Handle malloc() failures more gracefully by error'ing out rather than

segfaulting.

Submitted by:	gcooper
MFC after:	1 week
This commit is contained in:
John Baldwin 2010-11-19 15:39:59 +00:00
parent ad520892d7
commit 3c22a809ec
3 changed files with 36 additions and 0 deletions

View File

@ -328,6 +328,10 @@ parse_array(int fd, int raid_type, char *array_str, struct array_info *info)
/* Validate each drive. */ /* Validate each drive. */
info->drives = calloc(count, sizeof(struct mfi_pd_info)); info->drives = calloc(count, sizeof(struct mfi_pd_info));
if (info->drives == NULL) {
warnx("malloc failed");
return (ENOMEM);
}
info->drive_count = count; info->drive_count = count;
for (pinfo = info->drives; (cp = strsep(&array_str, ",")) != NULL; for (pinfo = info->drives; (cp = strsep(&array_str, ",")) != NULL;
pinfo++) { pinfo++) {
@ -638,6 +642,10 @@ create_volume(int ac, char **av)
break; break;
} }
arrays = calloc(narrays, sizeof(*arrays)); arrays = calloc(narrays, sizeof(*arrays));
if (arrays == NULL) {
warnx("malloc failed");
return (ENOMEM);
}
for (i = 0; i < narrays; i++) { for (i = 0; i < narrays; i++) {
error = parse_array(fd, raid_type, av[i], &arrays[i]); error = parse_array(fd, raid_type, av[i], &arrays[i]);
if (error) if (error)
@ -673,6 +681,10 @@ create_volume(int ac, char **av)
state.array_count = config->array_count; state.array_count = config->array_count;
if (config->array_count > 0) { if (config->array_count > 0) {
state.arrays = calloc(config->array_count, sizeof(int)); state.arrays = calloc(config->array_count, sizeof(int));
if (state.arrays == NULL) {
warnx("malloc failed");
return (ENOMEM);
}
for (i = 0; i < config->array_count; i++) { for (i = 0; i < config->array_count; i++) {
ar = (struct mfi_array *)p; ar = (struct mfi_array *)p;
state.arrays[i] = ar->array_ref; state.arrays[i] = ar->array_ref;
@ -685,6 +697,10 @@ create_volume(int ac, char **av)
state.log_drv_count = config->log_drv_count; state.log_drv_count = config->log_drv_count;
if (config->log_drv_count) { if (config->log_drv_count) {
state.volumes = calloc(config->log_drv_count, sizeof(int)); state.volumes = calloc(config->log_drv_count, sizeof(int));
if (state.volumes == NULL) {
warnx("malloc failed");
return (ENOMEM);
}
for (i = 0; i < config->log_drv_count; i++) { for (i = 0; i < config->log_drv_count; i++) {
ld = (struct mfi_ld_config *)p; ld = (struct mfi_ld_config *)p;
state.volumes[i] = ld->properties.ld.v.target_id; state.volumes[i] = ld->properties.ld.v.target_id;
@ -721,6 +737,10 @@ create_volume(int ac, char **av)
config_size = sizeof(struct mfi_config_data) + config_size = sizeof(struct mfi_config_data) +
sizeof(struct mfi_ld_config) * nvolumes + MFI_ARRAY_SIZE * narrays; sizeof(struct mfi_ld_config) * nvolumes + MFI_ARRAY_SIZE * narrays;
config = calloc(1, config_size); config = calloc(1, config_size);
if (config == NULL) {
warnx("malloc failed");
return (ENOMEM);
}
config->size = config_size; config->size = config_size;
config->array_count = narrays; config->array_count = narrays;
config->array_size = MFI_ARRAY_SIZE; /* XXX: Firmware hardcode */ config->array_size = MFI_ARRAY_SIZE; /* XXX: Firmware hardcode */
@ -902,6 +922,10 @@ add_spare(int ac, char **av)
spare = malloc(sizeof(struct mfi_spare) + sizeof(uint16_t) * spare = malloc(sizeof(struct mfi_spare) + sizeof(uint16_t) *
config->array_count); config->array_count);
if (spare == NULL) {
warnx("malloc failed");
return (ENOMEM);
}
bzero(spare, sizeof(struct mfi_spare)); bzero(spare, sizeof(struct mfi_spare));
spare->ref = info.ref; spare->ref = info.ref;
@ -1170,6 +1194,10 @@ dump(int ac, char **av)
} }
config = malloc(len); config = malloc(len);
if (config == NULL) {
warnx("malloc failed");
return (ENOMEM);
}
if (sysctlbyname(buf, config, &len, NULL, 0) < 0) { if (sysctlbyname(buf, config, &len, NULL, 0) < 0) {
error = errno; error = errno;
warn("Failed to read debug command"); warn("Failed to read debug command");

View File

@ -624,6 +624,10 @@ show_events(int ac, char **av)
} }
list = malloc(size); list = malloc(size);
if (list == NULL) {
warnx("malloc failed");
return (ENOMEM);
}
for (seq = start;;) { for (seq = start;;) {
if (mfi_get_events(fd, list, num_events, filter, seq, if (mfi_get_events(fd, list, num_events, filter, seq,
&status) < 0) { &status) < 0) {

View File

@ -163,6 +163,10 @@ flash_adapter(int ac, char **av)
/* Upload the file 64k at a time. */ /* Upload the file 64k at a time. */
buf = malloc(FLASH_BUF_SIZE); buf = malloc(FLASH_BUF_SIZE);
if (buf == NULL) {
warnx("malloc failed");
return (ENOMEM);
}
offset = 0; offset = 0;
while (sb.st_size > 0) { while (sb.st_size > 0) {
nread = read(flash, buf, FLASH_BUF_SIZE); nread = read(flash, buf, FLASH_BUF_SIZE);