This is an automated email from the ASF dual-hosted git repository.

zwoop pushed a commit to branch 9.2.x
in repository https://gitbox.apache.org/repos/asf/trafficserver.git


The following commit(s) were added to refs/heads/9.2.x by this push:
     new d9186e76c Fixes leak in SNIAction name globbing (#8827)
d9186e76c is described below

commit d9186e76ce7db8d8a1b7a6ef04b32b89a2199338
Author: Randall Meyer <[email protected]>
AuthorDate: Fri May 6 12:07:17 2022 -0700

    Fixes leak in SNIAction name globbing (#8827)
    
    pcre_compile allocated object is never pcre_free-ed
    
    (cherry picked from commit efaf44147bbf1b4a90fcb2289f01ff25708f0e0e)
---
 iocore/net/P_SSLSNI.h      | 25 +++++++++++++++++++++----
 iocore/net/SSLSNIConfig.cc |  5 +++--
 2 files changed, 24 insertions(+), 6 deletions(-)

diff --git a/iocore/net/P_SSLSNI.h b/iocore/net/P_SSLSNI.h
index 8897d0dbc..dbc1cc276 100644
--- a/iocore/net/P_SSLSNI.h
+++ b/iocore/net/P_SSLSNI.h
@@ -33,6 +33,7 @@
 #include <vector>
 #include <string_view>
 #include <strings.h>
+#include <memory>
 
 #include "ProxyConfig.h"
 #include "P_SNIActionPerformer.h"
@@ -51,10 +52,28 @@ struct NextHopProperty {
 
 using actionVector = std::vector<std::unique_ptr<ActionItem>>;
 
+struct pcreFreer {
+  void
+  operator()(void *p)
+  {
+    pcre_free(p);
+  }
+};
+
 struct namedElement {
 public:
   namedElement() {}
 
+  namedElement &
+  operator=(namedElement &&other)
+  {
+    if (this != &other) {
+      match = std::move(other.match);
+    }
+    return *this;
+  }
+  namedElement(namedElement &&other) { *this = std::move(other); }
+
   void
   setGlobName(std::string name)
   {
@@ -77,13 +96,11 @@ public:
     const char *err_ptr;
     int err_offset = 0;
     if (!regexName.empty()) {
-      match = pcre_compile(regexName.c_str(), PCRE_ANCHORED | PCRE_CASELESS, 
&err_ptr, &err_offset, nullptr);
-    } else {
-      match = nullptr;
+      match.reset(pcre_compile(regexName.c_str(), PCRE_ANCHORED | 
PCRE_CASELESS, &err_ptr, &err_offset, nullptr));
     }
   }
 
-  pcre *match = nullptr;
+  std::unique_ptr<pcre, pcreFreer> match;
 };
 
 struct actionElement : public namedElement {
diff --git a/iocore/net/SSLSNIConfig.cc b/iocore/net/SSLSNIConfig.cc
index 2d069f256..f48211205 100644
--- a/iocore/net/SSLSNIConfig.cc
+++ b/iocore/net/SSLSNIConfig.cc
@@ -49,7 +49,7 @@ SNIConfigParams::getPropertyConfig(const std::string 
&servername) const
 {
   const NextHopProperty *nps = nullptr;
   for (auto &&item : next_hop_list) {
-    if (pcre_exec(item.match, nullptr, servername.c_str(), 
servername.length(), 0, 0, nullptr, 0) >= 0) {
+    if (pcre_exec(item.match.get(), nullptr, servername.c_str(), 
servername.length(), 0, 0, nullptr, 0) >= 0) {
       // Found a match
       nps = &item.prop;
       break;
@@ -123,7 +123,8 @@ SNIConfigParams::get(std::string_view servername) const
     int length = servername.length();
     if (retval.match == nullptr && length == 0) {
       return {&retval.actions, {}};
-    } else if (auto offset = pcre_exec(retval.match, nullptr, 
servername.data(), length, 0, 0, ovector, OVECSIZE); offset >= 0) {
+    } else if (auto offset = pcre_exec(retval.match.get(), nullptr, 
servername.data(), length, 0, 0, ovector, OVECSIZE);
+               offset >= 0) {
       if (offset == 1) {
         // first pair identify the portion of the subject string matched by 
the entire pattern
         if (ovector[0] == 0 && ovector[1] == length) {

Reply via email to