Source-Changes-HG archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
[src/trunk]: src/sys/dev/usb check if buf/bufsz are non-NULL before freeing.
details:   https://anonhg.NetBSD.org/src/rev/39002e693fcb
branches:  trunk
changeset: 1004523:39002e693fcb
user:      maya <maya%NetBSD.org@localhost>
date:      Thu Oct 31 11:59:40 2019 +0000
description:
check if buf/bufsz are non-NULL before freeing.
not all control messages that can be received result in buf being
initialized, we might get a spurious different control message
seen in practice when swapping modes a few times on a urndis device
urndis0: SAMSUNG ...
autoconfiguration error: urndis0: invalid address
panic: kernel diagnostic assertion "p != NULL" failed: file "/cvs/src/sys/kern/subr_kmem.c", line 263
cpu0: Begin traceback...
vpanic() at netbsd:vpanic+0x178
kern_assert() at netbsd:kern_assert+0x48
kmem_intr_free() at netbsd:kmem_intr_free+0xca
urndis_attach() at netbsd:urndis_attach+0x4c2
diffstat:
 sys/dev/usb/if_urndis.c |  7 ++++---
 1 files changed, 4 insertions(+), 3 deletions(-)
diffs (28 lines):
diff -r d1ef05075b3c -r 39002e693fcb sys/dev/usb/if_urndis.c
--- a/sys/dev/usb/if_urndis.c   Thu Oct 31 10:21:29 2019 +0000
+++ b/sys/dev/usb/if_urndis.c   Thu Oct 31 11:59:40 2019 +0000
@@ -1,4 +1,4 @@
-/*     $NetBSD: if_urndis.c,v 1.33 2019/08/20 06:37:06 mrg Exp $ */
+/*     $NetBSD: if_urndis.c,v 1.34 2019/10/31 11:59:40 maya Exp $ */
 /*     $OpenBSD: if_urndis.c,v 1.31 2011/07/03 15:47:17 matthew Exp $ */
 
 /*
@@ -21,7 +21,7 @@
  */
 
 #include <sys/cdefs.h>
-__KERNEL_RCSID(0, "$NetBSD: if_urndis.c,v 1.33 2019/08/20 06:37:06 mrg Exp $");
+__KERNEL_RCSID(0, "$NetBSD: if_urndis.c,v 1.34 2019/10/31 11:59:40 maya Exp $");
 
 #ifdef _KERNEL_OPT
 #include "opt_usb.h"
@@ -1068,7 +1068,8 @@
                kmem_free(buf, bufsz);
        } else {
                aprint_error("%s: invalid address\n", DEVNAME(un));
-               kmem_free(buf, bufsz);
+               if (buf && bufsz)
+                       kmem_free(buf, bufsz);
                usbnet_lock(un);
                usbnet_stop(un, ifp, 1);
                usbnet_unlock(un);
Home |
Main Index |
Thread Index |
Old Index