diff options
| author | Alex Crichton <alex@alexcrichton.com> | 2016-11-10 08:00:22 -0800 |
|---|---|---|
| committer | Patrick Steinhardt <ps@pks.im> | 2016-11-11 11:22:15 +0100 |
| commit | 5ca75fd52c36f63fe9b1218e79953411d4435a9d (patch) | |
| tree | 9f13b1e0537853d53b35c1e8e3136153db373e4e /src/commit.h | |
| parent | 5fe5557e8a8d3fd6a4617c2d8c863c1f62848020 (diff) | |
| download | libgit2-5ca75fd52c36f63fe9b1218e79953411d4435a9d.tar.gz | |
curl_stream: check for -1 after CURLINFO_LASTSOCKET
We're recently trying to upgrade to the current master of libgit2
in Cargo but we're unfortunately hitting a segfault in one of our
tests. This particular test is just a small smoke test that https
works (e.g. it's configured in libgit2). It attempts to clone
from a URL which simply immediately drops connections after
they're accepted (e.g. terminate abnormally). We expect to see a
standard error from libgit2 but unfortunately we're seeing a
segfault.
This segfault is happening inside of the `wait_for` function of
`curl_stream.c` at the line `FD_SET(fd, &errfd)` because `fd` is
-1. This ends up doing an out-of-bounds array access that faults
the program. I tracked back to where this -1 came from to the
line here (returned by `CURLINFO_LASTSOCKET`) and added a check
to return an error.
Diffstat (limited to 'src/commit.h')
0 files changed, 0 insertions, 0 deletions
