diff options
author | Jeremy Allison <jra@samba.org> | 2010-06-08 21:20:07 -0700 |
---|---|---|
committer | Jeremy Allison <jra@samba.org> | 2010-06-08 21:20:07 -0700 |
commit | 34a8324409961c4837e83c714fb1a285f238312d (patch) | |
tree | d6372f70e6fdd55728e52c58e71c83820a727b71 /source3/smbd/smb2_glue.c | |
parent | 0c5d0e1c37daf5b802e990bde8469934ae33f6cc (diff) | |
download | samba-34a8324409961c4837e83c714fb1a285f238312d.tar.gz samba-34a8324409961c4837e83c714fb1a285f238312d.tar.bz2 samba-34a8324409961c4837e83c714fb1a285f238312d.zip |
Fix a valgrind error found by SMB2-COMPOUND test.
If a file is closed we must also NULL out all chained_fsp
pointers when the fsp is freed to prevent invalid pointer
access.
Jeremy.
Diffstat (limited to 'source3/smbd/smb2_glue.c')
-rw-r--r-- | source3/smbd/smb2_glue.c | 20 |
1 files changed, 20 insertions, 0 deletions
diff --git a/source3/smbd/smb2_glue.c b/source3/smbd/smb2_glue.c index d6252ef349..8b595affe0 100644 --- a/source3/smbd/smb2_glue.c +++ b/source3/smbd/smb2_glue.c @@ -49,6 +49,26 @@ struct smb_request *smbd_smb2_fake_smb_request(struct smbd_smb2_request *req) smbreq->mid = BVAL(inhdr, SMB2_HDR_MESSAGE_ID); smbreq->chain_fsp = req->compat_chain_fsp; smbreq->smb2req = req; + req->smb1req = smbreq; return smbreq; } + +/********************************************************* + Called from file_free() to remove any chained fsp pointers. +*********************************************************/ + +void remove_smb2_chained_fsp(files_struct *fsp) +{ + struct smbd_server_connection *sconn = smbd_server_conn; + struct smbd_smb2_request *smb2req; + + for (smb2req = sconn->smb2.requests; smb2req; smb2req = smb2req->next) { + if (smb2req->compat_chain_fsp == fsp) { + smb2req->compat_chain_fsp = NULL; + } + if (smb2req->smb1req && smb2req->smb1req->chain_fsp == fsp) { + smb2req->smb1req->chain_fsp = NULL; + } + } +} |