tree 66e3bb8d1750d065491477c0b422577323acf8a0
parent 21fab69d332bfafd0a214ee29d8ad0779a055988
author Willy Tarreau <w@1wt.eu> 1451936219 +0100
committer Willy Tarreau <w@1wt.eu> 1456397251 +0100
encoding latin1

BUG/MINOR: chunk: make chunk_dup() always check and set dst->size

chunk_dup() was affected by two bugs at once related to dst->size :
  - first, it didn't check dst->size to know if it could free(dst->str),
    so using it on a statically allocated chunk would cause a free(constant)
    and crash the process ;

  - second, it didn't properly set dst->size, possibly causing smaller
    strings not to be properly reported in a chunk that was previously
    used for something else.

Fortunately, neither of these situations ever happened since the function
is rarely used.

In the process of doing this, we even allocate one more byte for a
trailing zero if the input chunk was not full, so that the copied
string can safely be reused by standard string functions.

The bug was introduced in 1.3.4 nine years ago with this commit :

  0f77253 ("[MINOR] store HTTP error messages into a chunk array")

It's better to backport this fix in case a future fix relies on it.
(cherry picked from commit f9476a5a308df570239ab0a57de2759600dd9cc2)
(cherry picked from commit b513fcf83fb6da15952bf2f8b00129d837f7d92f)
