Bug Summary

File:root/firefox-clang/third_party/msgpack/src/vrefbuffer.c
Warning:line 118, column 26
Use of memory allocated with size zero

Annotated Source Code

Press '?' to see keyboard shortcuts

clang -cc1 -cc1 -triple x86_64-pc-linux-gnu -O2 -analyze -disable-free -clear-ast-before-backend -disable-llvm-verifier -discard-value-names -main-file-name vrefbuffer.c -analyzer-checker=core -analyzer-checker=apiModeling -analyzer-checker=unix -analyzer-checker=deadcode -analyzer-checker=security.insecureAPI.UncheckedReturn -analyzer-checker=security.insecureAPI.getpw -analyzer-checker=security.insecureAPI.gets -analyzer-checker=security.insecureAPI.mktemp -analyzer-checker=security.insecureAPI.mkstemp -analyzer-checker=security.insecureAPI.vfork -analyzer-checker=nullability.NullPassedToNonnull -analyzer-checker=nullability.NullReturnedFromNonnull -analyzer-output plist -w -setup-static-analyzer -analyzer-config-compatibility-mode=true -mrelocation-model pic -pic-level 2 -fhalf-no-semantic-interposition -mframe-pointer=all -relaxed-aliasing -ffp-contract=off -fno-rounding-math -mconstructor-aliases -funwind-tables=2 -target-cpu x86-64 -tune-cpu generic -debugger-tuning=gdb -fdebug-compilation-dir=/root/firefox-clang/obj-x86_64-pc-linux-gnu/third_party/msgpack -fcoverage-compilation-dir=/root/firefox-clang/obj-x86_64-pc-linux-gnu/third_party/msgpack -resource-dir /usr/lib/llvm-23/lib/clang/23 -include /root/firefox-clang/config/gcc_hidden.h -include /root/firefox-clang/obj-x86_64-pc-linux-gnu/mozilla-config.h -I /root/firefox-clang/obj-x86_64-pc-linux-gnu/dist/system_wrappers -U _FORTIFY_SOURCE -D _FORTIFY_SOURCE=2 -D DEBUG=1 -D MSGPACK_DLLEXPORT= -D MOZ_HAS_MOZGLUE -D MOZILLA_INTERNAL_API -D IMPL_LIBXUL -D MOZ_SUPPORT_LEAKCHECKING -D STATIC_EXPORTABLE_JS_API -I /root/firefox-clang/third_party/msgpack -I /root/firefox-clang/obj-x86_64-pc-linux-gnu/third_party/msgpack -I /root/firefox-clang/third_party/msgpack/include -I /root/firefox-clang/obj-x86_64-pc-linux-gnu/dist/include -I /root/firefox-clang/obj-x86_64-pc-linux-gnu/dist/include/nspr -I /root/firefox-clang/obj-x86_64-pc-linux-gnu/dist/include/nss -D MOZILLA_CLIENT -internal-isystem /usr/lib/llvm-23/lib/clang/23/include -internal-isystem /usr/local/include -internal-isystem /usr/lib/gcc/x86_64-linux-gnu/16/../../../../x86_64-linux-gnu/include -internal-externc-isystem /usr/include/x86_64-linux-gnu -internal-externc-isystem /include -internal-externc-isystem /usr/include -Wno-error=tautological-type-limit-compare -Wno-range-loop-analysis -Wno-error=deprecated-declarations -Wno-error=array-bounds -Wno-error=free-nonheap-object -Wno-error=atomic-alignment -Wno-error=deprecated-builtins -Wno-psabi -Wno-error=builtin-macro-redefined -Wno-unknown-warning-option -Wno-character-conversion -ferror-limit 19 -fstrict-flex-arrays=1 -stack-protector 2 -fstack-clash-protection -ftrivial-auto-var-init=pattern -fgnuc-version=4.2.1 -fskip-odr-check-in-gmf -fdiagnostics-absolute-paths -vectorize-loops -vectorize-slp -analyzer-checker optin.performance.Padding -analyzer-output=html -analyzer-config stable-report-filename=true -mllvm -dwarf-linkage-names=Abstract -faddrsig -fdwarf2-cfi-asm -o /tmp/scan-build-2026-09-01-224014-2642839-1 -x c /root/firefox-clang/third_party/msgpack/src/vrefbuffer.c
1/*
2 * MessagePack for C zero-copy buffer implementation
3 *
4 * Copyright (C) 2008-2009 FURUHASHI Sadayuki
5 *
6 * Distributed under the Boost Software License, Version 1.0.
7 * (See accompanying file LICENSE_1_0.txt or copy at
8 * http://www.boost.org/LICENSE_1_0.txt)
9 */
10#include "msgpack/vrefbuffer.h"
11#include <stdlib.h>
12#include <string.h>
13
14#define MSGPACK_PACKER_MAX_BUFFER_SIZE9 9
15
16struct msgpack_vrefbuffer_chunk {
17 struct msgpack_vrefbuffer_chunk* next;
18 /* data ... */
19};
20
21bool_Bool msgpack_vrefbuffer_init(msgpack_vrefbuffer* vbuf,
22 size_t ref_size, size_t chunk_size)
23{
24 size_t nfirst;
25 struct iovec* array;
26 msgpack_vrefbuffer_chunk* chunk;
27
28 vbuf->chunk_size = chunk_size;
29 vbuf->ref_size =
30 ref_size > MSGPACK_PACKER_MAX_BUFFER_SIZE9 + 1 ?
31 ref_size : MSGPACK_PACKER_MAX_BUFFER_SIZE9 + 1 ;
32
33 nfirst = (sizeof(struct iovec) < 72/2) ?
34 72 / sizeof(struct iovec) : 8;
35
36 array = (struct iovec*)malloc(
37 sizeof(struct iovec) * nfirst);
38 if(array == NULL((void*)0)) {
39 return false0;
40 }
41
42 vbuf->tail = array;
43 vbuf->end = array + nfirst;
44 vbuf->array = array;
45
46 chunk = (msgpack_vrefbuffer_chunk*)malloc(
47 sizeof(msgpack_vrefbuffer_chunk) + chunk_size);
48 if(chunk == NULL((void*)0)) {
49 free(array);
50 return false0;
51 }
52 else {
53 msgpack_vrefbuffer_inner_buffer* const ib = &vbuf->inner_buffer;
54
55 ib->free = chunk_size;
56 ib->ptr = ((char*)chunk) + sizeof(msgpack_vrefbuffer_chunk);
57 ib->head = chunk;
58 chunk->next = NULL((void*)0);
59
60 return true1;
61 }
62}
63
64void msgpack_vrefbuffer_destroy(msgpack_vrefbuffer* vbuf)
65{
66 msgpack_vrefbuffer_chunk* c = vbuf->inner_buffer.head;
67 while(true1) {
68 msgpack_vrefbuffer_chunk* n = c->next;
69 free(c);
70 if(n != NULL((void*)0)) {
71 c = n;
72 } else {
73 break;
74 }
75 }
76 free(vbuf->array);
77}
78
79void msgpack_vrefbuffer_clear(msgpack_vrefbuffer* vbuf)
80{
81 msgpack_vrefbuffer_chunk* c = vbuf->inner_buffer.head->next;
82 msgpack_vrefbuffer_chunk* n;
83 while(c != NULL((void*)0)) {
84 n = c->next;
85 free(c);
86 c = n;
87 }
88
89 {
90 msgpack_vrefbuffer_inner_buffer* const ib = &vbuf->inner_buffer;
91 msgpack_vrefbuffer_chunk* chunk = ib->head;
92 chunk->next = NULL((void*)0);
93 ib->free = vbuf->chunk_size;
94 ib->ptr = ((char*)chunk) + sizeof(msgpack_vrefbuffer_chunk);
95
96 vbuf->tail = vbuf->array;
97 }
98}
99
100int msgpack_vrefbuffer_append_ref(msgpack_vrefbuffer* vbuf,
101 const char* buf, size_t len)
102{
103 if(vbuf->tail == vbuf->end) {
5
Assuming field 'tail' is equal to field 'end'
6
Taking true branch
104 const size_t nused = (size_t)(vbuf->tail - vbuf->array);
105 const size_t nnext = nused * 2;
106
107 struct iovec* nvec = (struct iovec*)realloc(
108 vbuf->array, sizeof(struct iovec)*nnext);
109 if(nvec == NULL((void*)0)) {
7
Assuming 'nvec' is not equal to NULL
8
Taking false branch
110 return -1;
111 }
112
113 vbuf->array = nvec;
114 vbuf->end = nvec + nnext;
115 vbuf->tail = nvec + nused;
116 }
117
118 vbuf->tail->iov_base = (char*)buf;
9
Use of memory allocated with size zero
119 vbuf->tail->iov_len = len;
120 ++vbuf->tail;
121
122 return 0;
123}
124
125int msgpack_vrefbuffer_append_copy(msgpack_vrefbuffer* vbuf,
126 const char* buf, size_t len)
127{
128 msgpack_vrefbuffer_inner_buffer* const ib = &vbuf->inner_buffer;
129 char* m;
130
131 if(ib->free < len) {
1
Assuming 'len' is <= field 'free'
2
Taking false branch
132 msgpack_vrefbuffer_chunk* chunk;
133 size_t sz = vbuf->chunk_size;
134 if(sz < len) {
135 sz = len;
136 }
137
138 chunk = (msgpack_vrefbuffer_chunk*)malloc(
139 sizeof(msgpack_vrefbuffer_chunk) + sz);
140 if(chunk == NULL((void*)0)) {
141 return -1;
142 }
143
144 chunk->next = ib->head;
145 ib->head = chunk;
146 ib->free = sz;
147 ib->ptr = ((char*)chunk) + sizeof(msgpack_vrefbuffer_chunk);
148 }
149
150 m = ib->ptr;
151 memcpy(m, buf, len);
152 ib->free -= len;
153 ib->ptr += len;
154
155 if(vbuf->tail != vbuf->array && m ==
3
Assuming field 'tail' is equal to field 'array'
156 (const char*)((vbuf->tail-1)->iov_base) + (vbuf->tail-1)->iov_len) {
157 (vbuf->tail-1)->iov_len += len;
158 return 0;
159 } else {
160 return msgpack_vrefbuffer_append_ref(vbuf, m, len);
4
Calling 'msgpack_vrefbuffer_append_ref'
161 }
162}
163
164int msgpack_vrefbuffer_migrate(msgpack_vrefbuffer* vbuf, msgpack_vrefbuffer* to)
165{
166 size_t sz = vbuf->chunk_size;
167
168 msgpack_vrefbuffer_chunk* empty = (msgpack_vrefbuffer_chunk*)malloc(
169 sizeof(msgpack_vrefbuffer_chunk) + sz);
170 if(empty == NULL((void*)0)) {
171 return -1;
172 }
173
174 empty->next = NULL((void*)0);
175
176 {
177 const size_t nused = (size_t)(vbuf->tail - vbuf->array);
178 if(to->tail + nused < vbuf->end) {
179 struct iovec* nvec;
180 const size_t tosize = (size_t)(to->tail - to->array);
181 const size_t reqsize = nused + tosize;
182 size_t nnext = (size_t)(to->end - to->array) * 2;
183 while(nnext < reqsize) {
184 size_t tmp_nnext = nnext * 2;
185 if (tmp_nnext <= nnext) {
186 nnext = reqsize;
187 break;
188 }
189 nnext = tmp_nnext;
190 }
191
192 nvec = (struct iovec*)realloc(
193 to->array, sizeof(struct iovec)*nnext);
194 if(nvec == NULL((void*)0)) {
195 free(empty);
196 return -1;
197 }
198
199 to->array = nvec;
200 to->end = nvec + nnext;
201 to->tail = nvec + tosize;
202 }
203
204 memcpy(to->tail, vbuf->array, sizeof(struct iovec)*nused);
205
206 to->tail += nused;
207 vbuf->tail = vbuf->array;
208
209 {
210 msgpack_vrefbuffer_inner_buffer* const ib = &vbuf->inner_buffer;
211 msgpack_vrefbuffer_inner_buffer* const toib = &to->inner_buffer;
212
213 msgpack_vrefbuffer_chunk* last = ib->head;
214 while(last->next != NULL((void*)0)) {
215 last = last->next;
216 }
217 last->next = toib->head;
218 toib->head = ib->head;
219
220 if(toib->free < ib->free) {
221 toib->free = ib->free;
222 toib->ptr = ib->ptr;
223 }
224
225 ib->head = empty;
226 ib->free = sz;
227 ib->ptr = ((char*)empty) + sizeof(msgpack_vrefbuffer_chunk);
228 }
229 }
230
231 return 0;
232}