Bug fixes: heap-use-after-free in pmem_realloc, auto-create FUSE mountpoint (#374)

* Fix heap-use-after-free in pmem_realloc

realloc() frees the old block when it moves the allocation. hdr->subsystem
was read after the realloc call, from potentially freed memory. Save it to
old_subsystem before the call, matching the existing pattern for old_size.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

* Auto-create missing FUSE mountpoint directory

Previously the mountpoint had to exist before starting pcloudcc; if it
was missing the error was only visible in the debug log. Restore the
prior behavior of automatically creating the directory when it does not
exist, logging a notice when creation succeeds or a critical error if
it fails.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>

---------

Co-authored-by: Levi Neely <lkn@darkstar.example.net>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Levi Neely 2026-03-10 13:01:53 +01:00 committed by GitHub
parent 0c0c6855c1
commit 478c1a85a9
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
2 changed files with 12 additions and 5 deletions

View File

@ -29,6 +29,8 @@
*/
#include <errno.h>
#include <sys/stat.h>
#include <sys/types.h>
#include <fuse.h>
#include <pthread.h>
#include <stdint.h>
@ -3516,9 +3518,13 @@ static char *psync_fuse_get_mountpoint() {
"Mount point %s has a stale FUSE mount (Transport endpoint is not connected). "
"Please unmount it first with: fusermount -u %s", mp, mp);
} else if (stat_errno == ENOENT) {
if (mkdir(mp, 0755) == 0) {
pdbg_logf(D_NOTICE, "Mount point %s did not exist, created it.", mp);
return mp;
}
pdbg_logf(D_CRITICAL,
"Mount point %s does not exist. "
"Please create the directory first with: mkdir -p %s", mp, mp);
"Mount point %s does not exist and could not be created: %s",
mp, strerror(errno));
} else {
pdbg_logf(D_CRITICAL,
"Cannot access mount point %s (errno=%d: %s). "

View File

@ -118,13 +118,14 @@ void *pmem_realloc(pmem_subsystem_t subsystem, void *ptr, size_t size) {
hdr = ((pmem_header_t *)ptr) - 1;
old_size = hdr->size;
pmem_subsystem_t old_subsystem = hdr->subsystem;
new_hdr = (pmem_header_t *)realloc(hdr, total_size);
if (!new_hdr) {
return NULL;
}
__atomic_sub_fetch(&subsystem_stats[hdr->subsystem], old_size, __ATOMIC_RELAXED);
__atomic_sub_fetch(&subsystem_stats[old_subsystem], old_size, __ATOMIC_RELAXED);
__atomic_add_fetch(&subsystem_stats[subsystem], size, __ATOMIC_RELAXED);
new_hdr->size = size;