]> git.ipfire.org Git - thirdparty/libnftnl.git/commitdiff
chain: fix segfault in 'device' XML parsing
authorArturo Borrero <arturo.borrero.glez@gmail.com>
Tue, 13 Oct 2015 07:39:10 +0000 (09:39 +0200)
committerPablo Neira Ayuso <pablo@netfilter.org>
Tue, 13 Oct 2015 10:06:29 +0000 (12:06 +0200)
Reported by valgrind:
[...]
==14065== Process terminating with default action of signal 11 (SIGSEGV)
==14065==  Access not within mapped region at address 0x0
==14065==    at 0x4C2C022: strlen (vg_replace_strmem.c:454)
==14065==    by 0x4E41A93: nftnl_chain_set_str (chain.c:259)
==14065==    by 0x4E427F7: nftnl_mxml_chain_parse (chain.c:770)
==14065==    by 0x4E48F96: nftnl_ruleset_parse_chains (ruleset.c:314)
==14065==    by 0x4E4959A: nftnl_ruleset_xml_parse_ruleset (ruleset.c:625)
==14065==    by 0x4E4959A: nftnl_ruleset_xml_parse_cmd (ruleset.c:668)
==14065==    by 0x4E4959A: nftnl_ruleset_xml_parse (ruleset.c:706)
==14065==    by 0x4E4959A: nftnl_ruleset_do_parse (ruleset.c:734)
==14065==    by 0x4013C9: test_xml (nft-parsing-test.c:166)
==14065==    by 0x4016F4: execute_test (nft-parsing-test.c:214)
==14065==    by 0x400EBA: main (nft-parsing-test.c:330)
[...]

While at it, fix a bit the coding style.

Signed-off-by: Arturo Borrero Gonzalez <arturo.borrero.glez@gmail.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
src/chain.c

index 8a8e8b8da49bb6221654171013bae7ed74d21fa5..2b44a3131a145478b7f1ded80999535658085576 100644 (file)
@@ -763,10 +763,10 @@ int nftnl_mxml_chain_parse(mxml_node_t *tree, struct nftnl_chain *c,
                        nftnl_chain_set_u32(c, NFTNL_CHAIN_POLICY,
                                               policy);
                }
-               dev = nftnl_mxml_str_parse(tree, "device", MXML_DESCEND_FIRST,
-                                        NFTNL_XML_MAND, err);
 
-               if (table != NULL)
+               dev = nftnl_mxml_str_parse(tree, "device", MXML_DESCEND_FIRST,
+                                          NFTNL_XML_MAND, err);
+               if (dev != NULL)
                        nftnl_chain_set_str(c, NFTNL_CHAIN_DEV, dev);
        }