Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit b51456a6 authored by Ilya Dryomov's avatar Ilya Dryomov
Browse files

libceph: fix error handling in process_one_ticket()



Don't leak key internals after new_session_key is populated.

Signed-off-by: default avatarIlya Dryomov <idryomov@gmail.com>
Reviewed-by: default avatarAlex Elder <elder@linaro.org>
parent d18a1247
Loading
Loading
Loading
Loading
+5 −5
Original line number Diff line number Diff line
@@ -151,7 +151,7 @@ static int process_one_ticket(struct ceph_auth_client *ac,
	struct timespec validity;
	void *tp, *tpend;
	void **ptp;
	struct ceph_crypto_key new_session_key;
	struct ceph_crypto_key new_session_key = { 0 };
	struct ceph_buffer *new_ticket_blob;
	unsigned long new_expires, new_renew_after;
	u64 new_secret_id;
@@ -237,13 +237,13 @@ static int process_one_ticket(struct ceph_auth_client *ac,
	     type, ceph_entity_type_name(type), th->secret_id,
	     (int)th->ticket_blob->vec.iov_len);
	xi->have_keys |= th->service;

out:
	return ret;
	return 0;

bad:
	ret = -EINVAL;
	goto out;
out:
	ceph_crypto_key_destroy(&new_session_key);
	return ret;
}

static int ceph_x_proc_ticket_reply(struct ceph_auth_client *ac,