X Tutup
The Wayback Machine - https://web.archive.org/web/20220418074126/https://github.com/nodejs/node/pull/42663
Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

doc: fix coverity report #42663

Closed
wants to merge 1 commit into from
Closed

doc: fix coverity report #42663

wants to merge 1 commit into from

Conversation

Copy link
Member

@mhdawson mhdawson commented Apr 8, 2022

Fix coverity report about possibly dereferencing
a null. If the the buffer.data != nullptr
check indicates that the buffer was null, then
relying on the value in buffer_size is no longer
safe. The later call to uv_pipe_getpeername
depends on the buffer_size being correct to
avoid deferencing buffer.data if it is not
big enough.

Signed-off-by: Michael Dawson mdawson@devrus.com

Fix coverity report about possibly dereferencing
a null. If the the buffer.data != nullptr
check indicates that the buffer was null, then
relying on the value in buffer_size is no longer
safe. The later call to uv_pipe_getpeername
depends on the buffer_size being correct to
avoid deferencing buffer.data if it is not
big enough.

Signed-off-by: Michael Dawson <mdawson@devrus.com>
@nodejs-github-bot nodejs-github-bot added c++ needs-ci report labels Apr 8, 2022
@mhdawson
Copy link
Member Author

@mhdawson mhdawson commented Apr 8, 2022

Report from Coverity

 // First call to get required buffer size.
 93  rc = uv_pipe_getsockname(&handle->pipe, buffer.data, &buffer_size);
   	1. Condition rc == UV_ENOBUFS, taking true branch.
 94  if (rc == UV_ENOBUFS) {
 95    buffer = MallocedBuffer<char>(buffer_size);
   	2. Condition buffer.data != NULL, taking false branch.
   	3. var_compare_op: Comparing buffer.data to null implies that buffer.data might be null.
 96    if (buffer.data != nullptr) {
 97      rc = uv_pipe_getsockname(&handle->pipe, buffer.data, &buffer_size);
 98    }
 99  }
   	4. Condition rc == 0, taking false branch.
100  if (rc == 0 && buffer_size != 0 && buffer.data != nullptr) {
101    writer->json_keyvalue("localEndpoint", buffer.data);
102  } else {
103    writer->json_keyvalue("localEndpoint", null);
104  }
105
106  // First call to get required buffer size.
   	
CID 239713 (#1 of 1): Dereference after null check (FORWARD_NULL)
5. var_deref_model: Passing null pointer buffer.data to uv_pipe_getpeername, which dereferences it.
107  rc = uv_pipe_getpeername(&handle->pipe, buffer.data, &buffer_size);
108  if (rc == UV_ENOBUFS) {
109    buffer = MallocedBuffer<char>(buffer_size);
110    if (buffer.data != nullptr) {
111      rc = uv_pipe_getpeername(&handle->pipe, buffer.data, &buffer_size);
112    }
113  }

Copy link
Member

@RaisinTen RaisinTen left a comment

This doesn't look like the correct fix because buffer.data can't be null here. Also, should we use src as the subsystem instead of doc?

src/node_report_utils.cc Show resolved Hide resolved
Copy link
Member

@RaisinTen RaisinTen left a comment

LGTM

src/node_report_utils.cc Show resolved Hide resolved
@mhdawson mhdawson added the request-ci label Apr 12, 2022
@github-actions github-actions bot removed the request-ci label Apr 12, 2022
@nodejs-github-bot
Copy link
Contributor

@nodejs-github-bot nodejs-github-bot commented Apr 12, 2022

@RaisinTen
Copy link
Member

@RaisinTen RaisinTen commented Apr 13, 2022

@mhdawson wdyt about?

Also, should we use src as the subsystem instead of doc?

Are you planning to change it while landing this?

@mhdawson
Copy link
Member Author

@mhdawson mhdawson commented Apr 13, 2022

Also, should we use src as the subsystem instead of doc?

Good point, I must have had doc on my mind, will change while landing.

@mhdawson
Copy link
Member Author

@mhdawson mhdawson commented Apr 13, 2022

CI run looks to be complete (https://ci.nodejs.org/job/node-test-pull-request/43464/) even though what's shown on the PR shows a job still running. Will land.

mhdawson added a commit that referenced this issue Apr 13, 2022
Fix coverity report about possibly dereferencing
a null. If the the buffer.data != nullptr
check indicates that the buffer was null, then
relying on the value in buffer_size is no longer
safe. The later call to uv_pipe_getpeername
depends on the buffer_size being correct to
avoid deferencing buffer.data if it is not
big enough.

Signed-off-by: Michael Dawson <mdawson@devrus.com>

PR-URL: #42663
Reviewed-By: Darshan Sen <raisinten@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
@mhdawson
Copy link
Member Author

@mhdawson mhdawson commented Apr 13, 2022

Landed in 3026ca0

@mhdawson mhdawson closed this Apr 13, 2022
vmoroz added a commit to vmoroz/node that referenced this issue Apr 13, 2022
Fix coverity report about possibly dereferencing
a null. If the the buffer.data != nullptr
check indicates that the buffer was null, then
relying on the value in buffer_size is no longer
safe. The later call to uv_pipe_getpeername
depends on the buffer_size being correct to
avoid deferencing buffer.data if it is not
big enough.

Signed-off-by: Michael Dawson <mdawson@devrus.com>

PR-URL: nodejs#42663
Reviewed-By: Darshan Sen <raisinten@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
c++ needs-ci report
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants
X Tutup