Fix use-after-free violation in NetlinkException #295
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Type
Side Effects
Goals
NetlinkException
does not cause a crash or weird results when later reading the error category information from theNetlinkException
instance.Technical Details
When creating an instance of
NetlinkException
, and temporary instance ofNetlinkErrorCategory
is passed to thestd::error_code
constructor. However,std::error_code
expects a const reference and does not make a copy of it. Since we passed a temporary, this later results in a use-after-free bug which would cause either a crash (good case) or weird results when reading the error category information from theNetlinkException
later. This is solved by using a singletonNetlinkErrorCategory
and passing this instance to thestd::error_code
constructor.NetlinkErrorCategory
.NetlinkErrorCategory
tostd:;error_code
constructor when creating aNetlinkException
.NetlinkException
doesn't cause a crash or trigger AddressSanitizer.Test Results
Reviewer Focus
Future Work
Checklist
all
compiles cleanly.