Conversation
Several source creation and cleanup routines have missing error reporting to callers or fail to finalize internal zip_error_t structures before freeing their enclosing contexts: - In zip_source_file_common_new, when a file does not exist and write mode is not applicable, report ZIP_ER_READ (ENOENT) into the caller-provided error pointer instead of setting the internal ctx->stat_error which was immediately freed without informing the caller. - Call zip_error_fini on ctx->stat_error and ctx->error in all error unwinding branches of zip_source_file_common_new as well as during read_file ZIP_SOURCE_FREE. - Call zip_error_fini(&src->error) in zip_source_free before free(src). - In buffer_new, set ZIP_ER_MEMORY when malloc for buffer fails, matching other allocation checks in the function. - In _zip_source_buffer_new and read_data ZIP_SOURCE_FREE, finalize ctx->error before freeing ctx. - In _zip_string_new, set ZIP_ER_MEMORY if allocating s->raw fails. - In _zip_winzip_aes_new, clear sensitive key material in buffer and ctx with _zip_crypto_clear and report ZIP_ER_INTERNAL if _zip_crypto_pbkdf2 fails. - In trad_pkware_free (zip_source_pkware_decode.c), finalize ctx->error before free(ctx), consistent with zip_source_pkware_encode.c. - In _zip_source_window_new and window_read ZIP_SOURCE_FREE, finalize ctx->error before freeing ctx. - In zip_source_crc_create, use crc_context_free instead of raw free(ctx) upon layered source creation failure.
|
I ran into the On current main, Both pass with this PR. Valgrind shows the same leak on a normal build. I also ran the full test suite with this PR under ASan. The only remaining failures are four tests using (clang 21, Ubuntu) |
This was referenced Sep 26, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This patch fixes several error reporting and resource cleanup defects across source constructors and crypto wrappers:
zip_source_file_common.c(zip_source_file_common_new):!sb.exists) and cannot be opened for writing (e.g. read-only, non-zero offset, or length specified),zip_error_set(&ctx->stat_error, ZIP_ER_READ, ENOENT)was called on the internalctx->stat_error, andctxwas immediately freed. The caller-providederrorpointer remained unpopulated, leaving callers ofzip_source_file_createwithNULLand an uninitialized error reason. This now correctly setszip_error_set(error, ZIP_ER_READ, ENOENT).!ops->stat,!sb.exists, length overflow, andzip_source_function_createfailure),zip_error_finiis now invoked on&ctx->stat_errorand&ctx->errorbefore freeingctx.read_fileunderZIP_SOURCE_FREE,zip_error_finiis now called on&ctx->stat_errorand&ctx->errorbefore freeingctx.zip_source_free.c(zip_source_free):zip_error_fini(&src->error)is now called before freeingsrc.src->erroris initialized in_zip_source_new(), and any dynamically allocated error string from operations on the source was previously leaked upon freeing.zip_source_buffer.c(buffer_new,_zip_source_buffer_new,read_data):buffer_new, if allocatingbufferfails,zip_error_set(error, ZIP_ER_MEMORY, 0)is now called, consistent with the other allocation checks in the function.zip_source_function_createfailure in_zip_source_buffer_newand underZIP_SOURCE_FREEinread_data,zip_error_fini(&ctx->error)is now called before freeingctx.zip_string.c(_zip_string_new):s->rawfails,zip_error_set(error, ZIP_ER_MEMORY, 0)is now called before freeingsand returningNULL(matching thes = malloc(...)check).zip_winzip_aes.c(_zip_winzip_aes_new):_zip_crypto_pbkdf2fails, sensitive key material inbufferandctxis now scrubbed with_zip_crypto_clear(),ctxis freed, andzip_error_set(error, ZIP_ER_INTERNAL, 0)is reported, preventing sensitive data leakage and unpopulated caller errors.zip_source_pkware_decode.c(trad_pkware_free):zip_error_fini(&ctx->error)is now called before freeingctx, matchingzip_source_pkware_encode.c.zip_source_window.c(_zip_source_window_new,window_read):zip_error_fini(&ctx->error)is now invoked on error unwinding and underZIP_SOURCE_FREE.zip_source_crc.c(zip_source_crc_create):zip_source_layered_createfails,crc_context_free(ctx)is now called instead of rawfree(ctx), ensuringctx->erroris finalized.