From mboxrd@z Thu Jan 1 00:00:00 1970 Delivery-date: Wed, 26 Aug 2026 14:21:52 +0200 Received: from mx1.white.stw.pengutronix.de ([2a0a:edc0:0:b01:1d::107]) by lore.white.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wzCdb-007QpL-0o for lore@lore.pengutronix.de; Wed, 26 Aug 2026 14:21:52 +0200 Received: from bombadil.infradead.org (bombadil.infradead.org [IPv6:2607:7c80:54:3::133]) by mx1.white.stw.pengutronix.de (Postfix) with ESMTPS id BDC63202148 for ; Wed, 26 Aug 2026 14:21:47 +0200 (CEST) Authentication-Results: mx1.white.stw.pengutronix.de; dkim=pass header.d=lists.infradead.org header.s=bombadil.20210309 header.b=OYfaJcdj; dmarc=none; spf=pass (mx1.white.stw.pengutronix.de: domain of "barebox-bounces+lore=pengutronix.de@lists.infradead.org" designates 2607:7c80:54:3::133 as permitted sender) smtp.mailfrom="barebox-bounces+lore=pengutronix.de@lists.infradead.org" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.infradead.org; s=bombadil.20210309; h=Sender:List-Subscribe:List-Help :List-Post:List-Archive:List-Unsubscribe:List-Id:Content-Transfer-Encoding: MIME-Version:References:In-Reply-To:Message-ID:Date:Subject:Cc:To:From: Reply-To:Content-Type:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=1uEOLWUe+jlJPlG6OSrf6eDK268UsBht9U8goKpwYyk=; b=OYfaJcdjZZtvObziAdo33wDjVs yp+cCw64hiGSWth76yZmy2tuHhZjHiB0Z4PMluzENakwZA1+0Yma4S313aHX2FP5SF4SllcZXHHaC 29/TSn6JTmTSHdJ3/DigqZcvvf9wfbw96zxogn5mPQfZ3mOwfb4VoiZIVy7vTI1xwYXLnCr+cY82w /GxVYcLeM90L9hd2esoa7WEQF1f9NMnBOVLU/4JcPnm908zuDVBu0RAI8031T3ZgWVfVk2bXwl21M C2G0q5RrkfoS+e1hyMNdRaqWV7SvRYNdiCYqmJPDaq+ddf8B/HfXQIEG6p6wIK0x7XIjbmab29m1X R1mKbROw==; Received: from localhost ([::1] helo=bombadil.infradead.org) by bombadil.infradead.org with esmtp (Exim 4.99.1 #2 (Red Hat Linux)) id 1wzCcB-00000002Puc-3KRl; Wed, 26 Aug 2026 12:20:24 +0000 Received: from mx1.white.stw.pengutronix.de ([185.203.200.13]) by bombadil.infradead.org with esmtps (Exim 4.99.1 #2 (Red Hat Linux)) id 1wzCbv-00000002Pkf-2g3w for barebox@lists.infradead.org; Wed, 26 Aug 2026 12:20:12 +0000 Received: from drehscheibe.grey.stw.pengutronix.de (drehscheibe.grey.stw.pengutronix.de [IPv6:2a0a:edc0:0:c01:1d::a2]) (Authenticated sender: relay-from-drehscheibe.grey.stw.pengutronix.de) by mx1.white.stw.pengutronix.de (Postfix) with ESMTPSA id 64349202282; Wed, 26 Aug 2026 14:19:57 +0200 (CEST) Received: from dude05.red.stw.pengutronix.de ([2a0a:edc0:0:1101:1d::54]) by drehscheibe.grey.stw.pengutronix.de with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.96) (envelope-from ) id 1wzCbl-003RBO-0v; Wed, 26 Aug 2026 14:19:57 +0200 Received: from [::1] (helo=dude05.red.stw.pengutronix.de) by dude05.red.stw.pengutronix.de with esmtp (Exim 4.98.2) (envelope-from ) id 1wzCbl-0000000CK1K-0ifg; Wed, 26 Aug 2026 14:19:57 +0200 From: Ahmad Fatoum To: barebox@lists.infradead.org Cc: fpg@pengutronix.de, Ahmad Fatoum Subject: [PATCH RFT 9/9] common: bootargs: don't leave linux_bootargs dangling after free Date: Wed, 26 Aug 2026 14:17:13 +0200 Message-ID: <20260826121956.2936414-10-a.fatoum@pengutronix.de> X-Mailer: git-send-email 2.47.3 In-Reply-To: <20260826121956.2936414-1-a.fatoum@pengutronix.de> References: <20260826121956.2936414-1-a.fatoum@pengutronix.de> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-CRM114-Version: 20100106-BlameMichelson ( TRE 0.9.0 (BSD) ) MR-646709E3 X-CRM114-CacheID: sfid-20260826_052007_919683_FA7F25FD X-CRM114-Status: UNSURE ( 7.53 ) X-CRM114-Notice: Please train this message. X-Spam-Score: -1.9 (-) X-Spam-Report: Spam detection software, running on the system "bombadil.infradead.org", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: linux_bootargs_get() frees the cached command line before recomputing it, but the early return taken when there are no bootargs leaves the static pointer referencing the freed allocation, so the next [...] Content analysis details: (-1.9 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record -1.9 BAYES_00 BODY: Bayes spam probability is 0 to 1% [score: 0.0000] 0.0 DMARC_MISSING Missing DMARC policy X-BeenThere: barebox@lists.infradead.org X-Mailman-Version: 2.1.34 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: "barebox" X-Spamd-Result: default: False [-56.21 / 15.00]; RECEIVED_AUTHENTICATED_BY_MX1(-50.00)[]; BAYES_HAM(-3.00)[99.99%]; DWL_DNSWL_MED(-2.00)[infradead.org:dkim]; KNOWN_LIST_ID(-1.00)[barebox.lists.infradead.org]; MID_CONTAINS_FROM(1.00)[]; RCVD_DKIM_ARC_DNSWL_MED(-0.50)[]; R_MISSING_CHARSET(0.50)[]; RCVD_IN_DNSWL_MED(-0.40)[2a0a:edc0:0:1101:1d::54:received,2607:7c80:54:3::133:from]; R_SPF_ALLOW(-0.20)[+mx:c]; R_DKIM_ALLOW(-0.20)[lists.infradead.org:s=bombadil.20210309]; MAILLIST(-0.20)[mailman]; MIME_GOOD(-0.10)[text/plain]; RCVD_IN_DNSWL_LOW(-0.10)[2a0a:edc0:0:c01:1d::a2:received]; HAS_LIST_UNSUB(-0.01)[]; TO_DN_SOME(0.00)[]; DMARC_NA(0.00)[pengutronix.de]; MIME_TRACE(0.00)[0:+]; ARC_NA(0.00)[]; RECEIVED_HELO_LOCALHOST(0.00)[]; RCVD_TLS_LAST(0.00)[]; RCPT_COUNT_THREE(0.00)[3]; DKIM_TRACE(0.00)[lists.infradead.org:+]; FROM_NEQ_ENVFROM(0.00)[a.fatoum@pengutronix.de,barebox-bounces@lists.infradead.org]; FROM_HAS_DN(0.00)[]; TAGGED_FROM(0.00)[lore=pengutronix.de]; RCVD_COUNT_FIVE(0.00)[5]; RCVD_VIA_SMTP_AUTH(0.00)[]; NEURAL_HAM(-0.00)[-1.000]; ASN(0.00)[asn:7247, ipnet:2607:7c80:54::/48, country:US]; FORGED_SENDER_MAILLIST(0.00)[] X-Rspamd-Action: no action X-Rspamd-Server: mx1 X-Stat-Signature: agpgethdohbxohchcpsmn76fnfucimtu X-Rspamd-Queue-Id: BDC63202148 linux_bootargs_get() frees the cached command line before recomputing it, but the early return taken when there are no bootargs leaves the static pointer referencing the freed allocation, so the next call frees it a second time. Clear the pointer right after freeing it. Fixes: ee4cab9e5874 ("booting: more flexible Linux bootargs generation") Assisted-by: Claude:opus-5 Signed-off-by: Ahmad Fatoum --- common/bootargs.c | 1 + 1 file changed, 1 insertion(+) diff --git a/common/bootargs.c b/common/bootargs.c index 710f74de9629..91e92e594876 100644 --- a/common/bootargs.c +++ b/common/bootargs.c @@ -30,6 +30,7 @@ const char *linux_bootargs_get(void) return linux_bootargs; free(linux_bootargs); + linux_bootargs = NULL; bootargs = globalvar_get_match("linux.bootargs.", " "); if (!*bootargs) { -- 2.47.3