diff options
| author | Even Rouault <even.rouault@spatialys.com> | 2017-05-30 12:14:26 +0200 |
|---|---|---|
| committer | Even Rouault <even.rouault@spatialys.com> | 2017-05-30 12:14:26 +0200 |
| commit | a395e6e244e04dd09284e24eb1ca3ff2a7c9f37f (patch) | |
| tree | ba43adeeac721f4b86f2b1842ee74a534a9a00ab | |
| parent | 6bb6184a84f136f1686d51d43bfc04065e329ae5 (diff) | |
| download | PROJ-a395e6e244e04dd09284e24eb1ca3ff2a7c9f37f.tar.gz PROJ-a395e6e244e04dd09284e24eb1ca3ff2a7c9f37f.zip | |
catalog: memory leak and crashes related fixes
* pj_transform() crashes on a catalog that has no matching grid
* pj_free() and pj_gc_unloadall() badly interact. No longer try to free the
catalog object in pj_free(). That is the job of pj_gc_unloadall()
* Fix memory leaks in pj_gc_readcatalog() and pj_gc_unloadall()
Fixes https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=1923
Credit to OSS Fuzz.
| -rw-r--r-- | src/pj_gc_reader.c | 6 | ||||
| -rw-r--r-- | src/pj_gridcatalog.c | 11 | ||||
| -rw-r--r-- | src/pj_init.c | 7 | ||||
| -rw-r--r-- | test/fuzzers/standard_fuzzer.cpp | 7 |
4 files changed, 29 insertions, 2 deletions
diff --git a/src/pj_gc_reader.c b/src/pj_gc_reader.c index 4b54d05a..dc528b52 100644 --- a/src/pj_gc_reader.c +++ b/src/pj_gc_reader.c @@ -55,7 +55,10 @@ PJ_GridCatalog *pj_gc_readcatalog( projCtx ctx, const char *catalog_name ) catalog = (PJ_GridCatalog *) calloc(1,sizeof(PJ_GridCatalog)); if( !catalog ) + { + pj_ctx_fclose(ctx, fid); return NULL; + } catalog->catalog_name = strdup(catalog_name); @@ -82,12 +85,15 @@ PJ_GridCatalog *pj_gc_readcatalog( projCtx ctx, const char *catalog_name ) free( catalog->entries[i].definition ); free( catalog->catalog_name ); free( catalog ); + pj_ctx_fclose(ctx, fid); return NULL; } catalog->entries = new_entries; } } + pj_ctx_fclose(ctx, fid); + return catalog; } diff --git a/src/pj_gridcatalog.c b/src/pj_gridcatalog.c index 79543185..053de5e7 100644 --- a/src/pj_gridcatalog.c +++ b/src/pj_gridcatalog.c @@ -56,6 +56,7 @@ void pj_gc_unloadall( projCtx ctx ) free( catalog->entries[i].definition ); } free( catalog->entries ); + free( catalog->catalog_name ); free( catalog ); } } @@ -136,6 +137,11 @@ int pj_gc_apply_gridshift( PJ *defn, int inverse, 1, input, defn->datum_date, &(defn->last_after_region), &(defn->last_after_date)); + if( defn->last_after_grid == NULL ) + { + pj_ctx_set_errno( defn->ctx, -38 ); + return -38; + } } gi = defn->last_after_grid; assert( gi->child == NULL ); @@ -179,6 +185,11 @@ int pj_gc_apply_gridshift( PJ *defn, int inverse, 0, input, defn->datum_date, &(defn->last_before_region), &(defn->last_before_date)); + if( defn->last_before_grid == NULL ) + { + pj_ctx_set_errno( defn->ctx, -38 ); + return -38; + } } gi = defn->last_before_grid; diff --git a/src/pj_init.c b/src/pj_init.c index 764784f5..e3d99a8f 100644 --- a/src/pj_init.c +++ b/src/pj_init.c @@ -735,8 +735,11 @@ pj_free(PJ *P) { if( P->catalog_name != NULL ) pj_dalloc( P->catalog_name ); - if( P->catalog != NULL ) - pj_dalloc( P->catalog ); + /* We used to call pj_dalloc( P->catalog ), but this will leak */ + /* memory. The safe way to clear catalog and grid is to call */ + /* pj_gc_unloadall(pj_get_default_ctx()); and pj_deallocate_grids(); */ + /* TODO: we should probably have a public pj_cleanup() method to do all */ + /* that */ if( P->geod != NULL ) pj_dalloc( P->geod ); diff --git a/test/fuzzers/standard_fuzzer.cpp b/test/fuzzers/standard_fuzzer.cpp index de2e2aa8..5e69b80f 100644 --- a/test/fuzzers/standard_fuzzer.cpp +++ b/test/fuzzers/standard_fuzzer.cpp @@ -34,6 +34,7 @@ #include <sys/types.h> #include <unistd.h> +#include "projects.h" // For pj_gc_unloadall() #include "proj_api.h" /* Standalone build: @@ -96,6 +97,8 @@ int LLVMFuzzerTestOneInput(const uint8_t *buf, size_t len) { free(buf_dup); pj_free(pj_src); + pj_gc_unloadall(pj_get_default_ctx()); + pj_deallocate_grids(); return 0; } double x = 0, y = 0; @@ -104,6 +107,8 @@ int LLVMFuzzerTestOneInput(const uint8_t *buf, size_t len) free(buf_dup); pj_free(pj_src); pj_free(pj_dst); + pj_gc_unloadall(pj_get_default_ctx()); + pj_deallocate_grids(); return 0; } #ifdef STANDALONE @@ -115,6 +120,8 @@ int LLVMFuzzerTestOneInput(const uint8_t *buf, size_t len) free(buf_dup); pj_free(pj_src); pj_free(pj_dst); + pj_gc_unloadall(pj_get_default_ctx()); + pj_deallocate_grids(); return 0; } |
