructure module documentation order 2008-12-10 18:12:30 +01:00
Makefile.am Switch to libtool versioning system 2011-09-13 22:58:08 +02:00
msg.c Make some functions and global variables static 2011-08-11 14:49:51 +02:00
nl.c Fix typo in debug message 2011-10-28 12:30:31 +02:00
object.c Provide nl_object_dump_buf() to easily dump to buffers 2011-04-10 10:22:01 +02:00
socket.c socket: fix two typos 2011-08-31 09:24:01 +02:00
utils.c utils: Initialize list head after freeing translation list 2011-10-10 12:02:33 +02:00