Commit 6d65a8a
authored
fix: fix dv descriptor map insert potential FFI pointer leak (#3265)
## What changes are proposed in this pull request?
<!--
**Uncomment** this section if there are any changes affecting public
APIs. Else, **delete** this section.
### This PR affects the following public APIs
If there are breaking changes, please ensure the `breaking-changes`
label gets added by CI, and describe why the changes are needed.
Note that _new_ public APIs are not considered breaking.
-->
Currently, the rust -> FFI bridge -> caller contract is built on the
following assumption:
1. **Borrow:** Rust accesses the handle with `as_ref()` (`&T`) or
`as_mut()` (`& mut T`). The caller retains ownership and remains
responsible for passing the handle to its `free_*` function.
2. **Unconditional consume:** Rust calls `into_inner()` before any
fallible work. Rust owns the value from native entry onward and is
responsible for dropping it on every result, including errors. The
caller must not use or free the handle after the call.
The `dv_descriptor_map_insert` did not comply with either of these 2
above invariants, as it ran potentially errorsome checks against an
input string pointer before taking ownership of said pointer. This made
it difficult for FFI callers to know when it was safe to consider the
native memory fully handed-off to Rust.
This PR ensures `dv_descriptor_map_insert` takes full ownership of the
provided pointer before running path compliance checks so it remains
compliant with the second invariant above. The intended goal of this is
to make FFI integrations easier at the connector level, and pass more of
the implementation complexity onto core kernel.
## How was this change tested?
UTs1 parent 4724eef commit 6d65a8a
3 files changed
Lines changed: 89 additions & 26 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
20 | 33 | | |
21 | 34 | | |
22 | 35 | | |
| |||
166 | 179 | | |
167 | 180 | | |
168 | 181 | | |
169 | | - | |
170 | | - | |
171 | | - | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
172 | 185 | | |
173 | 186 | | |
174 | 187 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
163 | 163 | | |
164 | 164 | | |
165 | 165 | | |
| 166 | + | |
166 | 167 | | |
167 | 168 | | |
168 | 169 | | |
169 | 170 | | |
170 | 171 | | |
171 | | - | |
172 | 172 | | |
173 | 173 | | |
174 | 174 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
57 | 57 | | |
58 | 58 | | |
59 | 59 | | |
60 | | - | |
61 | | - | |
| 60 | + | |
| 61 | + | |
62 | 62 | | |
63 | 63 | | |
64 | 64 | | |
| |||
173 | 173 | | |
174 | 174 | | |
175 | 175 | | |
176 | | - | |
177 | | - | |
178 | | - | |
| 176 | + | |
| 177 | + | |
179 | 178 | | |
180 | 179 | | |
181 | 180 | | |
| |||
185 | 184 | | |
186 | 185 | | |
187 | 186 | | |
188 | | - | |
| 187 | + | |
| 188 | + | |
189 | 189 | | |
190 | 190 | | |
191 | 191 | | |
| |||
195 | 195 | | |
196 | 196 | | |
197 | 197 | | |
198 | | - | |
199 | | - | |
200 | | - | |
| 198 | + | |
201 | 199 | | |
202 | | - | |
| 200 | + | |
203 | 201 | | |
204 | 202 | | |
205 | 203 | | |
206 | 204 | | |
207 | 205 | | |
208 | 206 | | |
209 | 207 | | |
210 | | - | |
| 208 | + | |
211 | 209 | | |
212 | 210 | | |
213 | 211 | | |
214 | | - | |
215 | | - | |
| 212 | + | |
216 | 213 | | |
217 | 214 | | |
218 | 215 | | |
| |||
270 | 267 | | |
271 | 268 | | |
272 | 269 | | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
273 | 274 | | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
274 | 292 | | |
275 | 293 | | |
276 | 294 | | |
| |||
335 | 353 | | |
336 | 354 | | |
337 | 355 | | |
338 | | - | |
| 356 | + | |
339 | 357 | | |
340 | 358 | | |
341 | 359 | | |
342 | | - | |
| 360 | + | |
343 | 361 | | |
344 | | - | |
| 362 | + | |
| 363 | + | |
| 364 | + | |
345 | 365 | | |
346 | 366 | | |
347 | 367 | | |
348 | 368 | | |
349 | | - | |
| 369 | + | |
350 | 370 | | |
351 | 371 | | |
352 | | - | |
353 | | - | |
354 | | - | |
355 | | - | |
| 372 | + | |
356 | 373 | | |
357 | | - | |
| 374 | + | |
| 375 | + | |
| 376 | + | |
| 377 | + | |
| 378 | + | |
| 379 | + | |
| 380 | + | |
| 381 | + | |
| 382 | + | |
| 383 | + | |
| 384 | + | |
| 385 | + | |
| 386 | + | |
| 387 | + | |
| 388 | + | |
| 389 | + | |
| 390 | + | |
| 391 | + | |
| 392 | + | |
| 393 | + | |
| 394 | + | |
| 395 | + | |
| 396 | + | |
| 397 | + | |
| 398 | + | |
| 399 | + | |
| 400 | + | |
| 401 | + | |
| 402 | + | |
| 403 | + | |
| 404 | + | |
| 405 | + | |
| 406 | + | |
| 407 | + | |
358 | 408 | | |
359 | 409 | | |
0 commit comments