Replace malloc(nmemb*size) with pmem_calloc_safe in high-risk sites

This commit is contained in:
Levi Neely 2026-03-08 14:49:06 +01:00
parent 4e3bb5a0c9
commit 09a17d204b
3 changed files with 67 additions and 15 deletions

View File

@ -39,6 +39,7 @@
#include "psynclib.h"
#include "ptimer.h"
#include "pdbg.h"
#include "pmem.h"
/*
commented definitions are unused, but kept because they may be
@ -313,7 +314,7 @@ static binresult *do_parse_result(unsigned char **restrict indata,
arr = NULL;
cnt = 0;
alloc = 128;
arr = (binresult **)malloc(sizeof(binresult *) * alloc);
arr = (binresult **)pmem_calloc_safe(alloc, sizeof(binresult *));
if (!arr)
return NULL;
while (**indata != RPARAM_END) {
@ -346,7 +347,7 @@ static binresult *do_parse_result(unsigned char **restrict indata,
arr = NULL;
cnt = 0;
alloc = 32;
arr = (struct _hashpair *)malloc(sizeof(struct _hashpair) * alloc);
arr = (struct _hashpair *)pmem_calloc_safe(alloc, sizeof(struct _hashpair));
if (!arr)
return NULL;
while (**indata != RPARAM_END) {
@ -398,10 +399,10 @@ static binresult *parse_result(unsigned char *data, size_t datalen) {
retlen = calc_ret_len(&datac, &datalenc, &strcnt);
if (retlen == -1)
return NULL;
datac = malloc(sizeof(unsigned char) * retlen);
datac = pmem_calloc_safe(retlen, sizeof(unsigned char));
if (!datac)
return NULL;
strings = malloc(sizeof(binresult *) * strcnt);
strings = pmem_calloc_safe(strcnt, sizeof(binresult *));
if (!strings) {
free(datac);
return NULL;

View File

@ -32,6 +32,7 @@
#include "pnetlibs.h"
#include "psys.h"
#include "psql.h"
#include "pmem.h"
#include <stdio.h>
@ -103,12 +104,18 @@ int do_psync_account_stopshare(psync_shareid_t usershareids[], int nusershareid,
if (unlikely(numparam == 1))
return -3;
t = (binparam *)malloc(numparam * sizeof(binparam));
t = (binparam *)pmem_calloc_safe(numparam, sizeof(binparam));
if (!t)
return -1;
init_param_str(t, "auth", psync_my_auth);
if (nusershareid) {
ids1 = (char *)malloc(nusershareid * FOLDERID_ENTRY_SIZE);
ids1 = (char *)pmem_calloc_safe(nusershareid, FOLDERID_ENTRY_SIZE);
if (!ids1) {
free(t);
return -1;
}
idsp = ids1;
for (i = 0; i < nusershareid; ++i) {
k = sprintf(idsp, "%lld", (long long)usershareids[i]);
@ -124,7 +131,13 @@ int do_psync_account_stopshare(psync_shareid_t usershareids[], int nusershareid,
}
if (nteamshareid) {
ids2 = (char *)malloc(nteamshareid * FOLDERID_ENTRY_SIZE);
ids2 = (char *)pmem_calloc_safe(nteamshareid, FOLDERID_ENTRY_SIZE);
if (!ids2) {
if (nusershareid)
free(ids1);
free(t);
return -1;
}
idsp = ids2;
for (i = 0; i < nteamshareid; ++i) {
k = sprintf(idsp, "%lld", (long long)teamshareids[i]);
@ -209,14 +222,25 @@ int do_psync_account_modifyshare(psync_shareid_t usrshrids[], uint32_t uperms[],
if (unlikely(numparam == 1))
return -3;
t = (binparam *)malloc(numparam * sizeof(binparam));
t = (binparam *)pmem_calloc_safe(numparam, sizeof(binparam));
if (!t)
return -1;
init_param_str(t, "auth", psync_my_auth);
if (nushid) {
ids1 = (char *)malloc(nushid * FOLDERID_ENTRY_SIZE);
ids1 = (char *)pmem_calloc_safe(nushid, FOLDERID_ENTRY_SIZE);
if (!ids1) {
free(t);
return -1;
}
idsp = ids1;
perms1 = (char *)malloc(nushid * FOLDERID_ENTRY_SIZE);
perms1 = (char *)pmem_calloc_safe(nushid, FOLDERID_ENTRY_SIZE);
if (!perms1) {
free(ids1);
free(t);
return -1;
}
permsp = perms1;
for (i = 0; i < nushid; ++i) {
k = sprintf(idsp, "%lld", (long long)usrshrids[i]);
@ -241,9 +265,26 @@ int do_psync_account_modifyshare(psync_shareid_t usrshrids[], uint32_t uperms[],
}
if (ntmshid) {
ids2 = (char *)malloc(ntmshid * FOLDERID_ENTRY_SIZE);
ids2 = (char *)pmem_calloc_safe(ntmshid, FOLDERID_ENTRY_SIZE);
if (!ids2) {
if (nushid) {
free(perms1);
free(ids1);
}
free(t);
return -1;
}
idsp = ids2;
perms2 = (char *)malloc(ntmshid * FOLDERID_ENTRY_SIZE);
perms2 = (char *)pmem_calloc_safe(ntmshid, FOLDERID_ENTRY_SIZE);
if (!perms2) {
free(ids2);
if (nushid) {
free(perms1);
free(ids1);
}
free(t);
return -1;
}
permsp = perms2;
for (i = 0; i < ntmshid; ++i) {

View File

@ -50,6 +50,7 @@
#include "psettings.h"
#include "psql.h"
#include "ptools.h"
#include "pmem.h"
#define PTOOLS_MAX_PARAMS 30
@ -135,7 +136,10 @@ int ptools_create_backend_event(const char *binapi, const char *category,
paramsLocal[5] = (binparam)PAPI_NUM(EPARAM_TIME, etime);
if (pCnt > 0) {
keyParams = (char *)malloc(258 * pCnt);
keyParams = (char *)pmem_calloc_safe(pCnt, 258);
if (!keyParams) {
return -1;
}
keyParams[0] = 0;
for (i = 0; i < pCnt; i++) {
@ -371,7 +375,10 @@ int ptools_backend_call(const char *binapi, const char *wsPath,
if (strlen(payloadName) > 0) {
payload = (binresult *)papi_find_result2(res, payloadName, PARAM_HASH);
*resData = (binresult *)malloc(payload->length * sizeof(binresult));
*resData = (binresult *)pmem_calloc_safe(payload->length, sizeof(binresult));
if (!*resData) {
return -1;
}
memcpy(*resData, payload, (payload->length * sizeof(binresult)));
}
}
@ -450,7 +457,10 @@ void ptools_send_psyncs_event(const char *binapi, const char *auth) {
int intRes;
int syncCnt = 0;
errMsg = (char *)malloc(1024 * sizeof(char));
errMsg = (char *)pmem_calloc_safe(1024, sizeof(char));
if (!errMsg) {
return;
}
errMsg[0] = 0;
time(&rawtime);