summaryrefslogtreecommitdiffstats
path: root/bin
diff options
context:
space:
mode:
authorjilles <jilles@FreeBSD.org>2016-03-28 18:58:40 +0000
committerjilles <jilles@FreeBSD.org>2016-03-28 18:58:40 +0000
commita90ad707c5487d6270fc478806ed335203056526 (patch)
tree11c5a13a8b14c23575e92ba15e8d7ebe8561772f /bin
parent2d884a83b2752861330ec6b2172e81b6c478fd17 (diff)
downloadFreeBSD-src-a90ad707c5487d6270fc478806ed335203056526.zip
FreeBSD-src-a90ad707c5487d6270fc478806ed335203056526.tar.gz
sh: Fix use-after-free if a trap replaces itself.
MFC after: 1 week
Diffstat (limited to 'bin')
-rw-r--r--bin/sh/tests/builtins/Makefile1
-rw-r--r--bin/sh/tests/builtins/trap17.010
-rw-r--r--bin/sh/trap.c5
3 files changed, 15 insertions, 1 deletions
diff --git a/bin/sh/tests/builtins/Makefile b/bin/sh/tests/builtins/Makefile
index 8292665..6efec15 100644
--- a/bin/sh/tests/builtins/Makefile
+++ b/bin/sh/tests/builtins/Makefile
@@ -149,6 +149,7 @@ FILES+= trap13.0
FILES+= trap14.0
FILES+= trap15.0
FILES+= trap16.0
+FILES+= trap17.0
FILES+= trap2.0
FILES+= trap3.0
FILES+= trap4.0
diff --git a/bin/sh/tests/builtins/trap17.0 b/bin/sh/tests/builtins/trap17.0
new file mode 100644
index 0000000..89be893
--- /dev/null
+++ b/bin/sh/tests/builtins/trap17.0
@@ -0,0 +1,10 @@
+# $FreeBSD$
+# This use-after-free bug probably needs non-default settings to show up.
+
+v1=nothing v2=nothing
+trap 'trap "echo bad" USR1
+v1=trap_received
+v2=trap_invoked
+:' USR1
+kill -USR1 "$$"
+[ "$v1.$v2" = trap_received.trap_invoked ]
diff --git a/bin/sh/trap.c b/bin/sh/trap.c
index f562e27..8bfebc1 100644
--- a/bin/sh/trap.c
+++ b/bin/sh/trap.c
@@ -412,6 +412,7 @@ onsig(int signo)
void
dotrap(void)
{
+ struct stackmark smark;
int i;
int savestatus, prev_evalskip, prev_skipcount;
@@ -445,7 +446,9 @@ dotrap(void)
last_trapsig = i;
savestatus = exitstatus;
- evalstring(trap[i], 0);
+ setstackmark(&smark);
+ evalstring(stsavestr(trap[i]), 0);
+ popstackmark(&smark);
/*
* If such a command was not
OpenPOWER on IntegriCloud