[Dnsmasq-discuss] [PATCH] Don't hand a NULL hostname to my_syslog() in slaac_ping_reply().
Martin Vlach
userhuge at gmail.com
Wed Sep 30 23:00:05 UTC 2026
slaac_add_addrs() won't create SLAAC addresses for a lease without a
hostname, but addresses already attached to a lease stay around if the
hostname goes away later, e.g. via kill_name() when another client
claims the same name. A matching ICMPv6 echo reply then makes
slaac_ping_reply() pass lease->hostname == NULL to a %s format, which is
undefined behaviour (glibc and musl just print "(null)").
Log "*" in that case, like the lease file code in lease.c already does.
Co-Authored-By: Claude Sonnet 5.5 <noreply at anthropic.com>
---
Another one from the same BudgetScan run. On glibc/musl it's purely
cosmetic ("(null)" in the log), so take it or leave it.
It can happen without DHCPv6: a second DHCPv4 client claiming the same
(client supplied) name makes lease_set_hostname() call kill_name() on the
first lease while that one still has an unconfirmed SLAAC address
(backoff != 0), and the echo reply then hits the log line. Found by
reading the code, I haven't reproduced it at runtime. Builds fine (macOS
only).
src/slaac.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/src/slaac.c b/src/slaac.c
index ca92ac0..f696fdb 100644
--- a/src/slaac.c
+++ b/src/slaac.c
@@ -204,7 +204,7 @@ void slaac_ping_reply(struct in6_addr *sender, unsigned char *packet, char *inte
gotone = 1;
inet_ntop(AF_INET6, sender, daemon->addrbuff, ADDRSTRLEN);
if (!option_bool(OPT_QUIET_DHCP6))
- my_syslog(MS_DHCP | LOG_INFO, "SLAAC-CONFIRM(%s) %s %s", interface, daemon->addrbuff, lease->hostname);
+ my_syslog(MS_DHCP | LOG_INFO, "SLAAC-CONFIRM(%s) %s %s", interface, daemon->addrbuff, lease->hostname ? lease->hostname : "*");
}
lease_update_dns(gotone);
More information about the Dnsmasq-discuss
mailing list