[PATCH] corelib: Initialize strictssl to avoid uninitialized value

12 views
Skip to first unread message

Shota Shimoyama

unread,
Sep 23, 2026, 9:21:20 PMSep 23
to swup...@googlegroups.com
Initialize tmp_bool to false in channel_settings() before calling
GET_FIELD_BOOL().

If the "nocheckcert" option is omitted from the configuration file,
GET_FIELD_BOOL() returns early without modifying tmp_bool. Previously,
this left tmp_bool uninitialized, causing chan->strictssl to be assigned
an indeterminate value. Consequently, subsequent checks on strictssl
triggered a Valgrind warning:

Conditional jump or move depends on uninitialised value(s)
at 0x1490BB: channel_set_options (channel_curl.c:753)
Uninitialised value was created by a stack allocation
at 0x1557F6: channel_settings (server_utils.c:20)

Reviewed-by: Dominique Martinet <dominique...@atmark-techno.com>
Signed-off-by: Shota Shimoyama <shota.s...@atmark-techno.com>
---
corelib/server_utils.c | 1 +
1 file changed, 1 insertion(+)

diff --git a/corelib/server_utils.c b/corelib/server_utils.c
index 13923d50..aab99740 100644
--- a/corelib/server_utils.c
+++ b/corelib/server_utils.c
@@ -36,6 +36,7 @@ int channel_settings(void *elem, void *data)
if (strlen(tmp))
chan->retry_sleep =
(unsigned int)strtoul(tmp, NULL, 10);
+ tmp_bool = false;
GET_FIELD_BOOL(LIBCFG_PARSER, elem, "nocheckcert", &tmp_bool);
chan->strictssl = !tmp_bool;
GET_FIELD_STRING_RESET(LIBCFG_PARSER, elem, "cafile", tmp);
--
2.34.1

Stefano Babic

unread,
Sep 28, 2026, 6:32:49 AM (11 days ago) Sep 28
to Shota Shimoyama, swup...@googlegroups.com
Reviewed-by: Stefano Babic <stefan...@swupdate.org>

--
_______________________________________________________________________
Nabla Software Engineering GmbH
Hirschstr. 111A | 86156 Augsburg | Tel: +49 821 45592596
Geschäftsführer : Stefano Babic | HRB 40522 Augsburg
E-Mail: sba...@nabladev.com

Reply all
Reply to author
Forward
0 new messages