]> git.kaiwu.me - nginx.git/commitdiff
QUIC: fixed stream cleanup (ticket #2586).
authorRoman Arutyunyan <arut@nginx.com>
Wed, 14 Feb 2024 11:55:37 +0000 (15:55 +0400)
committerRoman Arutyunyan <arut@nginx.com>
Wed, 14 Feb 2024 11:55:37 +0000 (15:55 +0400)
Stream connection cleanup handler ngx_quic_stream_cleanup_handler() calls
ngx_quic_shutdown_stream() after which it resets the pointer from quic stream
to the connection (sc->connection = NULL).  Previously if this call failed,
sc->connection retained the old value, while the connection was freed by the
application code.  This resulted later in a second attempt to close the freed
connection, which lead to allocator double free error.

The fix is to reset the sc->connection pointer in case of error.

src/event/quic/ngx_event_quic_streams.c

index df04d0f07407ddc310d524b357150ce16af27bff..178b805e450443e4334eff19588f6d99a75debf1 100644 (file)
@@ -1097,6 +1097,7 @@ ngx_quic_stream_cleanup_handler(void *data)
                    "quic stream id:0x%xL cleanup", qs->id);
 
     if (ngx_quic_shutdown_stream(c, NGX_RDWR_SHUTDOWN) != NGX_OK) {
+        qs->connection = NULL;
         goto failed;
     }