From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from [87.239.111.99] (localhost [127.0.0.1]) by dev.tarantool.org (Postfix) with ESMTP id 11F3C6EC5B; Fri, 14 May 2021 10:44:51 +0300 (MSK) DKIM-Filter: OpenDKIM Filter v2.11.0 dev.tarantool.org 11F3C6EC5B DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=tarantool.org; s=dev; t=1620978291; bh=OC4uUu+zaa6FdKj9cWE0Q7VqAR2jVH7+tSQ+QyqeuEE=; h=Date:To:References:In-Reply-To:Subject:List-Id:List-Unsubscribe: List-Archive:List-Post:List-Help:List-Subscribe:From:Reply-To:Cc: From; b=OIs9O8a2oPD2PLO372qceTxSLIVQpbu2KGg96XCwSvdZE316TM9/+WxPSTl9gjLCA ZujXpY2t5OYMLiGt00smIiWuyZdDJ3r2rOGFcwcRNmZj0TCvmX/9uHesV7u35b5nYR xBwpSPZgzdX4hWO3H49cmT2s3S1Luvk8utAA/JPI= Received: from smtp57.i.mail.ru (smtp57.i.mail.ru [217.69.128.37]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by dev.tarantool.org (Postfix) with ESMTPS id C5BE56EC5B for ; Fri, 14 May 2021 10:44:49 +0300 (MSK) DKIM-Filter: OpenDKIM Filter v2.11.0 dev.tarantool.org C5BE56EC5B Received: by smtp57.i.mail.ru with esmtpa (envelope-from ) id 1lhSV6-0001iE-Jm; Fri, 14 May 2021 10:44:49 +0300 Date: Fri, 14 May 2021 07:44:45 +0000 To: Serge Petrenko Message-ID: <20210514074445.sn6x75muzescawtz@tarantool.org> References: <20210512113907.12968-1-sergepetrenko@tarantool.org> MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Disposition: inline Content-Transfer-Encoding: 8bit In-Reply-To: <20210512113907.12968-1-sergepetrenko@tarantool.org> User-Agent: NeoMutt/20170113 (1.7.2) X-7564579A: 646B95376F6C166E X-77F55803: 4F1203BC0FB41BD95978C26455E69BE0B2C7F7C3B0039F1303CE517DE434612D182A05F53808504063ADC67F695A84A7A8201B266069131D9801BC29FEB813AA08A4E9568B0E0E81 X-7FA49CB5: FF5795518A3D127A4AD6D5ED66289B5278DA827A17800CE7C2204D4F9A221771EA1F7E6F0F101C67BD4B6F7A4D31EC0BCC500DACC3FED6E28638F802B75D45FF8AA50765F79006376602C647E39EFA3A8638F802B75D45FF914D58D5BE9E6BC1A93B80C6DEB9DEE97C6FB206A91F05B2F6B79B1073F910DBE12EC6858044DB0E32051A2C76225635D2E47CDBA5A96583C09775C1D3CA48CF27ED053E960B195E117882F4460429724CE54428C33FAD30A8DF7F3B2552694AC26CFBAC0749D213D2E47CDBA5A9658378DA827A17800CE7ABB305BD10C6E5099FA2833FD35BB23DF004C90652538430302FCEF25BFAB3454AD6D5ED66289B5278DA827A17800CE766F62E84CA280C2BD32BA5DBAC0009BE395957E7521B51C20BC6067A898B09E4090A508E0FED6299176DF2183F8FC7C0301D0F243F962D12CD04E86FAF290E2D7E9C4E3C761E06A71DD303D21008E29813377AFFFEAFD269A417C69337E82CC2E827F84554CEF50127C277FBC8AE2E8BA83251EDC214901ED5E8D9A59859A8B6D0C9BB9AE6BD5D69089D37D7C0E48F6C5571747095F342E88FB05168BE4CE3AF X-C1DE0DAB: 0D63561A33F958A5724580F2A3E14213914ABDE2F127364B8C670AF0BA26AF27D59269BC5F550898D99A6476B3ADF6B47008B74DF8BB9EF7333BD3B22AA88B938A852937E12ACA75F04B387B5D7535DE410CA545F18667F91A7EA1CDA0B5A7A0 X-C8649E89: 4E36BF7865823D7055A7F0CF078B5EC49A30900B95165D3494FB0335DF05DC3AB1664BC9CA6416DFAE23E928D32279F90B008DD983367A308EA7924415B15F721D7E09C32AA3244C2F43C00B95A2FD996C1571F36CFDFDBA3E8609A02908F271927AC6DF5659F194 X-D57D3AED: 3ZO7eAau8CL7WIMRKs4sN3D3tLDjz0dLbV79QFUyzQ2Ujvy7cMT6pYYqY16iZVKkSc3dCLJ7zSJH7+u4VD18S7Vl4ZUrpaVfd2+vE6kuoey4m4VkSEu530nj6fImhcD4MUrOEAnl0W826KZ9Q+tr5ycPtXkTV4k65bRjmOUUP8cvGozZ33TWg5HZplvhhXbhDGzqmQDTd6OAevLeAnq3Ra9uf7zvY2zzsIhlcp/Y7m53TZgf2aB4JOg4gkr2biojoybArHp+PQXocZtaFM16zQ== X-Mailru-Sender: 05EB39F83D09414F9B5D7F52D7CDFDD20AE29BAE5BA69B1BB1C2E06550C4517853AAA2A269CCE9E6CA16B95394F0DD5CE99530A0C0F27B5268329DCED823713783C0E760C018FF54112434F685709FCF0DA7A0AF5A3A8387 X-Mras: Ok Subject: Re: [Tarantool-patches] [PATCH] relay: fix use after free in subscribe_f X-BeenThere: tarantool-patches@dev.tarantool.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: Tarantool development patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , From: Kirill Yukhin via Tarantool-patches Reply-To: Kirill Yukhin Cc: tarantool-patches@dev.tarantool.org, v.shpilevoy@tarantool.org Errors-To: tarantool-patches-bounces@dev.tarantool.org Sender: "Tarantool-patches" Hello, On 12 май 14:39, Serge Petrenko via Tarantool-patches wrote: > relay_subscribe_f() remembered old recovery pointer, which might be > replaced by relay_restart_recovery() if a raft message is delivered during > cbus_process() loop in relay_send_is_raft_enabled(). > > Fix the issue by moving variable initialization below > relay_send_is_raft_enabled() > > Closes #6031 > --- > https://github.com/tarantool/tarantool/issues/6031 > https://github.com/tarantool/tarantool/tree/sp/gh-6031-use-after-free I've checked your patch into 2.8 and master. -- Regards, Kirill Yukhin