eal: fix use-after-free on control thread creation
[dpdk.git] / lib / librte_eal / common / eal_common_thread.c
index fcf00cd..4239863 100644 (file)
@@ -149,11 +149,16 @@ struct rte_thread_ctrl_params {
 
 static void *rte_thread_init(void *arg)
 {
+       int ret;
        struct rte_thread_ctrl_params *params = arg;
        void *(*start_routine)(void *) = params->start_routine;
        void *routine_arg = params->arg;
 
-       pthread_barrier_wait(&params->configured);
+       ret = pthread_barrier_wait(&params->configured);
+       if (ret == PTHREAD_BARRIER_SERIAL_THREAD) {
+               pthread_barrier_destroy(&params->configured);
+               free(params);
+       }
 
        return start_routine(routine_arg);
 }
@@ -163,19 +168,25 @@ rte_ctrl_thread_create(pthread_t *thread, const char *name,
                const pthread_attr_t *attr,
                void *(*start_routine)(void *), void *arg)
 {
-       struct rte_thread_ctrl_params params = {
-               .start_routine = start_routine,
-               .arg = arg,
-       };
+       struct rte_thread_ctrl_params *params;
        unsigned int lcore_id;
        rte_cpuset_t cpuset;
        int cpu_found, ret;
 
-       pthread_barrier_init(&params.configured, NULL, 2);
+       params = malloc(sizeof(*params));
+       if (!params)
+               return -1;
+
+       params->start_routine = start_routine;
+       params->arg = arg;
 
-       ret = pthread_create(thread, attr, rte_thread_init, (void *)&params);
-       if (ret != 0)
+       pthread_barrier_init(&params->configured, NULL, 2);
+
+       ret = pthread_create(thread, attr, rte_thread_init, (void *)params);
+       if (ret != 0) {
+               free(params);
                return ret;
+       }
 
        if (name != NULL) {
                ret = rte_thread_setname(*thread, name);
@@ -200,11 +211,20 @@ rte_ctrl_thread_create(pthread_t *thread, const char *name,
        if (ret < 0)
                goto fail;
 
-       pthread_barrier_wait(&params.configured);
+       ret = pthread_barrier_wait(&params->configured);
+       if (ret == PTHREAD_BARRIER_SERIAL_THREAD) {
+               pthread_barrier_destroy(&params->configured);
+               free(params);
+       }
 
        return 0;
 
 fail:
+       if (PTHREAD_BARRIER_SERIAL_THREAD ==
+           pthread_barrier_wait(&params->configured)) {
+               pthread_barrier_destroy(&params->configured);
+               free(params);
+       }
        pthread_cancel(*thread);
        pthread_join(*thread, NULL);
        return ret;