projects
/
lttng-tools.git
/ blobdiff
commit
grep
author
committer
pickaxe
?
search:
re
summary
|
shortlog
|
log
|
commit
|
commitdiff
|
tree
raw
|
inline
| side by side
Fix: filter error path could free invalid ptr
[lttng-tools.git]
/
src
/
lib
/
lttng-ctl
/
filter
/
filter-visitor-generate-bytecode.c
diff --git
a/src/lib/lttng-ctl/filter/filter-visitor-generate-bytecode.c
b/src/lib/lttng-ctl/filter/filter-visitor-generate-bytecode.c
index 898072227775b2e568d5c7a90033e0403958753a..1cf7cb5c3cf0324048c7d360980564494eb1450e 100644
(file)
--- a/
src/lib/lttng-ctl/filter/filter-visitor-generate-bytecode.c
+++ b/
src/lib/lttng-ctl/filter/filter-visitor-generate-bytecode.c
@@
-222,7
+222,7
@@
int visit_node_load(struct filter_parser_ctx *ctx, struct ir_op *node)
if (!insn)
return -ENOMEM;
insn->op = FILTER_OP_LOAD_S64;
if (!insn)
return -ENOMEM;
insn->op = FILTER_OP_LOAD_S64;
-
*(int64_t *) insn->data = node->u.load.u.num
;
+
memcpy(insn->data, &node->u.load.u.num, sizeof(int64_t))
;
ret = bytecode_push(&ctx->bytecode, insn, 1, insn_len);
free(insn);
return ret;
ret = bytecode_push(&ctx->bytecode, insn, 1, insn_len);
free(insn);
return ret;
@@
-237,12
+237,13
@@
int visit_node_load(struct filter_parser_ctx *ctx, struct ir_op *node)
if (!insn)
return -ENOMEM;
insn->op = FILTER_OP_LOAD_DOUBLE;
if (!insn)
return -ENOMEM;
insn->op = FILTER_OP_LOAD_DOUBLE;
-
*(double *) insn->data = node->u.load.u.flt
;
+
memcpy(insn->data, &node->u.load.u.flt, sizeof(double))
;
ret = bytecode_push(&ctx->bytecode, insn, 1, insn_len);
free(insn);
return ret;
}
ret = bytecode_push(&ctx->bytecode, insn, 1, insn_len);
free(insn);
return ret;
}
- case IR_DATA_FIELD_REF:
+ case IR_DATA_FIELD_REF: /* fall-through */
+ case IR_DATA_GET_CONTEXT_REF:
{
struct load_op *insn;
uint32_t insn_len = sizeof(struct load_op)
{
struct load_op *insn;
uint32_t insn_len = sizeof(struct load_op)
@@
-254,7
+255,17
@@
int visit_node_load(struct filter_parser_ctx *ctx, struct ir_op *node)
insn = calloc(insn_len, 1);
if (!insn)
return -ENOMEM;
insn = calloc(insn_len, 1);
if (!insn)
return -ENOMEM;
- insn->op = FILTER_OP_LOAD_FIELD_REF;
+ switch(node->data_type) {
+ case IR_DATA_FIELD_REF:
+ insn->op = FILTER_OP_LOAD_FIELD_REF;
+ break;
+ case IR_DATA_GET_CONTEXT_REF:
+ insn->op = FILTER_OP_GET_CONTEXT_REF;
+ break;
+ default:
+ free(insn);
+ return -EINVAL;
+ }
ref_offset.offset = (uint16_t) -1U;
memcpy(insn->data, &ref_offset, sizeof(ref_offset));
/* reloc_offset points to struct load_op */
ref_offset.offset = (uint16_t) -1U;
memcpy(insn->data, &ref_offset, sizeof(ref_offset));
/* reloc_offset points to struct load_op */
@@
-414,11
+425,13
@@
int visit_node_logical(struct filter_parser_ctx *ctx, struct ir_op *node)
if (ret)
return ret;
/* Cast to s64 if float or field ref */
if (ret)
return ret;
/* Cast to s64 if float or field ref */
- if (node->u.binary.left->data_type == IR_DATA_FIELD_REF
+ if ((node->u.binary.left->data_type == IR_DATA_FIELD_REF
+ || node->u.binary.left->data_type == IR_DATA_GET_CONTEXT_REF)
|| node->u.binary.left->data_type == IR_DATA_FLOAT) {
struct cast_op cast_insn;
|| node->u.binary.left->data_type == IR_DATA_FLOAT) {
struct cast_op cast_insn;
- if (node->u.binary.left->data_type == IR_DATA_FIELD_REF) {
+ if (node->u.binary.left->data_type == IR_DATA_FIELD_REF
+ || node->u.binary.left->data_type == IR_DATA_GET_CONTEXT_REF) {
cast_insn.op = FILTER_OP_CAST_TO_S64;
} else {
cast_insn.op = FILTER_OP_CAST_DOUBLE_TO_S64;
cast_insn.op = FILTER_OP_CAST_TO_S64;
} else {
cast_insn.op = FILTER_OP_CAST_DOUBLE_TO_S64;
@@
-451,11
+464,13
@@
int visit_node_logical(struct filter_parser_ctx *ctx, struct ir_op *node)
if (ret)
return ret;
/* Cast to s64 if float or field ref */
if (ret)
return ret;
/* Cast to s64 if float or field ref */
- if (node->u.binary.right->data_type == IR_DATA_FIELD_REF
+ if ((node->u.binary.right->data_type == IR_DATA_FIELD_REF
+ || node->u.binary.right->data_type == IR_DATA_GET_CONTEXT_REF)
|| node->u.binary.right->data_type == IR_DATA_FLOAT) {
struct cast_op cast_insn;
|| node->u.binary.right->data_type == IR_DATA_FLOAT) {
struct cast_op cast_insn;
- if (node->u.binary.right->data_type == IR_DATA_FIELD_REF) {
+ if (node->u.binary.right->data_type == IR_DATA_FIELD_REF
+ || node->u.binary.right->data_type == IR_DATA_GET_CONTEXT_REF) {
cast_insn.op = FILTER_OP_CAST_TO_S64;
} else {
cast_insn.op = FILTER_OP_CAST_DOUBLE_TO_S64;
cast_insn.op = FILTER_OP_CAST_TO_S64;
} else {
cast_insn.op = FILTER_OP_CAST_DOUBLE_TO_S64;
@@
-505,10
+520,19
@@
int recursive_visit_gen_bytecode(struct filter_parser_ctx *ctx,
LTTNG_HIDDEN
void filter_bytecode_free(struct filter_parser_ctx *ctx)
{
LTTNG_HIDDEN
void filter_bytecode_free(struct filter_parser_ctx *ctx)
{
- free(ctx->bytecode);
- ctx->bytecode = NULL;
- free(ctx->bytecode_reloc);
- ctx->bytecode_reloc = NULL;
+ if (!ctx) {
+ return;
+ }
+
+ if (ctx->bytecode) {
+ free(ctx->bytecode);
+ ctx->bytecode = NULL;
+ }
+
+ if (ctx->bytecode_reloc) {
+ free(ctx->bytecode_reloc);
+ ctx->bytecode_reloc = NULL;
+ }
}
LTTNG_HIDDEN
}
LTTNG_HIDDEN
This page took
0.025999 seconds
and
4
git commands to generate.