Fix memory corruption faulting [VPP-1639] 04/19004/3
authorArtem Belov <artem.belov@xored.com>
Thu, 18 Apr 2019 07:30:43 +0000 (07:30 +0000)
committerFlorin Coras <florin.coras@gmail.com>
Thu, 18 Apr 2019 15:08:36 +0000 (15:08 +0000)
File pool may be reallocated on epoll events processing.
*f* pointer shows to already freed address and corrupting
memory chunk on clib_file_t property change.

Change-Id: I751bddce27325452862b939c1a3eec2ccd9b71bb
Signed-off-by: Artem Belov <artem.belov@xored.com>
src/vlib/unix/input.c

index 6b519e5..0edc4e4 100644 (file)
@@ -285,14 +285,14 @@ linux_epoll_input_inline (vlib_main_t * vm, vlib_node_runtime_t * node,
        {
          if (e->events & EPOLLIN)
            {
-             errors[n_errors] = f->read_function (f);
              f->read_events++;
+             errors[n_errors] = f->read_function (f);
              n_errors += errors[n_errors] != 0;
            }
          if (e->events & EPOLLOUT)
            {
-             errors[n_errors] = f->write_function (f);
              f->write_events++;
+             errors[n_errors] = f->write_function (f);
              n_errors += errors[n_errors] != 0;
            }
        }
@@ -300,8 +300,8 @@ linux_epoll_input_inline (vlib_main_t * vm, vlib_node_runtime_t * node,
        {
          if (f->error_function)
            {
-             errors[n_errors] = f->error_function (f);
              f->error_events++;
+             errors[n_errors] = f->error_function (f);
              n_errors += errors[n_errors] != 0;
            }
          else