From ccd37226c6d337ea8ce3c0f9b7ddd1bd7eeaec1f Mon Sep 17 00:00:00 2001 From: Ben Noordhuis Date: Tue, 16 Apr 2013 22:59:35 +0200 Subject: [PATCH] handle_wrap: fix NULL pointer dereference Fix a NULL pointer dereference in src/handle_wrap.cc which is really a use-after-close bug. The test checks that unref() after close() works on process.stdout but this bug affects everything that derives from HandleWrap. I discovered it because child processes would sometimes quit for no reason (that is, no reason until I turned on core dumps.) --- src/handle_wrap.cc | 4 ++-- test/simple/test-stdout-close-unref.js | 23 +++++++++++++++++++++++ 2 files changed, 25 insertions(+), 2 deletions(-) create mode 100644 test/simple/test-stdout-close-unref.js diff --git a/src/handle_wrap.cc b/src/handle_wrap.cc index 3f05c7d81b..a63421bc29 100644 --- a/src/handle_wrap.cc +++ b/src/handle_wrap.cc @@ -57,7 +57,7 @@ Handle HandleWrap::Ref(const Arguments& args) { UNWRAP_NO_ABORT(HandleWrap) - if (wrap) { + if (wrap != NULL && wrap->handle__ != NULL) { uv_ref(wrap->handle__); wrap->flags_ &= ~kUnref; } @@ -71,7 +71,7 @@ Handle HandleWrap::Unref(const Arguments& args) { UNWRAP_NO_ABORT(HandleWrap) - if (wrap) { + if (wrap != NULL && wrap->handle__ != NULL) { uv_unref(wrap->handle__); wrap->flags_ |= kUnref; } diff --git a/test/simple/test-stdout-close-unref.js b/test/simple/test-stdout-close-unref.js new file mode 100644 index 0000000000..533a005936 --- /dev/null +++ b/test/simple/test-stdout-close-unref.js @@ -0,0 +1,23 @@ +// Copyright Joyent, Inc. and other Node contributors. +// +// Permission is hereby granted, free of charge, to any person obtaining a +// copy of this software and associated documentation files (the +// "Software"), to deal in the Software without restriction, including +// without limitation the rights to use, copy, modify, merge, publish, +// distribute, sublicense, and/or sell copies of the Software, and to permit +// persons to whom the Software is furnished to do so, subject to the +// following conditions: +// +// The above copyright notice and this permission notice shall be included +// in all copies or substantial portions of the Software. +// +// THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS +// OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF +// MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN +// NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, +// DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR +// OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE +// USE OR OTHER DEALINGS IN THE SOFTWARE. + +process.stdout._handle.close(); +process.stdout._handle.unref(); // Should not segfault.