Skip to content

Commit f152be6

Browse files
committed
Fix corrupted sendmmsg() call
Before this fix, the buffer that holds cmsgs may move due to the resize() call. That causes msg_hdr pointing to invalid memory, which ends up breaking the sendmmsg() call, resulting in EINVAL. This change fixes it by avoiding re-allocating the buffers.
1 parent 6af11c1 commit f152be6

File tree

1 file changed

+5
-6
lines changed

1 file changed

+5
-6
lines changed

src/sys/socket/mod.rs

Lines changed: 5 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1101,23 +1101,22 @@ pub fn sendmmsg<'a, I, C>(
11011101

11021102
let mut output = Vec::<libc::mmsghdr>::with_capacity(reserve_items);
11031103

1104-
let mut cmsgs_buffer = vec![0u8; 0];
1104+
let mut cmsgs_buffers = Vec::<Vec<u8>>::with_capacity(reserve_items);
11051105

11061106
for d in iter {
1107-
let cmsgs_start = cmsgs_buffer.len();
1108-
let cmsgs_required_capacity: usize = d.cmsgs.as_ref().iter().map(|c| c.space()).sum();
1109-
let cmsgs_buffer_need_capacity = cmsgs_start + cmsgs_required_capacity;
1110-
cmsgs_buffer.resize(cmsgs_buffer_need_capacity, 0);
1107+
let capacity: usize = d.cmsgs.as_ref().iter().map(|c| c.space()).sum();
1108+
let mut cmsgs_buffer = vec![0u8; capacity];
11111109

11121110
output.push(libc::mmsghdr {
11131111
msg_hdr: pack_mhdr_to_send(
1114-
&mut cmsgs_buffer[cmsgs_start..],
1112+
&mut cmsgs_buffer,
11151113
&d.iov,
11161114
&d.cmsgs,
11171115
d.addr.as_ref()
11181116
),
11191117
msg_len: 0,
11201118
});
1119+
cmsgs_buffers.push(cmsgs_buffer);
11211120
};
11221121

11231122
let ret = unsafe { libc::sendmmsg(fd, output.as_mut_ptr(), output.len() as _, flags.bits() as _) };

0 commit comments

Comments
 (0)