diff options
| author | Ben Pfaff <blp@nicira.com> | 2010-12-15 09:48:16 -0800 |
|---|---|---|
| committer | Ben Pfaff <blp@nicira.com> | 2010-12-15 09:48:16 -0800 |
| commit | 4d0ed51998b35595474d62f6696928c8d0cd209e (patch) | |
| tree | 20d80191aadef2a978208fcfb7a591715589be84 /lib/nx-match.c | |
| parent | 94947cd83a796c4bf5a77fdf488662d0a0681c18 (diff) | |
| download | openvswitch-4d0ed51998b35595474d62f6696928c8d0cd209e.tar.gz | |
ofproto: Fix write-after-free error in compose_nx_flow_removed().
Diffstat (limited to 'lib/nx-match.c')
| -rw-r--r-- | lib/nx-match.c | 10 |
1 files changed, 10 insertions, 0 deletions
diff --git a/lib/nx-match.c b/lib/nx-match.c index c1d8fa84e..0b87fc92f 100644 --- a/lib/nx-match.c +++ b/lib/nx-match.c @@ -562,6 +562,16 @@ nxm_put_eth_dst(struct ofpbuf *b, } } +/* Appends to 'b' the nx_match format that expresses 'cr' (except for + * 'cr->priority', because priority is not part of nx_match), plus enough + * zero bytes to pad the nx_match out to a multiple of 8. + * + * This function can cause 'b''s data to be reallocated. + * + * Returns the number of bytes appended to 'b', excluding padding. + * + * If 'cr' is a catch-all rule that matches every packet, then this function + * appends nothing to 'b' and returns 0. */ int nx_put_match(struct ofpbuf *b, const struct cls_rule *cr) { |
