Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 104146

Summary: Fault pointer in "watch"
Product: [Retired] Red Hat Linux Reporter: JW <ohtmvyyn>
Component: procpsAssignee: Daniel Walsh <dwalsh>
Status: CLOSED CURRENTRELEASE QA Contact: Brian Brock <bbrock>
Severity: high Docs Contact:
Priority: medium    
Version: 9   
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2004-02-11 13:42:06 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description JW 2003-09-10 15:01:45 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (compatible; MSIE 5.01; Windows 98;)

Description of problem:
Here is the code in question:

        for (; optind < argc; optind++) {
                int s = strlen(argv[optind]);
                char *endp = &command[command_length];
                *endp = ' ';
                command_length += s + 1;
                command = realloc(command, command_length + 1);
                strcpy(endp + 1, argv[optind]);
        }

Study it carefully.  Looks fine doesn't it.
Well it isn't.

The 'endp' is set to point somewhere in relation to 'command'
Then 'command' is changed via realloc.
Then 'endp' is used again like nothing has changed!


Version-Release number of selected component (if applicable):
2.0.13-8

How reproducible:
Always

Steps to Reproduce:
1. Read the code
2. 
3.
    

Actual Results:  Depends on realloc/malloc implementation.
At worse segmentation error, but usually just garbled result.
Unless your system allocate memory in rather large chunks.

Additional info:

Comment 1 Alexander Larsson 2003-09-25 09:01:55 UTC
This is fixed in 2.0.16, we need to upgrade.


Comment 2 Pete Zaitcev 2003-10-08 19:35:06 UTC
*** Bug 106399 has been marked as a duplicate of this bug. ***

Comment 3 Pete Zaitcev 2003-10-08 19:37:41 UTC
Eek. Ignore a mistaken dup.


Comment 4 Daniel Walsh 2004-02-11 13:42:06 UTC
Fixed in latest release 3.1.15