CLEANUP: vars: always zero the pointers after a free()

In sample_store(), depending on the new sample types, the area pointer
was not always zeroed after being freed. Let's make sure it's always the
case to avoid the risk of dangling pointers being misused.
This commit is contained in:
Willy Tarreau 2021-02-26 21:19:53 +01:00
parent 35cd734356
commit 5b52b00393

View File

@ -141,11 +141,11 @@ unsigned int var_clear(struct var *var)
unsigned int size = 0;
if (var->data.type == SMP_T_STR || var->data.type == SMP_T_BIN) {
free(var->data.u.str.area);
ha_free(&var->data.u.str.area);
size += var->data.u.str.data;
}
else if (var->data.type == SMP_T_METH && var->data.u.meth.meth == HTTP_METH_OTHER) {
free(var->data.u.meth.str.area);
ha_free(&var->data.u.meth.str.area);
size += var->data.u.meth.str.data;
}
LIST_DEL(&var->l);
@ -352,12 +352,12 @@ static int sample_store(struct vars *vars, const char *name, struct sample *smp)
/* free its used memory. */
if (var->data.type == SMP_T_STR ||
var->data.type == SMP_T_BIN) {
free(var->data.u.str.area);
ha_free(&var->data.u.str.area);
var_accounting_diff(vars, smp->sess, smp->strm,
-var->data.u.str.data);
}
else if (var->data.type == SMP_T_METH && var->data.u.meth.meth == HTTP_METH_OTHER) {
free(var->data.u.meth.str.area);
ha_free(&var->data.u.meth.str.area);
var_accounting_diff(vars, smp->sess, smp->strm,
-var->data.u.meth.str.data);
}