Hi, I was testing this project and came across an interesting point.
Problem:
_pool may be NULL if the cache pool has not been initialized yet. In clcache_get_buffer(), this condition is handled by setting need_new, but execution may still proceed to clcache_enqueue_busy_list() after a new buffer is allocated.
Inside clcache_enqueue_busy_list(), _pool->pl_lock is accessed without checking whether _pool is NULL:
slapi_rwlock_rdlock(_pool->pl_lock) (
|
slapi_rwlock_rdlock(_pool->pl_lock); |
);
This may result in a NULL pointer dereference if clcache_get_buffer() is called before the cache pool is initialized.
Solution:
Add an explicit check that _pool is initialized before calling clcache_enqueue_busy_list(), or otherwise ensure that clcache_get_buffer() cannot be called before clcache_init() has successfully initialized _pool.
389-ds-base v3.1.4
I hope this was helpful!
Hi, I was testing this project and came across an interesting point.
Problem:
_pool may be NULL if the cache pool has not been initialized yet. In clcache_get_buffer(), this condition is handled by setting need_new, but execution may still proceed to clcache_enqueue_busy_list() after a new buffer is allocated.
Inside clcache_enqueue_busy_list(), _pool->pl_lock is accessed without checking whether _pool is NULL:
slapi_rwlock_rdlock(_pool->pl_lock) (
389-ds-base/ldap/servers/plugins/replication/cl5_clcache.c
Line 1051 in a1ba34a
This may result in a NULL pointer dereference if clcache_get_buffer() is called before the cache pool is initialized.
Solution:
Add an explicit check that _pool is initialized before calling clcache_enqueue_busy_list(), or otherwise ensure that clcache_get_buffer() cannot be called before clcache_init() has successfully initialized _pool.
389-ds-base v3.1.4
I hope this was helpful!