Hello,

cppcheck wrongly reported a double free of buffer in py_uwsgi_parse_file. Unfortunately checking that is difficult if the error handling in the code make it a mess ;) so while at it cleanup the error handling code to be easier to follow.
For review i suggest to use hg diff -w to skip whitespace changes.

thanks,
riccardo
diff -r 748b0e4fe525 plugins/python/uwsgi_pymodule.c
--- a/plugins/python/uwsgi_pymodule.c	Sun Jul 22 11:43:39 2012 +0200
+++ b/plugins/python/uwsgi_pymodule.c	Sun Jul 22 18:48:41 2012 +0200
@@ -2895,46 +2895,38 @@
 		zero = PyDict_New();
 
 		while (ptrbuf < bufferend) {
-			if (ptrbuf + 2 < bufferend) {
-				memcpy(&strsize, ptrbuf, 2);
+			if (ptrbuf + 2 >= bufferend)
+				goto clear3;
+			memcpy(&strsize, ptrbuf, 2);
 #ifdef __BIG_ENDIAN__
-				strsize = uwsgi_swap16(strsize);
+			strsize = uwsgi_swap16(strsize);
 #endif
-				/* key cannot be null */
-				if (!strsize) {
-					uwsgi_log("uwsgi key cannot be null.\n");
-					goto clear3;
-				}
-
-				ptrbuf += 2;
-				if (ptrbuf + strsize < bufferend) {
-					// var key
-					keybuf = ptrbuf;
-					keysize = strsize;
-					ptrbuf += strsize;
-					// value can be null (even at the end) so use <=
-					if (ptrbuf + 2 <= bufferend) {
-						memcpy(&strsize, ptrbuf, 2);
-#ifdef __BIG_ENDIAN__
-						strsize = uwsgi_swap16(strsize);
-#endif
-						ptrbuf += 2;
-						if (ptrbuf + strsize <= bufferend) {
-							PyDict_SetItem(zero, PyString_FromStringAndSize(keybuf, keysize), PyString_FromStringAndSize(ptrbuf, strsize));
-							ptrbuf += strsize;
-						}
-						else {
-							goto clear3;
-						}
-					}
-					else {
-						goto clear3;
-					}
-				}
-			}
-			else {
+			/* key cannot be null */
+			if (!strsize) {
+				uwsgi_log("uwsgi key cannot be null.\n");
 				goto clear3;
 			}
+
+			ptrbuf += 2;
+			if (ptrbuf + strsize >= bufferend)
+				continue;
+
+			// var key
+			keybuf = ptrbuf;
+			keysize = strsize;
+			ptrbuf += strsize;
+			// value can be null (even at the end)
+			if (ptrbuf + 2 > bufferend)
+				goto clear3;
+			memcpy(&strsize, ptrbuf, 2);
+#ifdef __BIG_ENDIAN__
+			strsize = uwsgi_swap16(strsize);
+#endif
+			ptrbuf += 2;
+			if (ptrbuf + strsize > bufferend)
+				goto clear3;
+			PyDict_SetItem(zero, PyString_FromStringAndSize(keybuf, keysize), PyString_FromStringAndSize(ptrbuf, strsize));
+			ptrbuf += strsize;
 		}
 
 		close(fd);
_______________________________________________
uWSGI mailing list
[email protected]
http://lists.unbit.it/cgi-bin/mailman/listinfo/uwsgi

Reply via email to