]> git.ipfire.org Git - thirdparty/nftables.git/commitdiff
parser_bison: fix memory leaks on hookspec error processing
authorFlorian Westphal <fw@strlen.de>
Wed, 13 Dec 2023 10:18:06 +0000 (11:18 +0100)
committerFlorian Westphal <fw@strlen.de>
Wed, 13 Dec 2023 11:08:19 +0000 (12:08 +0100)
prio_spec may contain an embedded expression, release it.
We also need to release the device expr and the hook string.

Signed-off-by: Florian Westphal <fw@strlen.de>
src/parser_bison.y
tests/shell/testcases/bogons/nft-f/memleak_on_hookspec_error [new file with mode: 0644]

index c69252fee7fb63b8b7335bf07278b3dba7e42eca..571eddf137aae8283a5eca97fe0c648073fc348f 100644 (file)
@@ -708,6 +708,8 @@ int nft_lex(void *, void *, void *);
 %type <val>                    family_spec family_spec_explicit
 %type <val32>                  int_num chain_policy
 %type <prio_spec>              extended_prio_spec prio_spec
+%destructor { expr_free($$.expr); } extended_prio_spec prio_spec
+
 %type <string>                 extended_prio_name quota_unit   basehook_device_name
 %destructor { free_const($$); }        extended_prio_name quota_unit   basehook_device_name
 
@@ -2615,6 +2617,9 @@ hook_spec         :       TYPE            close_scope_type        STRING          HOOK            STRING          dev_spec        prio_spec
                                        erec_queue(error(&@3, "unknown chain type"),
                                                   state->msgs);
                                        free_const($3);
+                                       free_const($5);
+                                       expr_free($6);
+                                       expr_free($7.expr);
                                        YYERROR;
                                }
                                $<chain>0->type.loc = @3;
@@ -2628,6 +2633,8 @@ hook_spec         :       TYPE            close_scope_type        STRING          HOOK            STRING          dev_spec        prio_spec
                                        erec_queue(error(&@5, "unknown chain hook"),
                                                   state->msgs);
                                        free_const($5);
+                                       expr_free($6);
+                                       expr_free($7.expr);
                                        YYERROR;
                                }
                                free_const($5);
diff --git a/tests/shell/testcases/bogons/nft-f/memleak_on_hookspec_error b/tests/shell/testcases/bogons/nft-f/memleak_on_hookspec_error
new file mode 100644 (file)
index 0000000..6f52658
--- /dev/null
@@ -0,0 +1,21 @@
+table ip filter {
+       ct expectation ctexpect {
+               protocol tcp
+               size 12
+               l3proto ip
+       } . inet_proto : mark
+               flags interval,timeout
+       }
+
+       chain output {
+               type gilter hook output priori
+
+       chain c {
+               cttable inet filter {
+       map test {
+               type mark . inet_service . inet_proto : mark
+               flags interval,timeout
+       }
+
+       chain output {
+               type gilter hook output priority filuer; policy 
\ No newline at end of file