From: Mathieu Desnoyers Date: Tue, 11 Jan 2022 18:59:15 +0000 (-0500) Subject: Fix: lttng-ctl: lttng_list_sessions: initialize out_sessions to NULL when returning 0 X-Git-Url: https://git.lttng.org./?a=commitdiff_plain;h=985aea182b618c85c51651f224abedfe367c75ee;p=lttng-tools.git Fix: lttng-ctl: lttng_list_sessions: initialize out_sessions to NULL when returning 0 Observed issue ============== Users of lttng-ctl API's lttng_list_sessions observe application crash when freeing the *out_sessions output value when lttng_list_sessions returns 0. Cause ===== The implementation does not set *out_sessions to NULL when lttng_ctl_ask_sessiond() sets the sessions variable to NULL. This causes the user application to attempt to free(3) an uninitialized pointer. Solution ======== Initialize out_sessions to NULL before invoking lttng_ctl_ask_sessiond(), so it is initialized when lttng_list_sessions returns 0, thus allowing *out_sessions to be subsequently freed. A free(3) on a NULL pointer is a no-op. Known drawbacks =============== None. History ======= This was introduced by those two commits: b178f53e90 ("Generate session name and default output on sessiond's end") 27ea4ba825 ("Fix: error when listing sessions with no session") This is a regression present in the stable-2.11, stable-2.12, stable-2.13, and master branches. Signed-off-by: Mathieu Desnoyers Signed-off-by: Jérémie Galarneau Change-Id: I34125d708a32674d79b831e5004c48321ebd711e --- diff --git a/src/lib/lttng-ctl/lttng-ctl.cpp b/src/lib/lttng-ctl/lttng-ctl.cpp index 63841df40..b7eaee260 100644 --- a/src/lib/lttng-ctl/lttng-ctl.cpp +++ b/src/lib/lttng-ctl/lttng-ctl.cpp @@ -2102,6 +2102,12 @@ int lttng_list_sessions(struct lttng_session **out_sessions) memset(&lsm, 0, sizeof(lsm)); lsm.cmd_type = LTTNG_LIST_SESSIONS; + /* + * Initialize out_sessions to NULL so it is initialized when + * lttng_list_sessions returns 0, thus allowing *out_sessions to + * be subsequently freed. + */ + *out_sessions = NULL; ret = lttng_ctl_ask_sessiond(&lsm, (void**) &sessions); if (ret <= 0) { goto end; @@ -2114,7 +2120,6 @@ int lttng_list_sessions(struct lttng_session **out_sessions) if (ret % session_size) { ret = -LTTNG_ERR_UNK; free(sessions); - *out_sessions = NULL; goto end; } session_count = (size_t) ret / session_size;