Commit 922d42b
json: Fix a memleak in parse_pair()
In qobject_type(), NULL is returned when the 'QObject' returned from parse_value() is not of QString type,
and this 'QObject' memory will leaked.
So we need to first cache the 'QObject' returned from parse_value(), and finally
free 'QObject' memory at the end of the function.
Also, we add a testcast about invalid dict key.
The memleak stack is as follows:
Direct leak of 32 byte(s) in 1 object(s) allocated from:
#0 0xfffe4b3c34fb in __interceptor_malloc (/lib64/libasan.so.4+0xd34fb)
#1 0xfffe4ae48aa3 in g_malloc (/lib64/libglib-2.0.so.0+0x58aa3)
#2 0xaaab3557d9f7 in qnum_from_int qemu/qobject/qnum.c:25
qemu#3 0xaaab35584d23 in parse_literal qemu/qobject/json-parser.c:511
qemu#4 0xaaab35584d23 in parse_value qemu/qobject/json-parser.c:554
qemu#5 0xaaab35583d77 in parse_pair qemu/qobject/json-parser.c:270
qemu#6 0xaaab355845db in parse_object qemu/qobject/json-parser.c:327
qemu#7 0xaaab355845db in parse_value qemu/qobject/json-parser.c:546
qemu#8 0xaaab35585b1b in json_parser_parse qemu/qobject/json-parser.c:580
qemu#9 0xaaab35583703 in json_message_process_token qemu/qobject/json-streamer.c:92
qemu#10 0xaaab355ddccf in json_lexer_feed_char qemu/qobject/json-lexer.c:313
qemu#11 0xaaab355de0eb in json_lexer_feed qemu/qobject/json-lexer.c:350
qemu#12 0xaaab354aff67 in tcp_chr_read qemu/chardev/char-socket.c:525
qemu#13 0xfffe4ae429db in g_main_context_dispatch (/lib64/libglib-2.0.so.0+0x529db)
qemu#14 0xfffe4ae42d8f (/lib64/libglib-2.0.so.0+0x52d8f)
qemu#15 0xfffe4ae430df in g_main_loop_run (/lib64/libglib-2.0.so.0+0x530df)
qemu#16 0xaaab34d70bff in iothread_run qemu/iothread.c:82
qemu#17 0xaaab3559d71b in qemu_thread_start qemu/util/qemu-thread-posix.c:519
Fixes: 532fb53 ("qapi: Make more of qobject_to()")
Reported-by: Euler Robot <euler.robot@huawei.com>
Signed-off-by: Alex Chen <alex.chen@huawei.com>
Signed-off-by: Chen Qun <kuhn.chenqun@huawei.com>
Signed-off-by: Markus Armbruster <armbru@redhat.com>
Message-Id: <20201113145525.85151-1-alex.chen@huawei.com>
[Commit message tweaked]1 parent 1c7ab09 commit 922d42b
2 files changed
+15
-6
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
257 | 257 | | |
258 | 258 | | |
259 | 259 | | |
| 260 | + | |
| 261 | + | |
260 | 262 | | |
261 | | - | |
262 | 263 | | |
263 | 264 | | |
264 | 265 | | |
| |||
267 | 268 | | |
268 | 269 | | |
269 | 270 | | |
270 | | - | |
| 271 | + | |
| 272 | + | |
271 | 273 | | |
272 | 274 | | |
273 | 275 | | |
| |||
297 | 299 | | |
298 | 300 | | |
299 | 301 | | |
300 | | - | |
301 | | - | |
| 302 | + | |
302 | 303 | | |
303 | 304 | | |
304 | 305 | | |
305 | | - | |
306 | | - | |
| 306 | + | |
307 | 307 | | |
308 | 308 | | |
309 | 309 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1415 | 1415 | | |
1416 | 1416 | | |
1417 | 1417 | | |
| 1418 | + | |
| 1419 | + | |
| 1420 | + | |
| 1421 | + | |
| 1422 | + | |
| 1423 | + | |
| 1424 | + | |
| 1425 | + | |
1418 | 1426 | | |
1419 | 1427 | | |
1420 | 1428 | | |
| |||
1500 | 1508 | | |
1501 | 1509 | | |
1502 | 1510 | | |
| 1511 | + | |
1503 | 1512 | | |
1504 | 1513 | | |
1505 | 1514 | | |
| |||
0 commit comments