(/home/sate/Testcases/c/cve/dovecot-1.2.0/src/lib-index/mail-transaction-log-view.c) |
| |
| 96 | | | int mail_transaction_log_view_set(struct mail_transaction_log_view *view, |
| 97 | | | uint32_t min_file_seq, uoff_t min_file_offset, |
| 98 | | | uint32_t max_file_seq, uoff_t max_file_offset, |
| 99 | | | bool *reset_r) |
| 100 | | | { |
| 101 | | | struct mail_transaction_log_file *file, *const *files; |
| 102 | | | uoff_t start_offset, end_offset; |
| 103 | | | unsigned int i; |
| 104 | | | uint32_t seq; |
| 105 | | | int ret; |
| 106 | | | |
| 107 | | | i_assert(view->log != NULL);
x /home/sate/Testcases/c/cve/dovecot-1.2.0/src/lib/macros.h |
| |
189 | #define i_assert(expr) STMT_START{ \ |
190 | if (unlikely(!(expr))) \ |
191 | i_panic("file %s: line %d (%s): assertion failed: (%s)", \ |
192 | __FILE__, \ |
193 | __LINE__, \ |
194 | __PRETTY_FUNCTION__, \ |
195 | #expr); }STMT_END |
| |
|
Event 1:
Skipping " if". view->log != (void *)0 evaluates to true.
hide
Event 2:
Skipping " if". !(view->log != (void *)0) evaluates to false.
hide
Event 3:
Skipping " if". !!(view->log != (void *)0) evaluates to true.
hide
Event 4:
Skipping " if". !!!(view->log != (void *)0) evaluates to false.
hide
Event 5:
Skipping " if". __builtin_expect(...) evaluates to false.
hide
|
|
| 108 | | | i_assert(min_file_seq <= max_file_seq);
x /home/sate/Testcases/c/cve/dovecot-1.2.0/src/lib/macros.h |
| |
189 | #define i_assert(expr) STMT_START{ \ |
190 | if (unlikely(!(expr))) \ |
191 | i_panic("file %s: line %d (%s): assertion failed: (%s)", \ |
192 | __FILE__, \ |
193 | __LINE__, \ |
194 | __PRETTY_FUNCTION__, \ |
195 | #expr); }STMT_END |
| |
|
Event 6:
Skipping " if". min_file_seq <= max_file_seq evaluates to true.
hide
Event 7:
Skipping " if". !(min_file_seq <= max_file_seq) evaluates to false.
hide
Event 8:
Skipping " if". !!(min_file_seq <= max_file_seq) evaluates to true.
hide
Event 9:
Skipping " if". !!!(min_file_seq <= max_file_seq) evaluates to false.
hide
Event 10:
Skipping " if". __builtin_expect(...) evaluates to false.
hide
|
|
| 109 | | | |
| 110 | | | *reset_r = FALSE; |
| 111 | | | |
| 112 | | | if (view->log == NULL) { |
Event 11:
Skipping " if". view->log == (void *)0 evaluates to false.
hide
|
|
| 113 | | | |
| 114 | | | |
| 115 | | | return -1; |
| 116 | | | } |
| 117 | | | |
| 118 | | | if (min_file_seq == 0) { |
Event 12:
Skipping " if". min_file_seq == 0 evaluates to false.
hide
|
|
| 119 | | | |
| 120 | | | |
| 121 | | | if (view->log->files->hdr.prev_file_seq != 0) { |
| 122 | | | |
| 123 | | | return 0; |
| 124 | | | } |
| 125 | | | |
| 126 | | | min_file_seq = view->log->files->hdr.file_seq; |
| 127 | | | min_file_offset = 0; |
| 128 | | | |
| 129 | | | if (max_file_seq == 0) { |
| 130 | | | max_file_seq = min_file_seq; |
| 131 | | | max_file_offset = min_file_offset; |
| 132 | | | } |
| 133 | | | } |
| 134 | | | |
| 135 | | | if (min_file_seq == view->log->files->hdr.prev_file_seq && |
Event 13:
Skipping " if". - min_file_seq == view->log->files->hdr.prev_file_seq evaluates to true.
- min_file_offset == view->log->files->hdr.prev_file_offset evaluates to false.
hide
|
|
| 136 | | | min_file_offset == view->log->files->hdr.prev_file_offset) { |
| 137 | | | |
| 138 | | | min_file_seq = view->log->files->hdr.file_seq; |
| 139 | | | min_file_offset = 0; |
| 140 | | | |
| 141 | | | if (min_file_seq > max_file_seq) { |
| 142 | | | |
| 143 | | | max_file_seq = min_file_seq; |
| 144 | | | max_file_offset = min_file_offset; |
| 145 | | | } |
| 146 | | | } |
| 147 | | | |
| 148 | | | if (min_file_seq == max_file_seq && min_file_offset > max_file_offset) { |
Event 14:
Skipping " if". min_file_seq == max_file_seq evaluates to false.
hide
|
|
| 149 | | | |
| 150 | | | mail_transaction_log_view_set_corrupted(view, |
| 151 | | | "file_seq=%u, min_file_offset (%"PRIuUOFF_T |
| 152 | | | ") > max_file_offset (%"PRIuUOFF_T")", |
| 153 | | | min_file_seq, min_file_offset, max_file_offset); |
| 154 | | | return -1; |
| 155 | | | } |
| 156 | | | |
| 157 | | | if (min_file_offset > 0 && |
Event 15:
Skipping " if". min_file_offset > 0 evaluates to false.
hide
|
|
| 158 | | | min_file_offset < view->log->files->hdr.hdr_size) { |
| 159 | | | |
| 160 | | | mail_transaction_log_view_set_corrupted(view, |
| 161 | | | "file_seq=%u, min_file_offset (%"PRIuUOFF_T |
| 162 | | | ") < hdr_size (%u)", |
| 163 | | | min_file_seq, min_file_offset, |
| 164 | | | view->log->files->hdr.hdr_size); |
| 165 | | | return -1; |
| 166 | | | } |
| 167 | | | |
| 168 | | | view->tail = view->head = file = NULL; |
Event 16:
file is set to NULL. - Dereferenced later, causing the null pointer dereference.
hide
Event 17:
view->head is set to file, which evaluates to NULL. See related event 16.
hide
Event 18:
view->tail is set to view->head, which evaluates to NULL. See related event 17.
hide
|
|
| 169 | | | for (seq = min_file_seq; seq <= max_file_seq; seq++) { |
Event 19:
Leaving loop. seq <= max_file_seq evaluates to false.
hide
|
|
| 170 | | | if (file == NULL || file->hdr.file_seq != seq) { |
| 171 | | | |
| 172 | | | |
| 173 | | | |
| 174 | | | bool nfs_flush = max_file_seq != (uint32_t)-1; |
| 175 | | | |
| 176 | | | ret = mail_transaction_log_find_file(view->log, seq, |
| 177 | | | nfs_flush, &file); |
| 178 | | | if (ret <= 0) { |
| 179 | | | if (ret < 0) |
| 180 211 |  | | [ Lines 180 to 211 omitted. ] |
| 212 | | | seq = file->hdr.file_seq; |
| 213 | | | view->tail = NULL; |
| 214 | | | } |
| 215 | | | |
| 216 | | | if (view->tail == NULL) |
| 217 | | | view->tail = file; |
| 218 | | | view->head = file; |
| 219 | | | file = file->next; |
| 220 | | | } |
| 221 | | | |
| 222 | | | if (min_file_offset == 0) { |
Event 20:
Skipping " if". min_file_offset == 0 evaluates to false.
hide
|
|
| 223 | | | |
| 224 | | | min_file_offset = view->tail->hdr.hdr_size; |
| 225 | | | if (min_file_offset > max_file_offset && |
| 226 | | | min_file_seq == max_file_seq) { |
| 227 | | | |
| 228 | | | max_file_offset = min_file_offset; |
| 229 | | | } |
| 230 | | | } |
| 231 | | | i_assert(min_file_offset >= view->tail->hdr.hdr_size);
x /home/sate/Testcases/c/cve/dovecot-1.2.0/src/lib/macros.h |
| |
189 | #define i_assert(expr) STMT_START{ \ |
190 | if (unlikely(!(expr))) \ |
191 | i_panic("file %s: line %d (%s): assertion failed: (%s)", \ |
192 | __FILE__, \ |
193 | __LINE__, \ |
194 | __PRETTY_FUNCTION__, \ |
195 | #expr); }STMT_END |
| |
|
Null Pointer Dereference
view->tail is dereferenced here, but it is NULL. The issue can occur if the highlighted code executes. See related event 18. Show: All events | Only primary events |
|
| |