[LTP] [PATCH 1/3] LTP/Lite test float_trigo core dumps due to free(): invalid pointer

Tomas Dzik tdzik@redhat.com
Wed Jul 15 15:04:46 CEST 2026


Function read_file() does not initialize *data on failure paths
(for example if malloc() fails) and caller ends up calling SAFE_FREE()
on an uninitialized pointer.

    Here is the log from failed run:
    ~==== float_trigo ====
    command: float_trigo -v
    float_trigo    0  TINFO  :  Using /tmp/LTP_floJSug25 as tmpdir (xfs
    filesystem)
    float_trigo    1  TPASS  :  Test passed
    float_trigo    0  TINFO  :  float_trigo: will run for 500 loops;
    using . as a data directory
    float_trigo    0  TINFO  :  float_trigo: will run 7 functions, 20
    threads per function
    float_trigo    0  TINFO  :  signal handler 140451533870784 started
    float_trigo    0  TINFO  :  Signal handler starts waiting...
    free(): invalid pointer

    Duration: 0.926

This fix initializes pointers where we actually core dumped (*din, *dex).

Signed-off-by: Tomas Dzik <tdzik@redhat.com>
---
 testcases/misc/math/float/thread_code.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/testcases/misc/math/float/thread_code.c b/testcases/misc/math/float/thread_code.c
index ca18cef1e..6f3a463dd 100644
--- a/testcases/misc/math/float/thread_code.c
+++ b/testcases/misc/math/float/thread_code.c
@@ -278,7 +278,12 @@ void *thread_code(void *arg)
 {
 	TH_DATA *th_data = (TH_DATA *) arg;
 	size_t fsize, fsize2, fsize3;
-	double *din, *dex, *dex2 = NULL;
+	/*
+	 * If read_file() fails for whatever reason, these pointers might
+	 * stay uninitialized. Initialize them to NULL, because SAFE_FREE()
+	 * can handle it.
+	 */
+	double *din = NULL, *dex = NULL, *dex2 = NULL;
 	int imax, index;
 
 	fsize = read_file(th_data->th_func.din_fname, (void **)&din);
-- 
2.55.0



More information about the ltp mailing list