Fix bad-free in pcache callbacks using pmem-allocated values

pcache_add callers in ppagecache.c and pfstasks.c registered bare
free() as the eviction callback, but the stored values were allocated
with pmem_malloc/pmem_malloc_array which prepends a 16-byte header.
After the pcache_clean fix that now correctly invokes callbacks, these
bad-frees became fatal. Replace with static helpers that call pmem_free
with the correct subsystem.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
Levi Neely 2026-03-10 13:40:40 +01:00
parent 8916acb4f6
commit 886abae1ab
2 changed files with 10 additions and 2 deletions

View File

@ -1116,6 +1116,10 @@ int pfs_task_unlink(psync_fsfolderid_t folderid, const char *name) {
return 0;
}
static void free_file_history_record(void *ptr) {
pmem_free(PMEM_SUBSYS_SYNC, ptr);
}
static void add_history_record(psync_fileid_t fileid, psync_folderid_t folderid,
const char *name) {
file_history_record *rec;
@ -1131,7 +1135,7 @@ static void add_history_record(psync_fileid_t fileid, psync_folderid_t folderid,
return;
rec->folderid = folderid;
memcpy(rec->name, name, len);
pcache_add(key, rec, PSYNC_FS_FILE_LOC_HIST_SEC, free, 1);
pcache_add(key, rec, PSYNC_FS_FILE_LOC_HIST_SEC, free_file_history_record, 1);
}
int pfs_task_rename_file(psync_fsfileid_t fileid,

View File

@ -509,6 +509,10 @@ static int wait_shared_api() {
return ret;
}
static void free_binresult_cache(void *ptr) {
pmem_free(PMEM_SUBSYS_CACHE, ptr);
}
static void set_urls(psync_urls_t *urls, binresult *res) {
pthread_mutex_lock(&url_cache_mutex);
if (res) {
@ -737,7 +741,7 @@ static void release_urls(psync_urls_t *urls) {
etime = papi_find_result2(urls->urls, "expires", PARAM_NUM)->num;
if (etime > ctime + 3600) {
psync_get_string_id(buff, "URLS", urls->hash);
pcache_add(buff, urls->urls, etime - ctime - 3600, free, 2);
pcache_add(buff, urls->urls, etime - ctime - 3600, free_binresult_cache, 2);
urls->urls = NULL;
}
}