BUG: Free the header on nifti_tool's duplicate-file failure paths - #60
Merged
hjmjohnson merged 1 commit intoSep 21, 2026
Conversation
This was referenced Aug 15, 2026
This was referenced Aug 15, 2026
gdevenyi
marked this pull request as ready for review
August 15, 2026 05:26
act_mod_hdrs(), act_mod_hdr2s() and act_swap_hdrs() -- five functions
across the two tools -- read a header, then, when -prefix is given,
duplicate the dataset before writing the modified header back. Each of
the three ways that duplication can fail returns without freeing the
header, and the last of them also loses the strdup'd duplicate name:
nhdr = nt_read_header(fname, &nver, &swap, 0, ...);
...
if( opts->prefix ) {
nim = nt_image_read(opts, fname, 1, 1);
if( !nim ) { fprintf(...); return 1; } /* nhdr */
if( nifti_set_filenames(nim, opts->prefix, 1, 1) ) {
nifti_image_free(nim); return 1; /* nhdr */
}
dupname = nifti_strdup(nim->fname);
if( nifti_image_write_status(nim) ) {
nifti_image_free(nim); return 1; /* nhdr, dupname */
}
}
...
free(dupname);
free(nhdr);
The normal path frees both. Reproduced by pointing -prefix at a
directory that cannot be written:
nifti_tool -mod_hdr -prefix <read-only dir>/anat1 -infiles anat0.nii \
-mod_field qoffset_x -17.325
before: definitely lost: 348 bytes in 1 blocks
after: ERROR SUMMARY: 0 errors from 0 contexts
Separately, act_diff_nims() in both tools releases the first image with
free(nim0) when reading the second one fails. That is a shallow free: it
loses nim0's fname, iname and any data or extensions. It now calls
nifti_image_free() like the success path six lines below.
Found by running the test suite under valgrind. On the normal paths the
suite is clean -- 484 traced processes, no invalid access, no
uninitialised value and no leak in any nifti binary -- so these are
error-path defects that the tests do not otherwise reach.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KSPnbwpDjVcAYqDdVqLkMU
hjmjohnson
force-pushed
the
pr/fix-tool-error-path-leaks
branch
from
September 21, 2026 23:29
90c7a50 to
23b9d0d
Compare
hjmjohnson
approved these changes
Sep 21, 2026
hjmjohnson
merged commit Sep 21, 2026
744e751
into
InsightSoftwareConsortium:master
17 of 21 checks passed
Member
|
The commit messages in this range were rewritten to remove trailers that do not belong in permanent history: This PR's commit on the rewritten
The SHA recorded above by GitHub is from the pre-rewrite history and no longer resolves. |
This was referenced Sep 24, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
act_mod_hdrs(), act_mod_hdr2s() and act_swap_hdrs() -- five functions
across the two tools -- read a header, then, when -prefix is given,
duplicate the dataset before writing the modified header back. Each of
the three ways that duplication can fail returns without freeing the
header, and the last of them also loses the strdup'd duplicate name:
The normal path frees both. Reproduced by pointing -prefix at a
directory that cannot be written:
before: definitely lost: 348 bytes in 1 blocks
after: ERROR SUMMARY: 0 errors from 0 contexts
Separately, act_diff_nims() in both tools releases the first image with
free(nim0) when reading the second one fails. That is a shallow free: it
loses nim0's fname, iname and any data or extensions. It now calls
nifti_image_free() like the success path six lines below.
Found by running the test suite under valgrind. On the normal paths the
suite is clean -- 484 traced processes, no invalid access, no
uninitialised value and no leak in any nifti binary -- so these are
error-path defects that the tests do not otherwise reach.
Interface impact: none. On the union of all these changes, configured with
USE_FSL_CODE=ONandUSE_CIFTI_CODE=ON: all 448 exported symbols acrosslibniftiio,libnifti2,libznz,libfslio,libnifticdfandlibciftiare identical tomasterundernm -D --defined-only, and all ten installed headers are identical undergcc -E -P. Undergcc -dM -Eone macro definition differs, intentionally and only in text: #61 makesFSL_RADIOLOGICALread(-1)so it is safe inside an expression. Its value is still-1, checked by compiling against each installedfslio.hand printing it.Verification. This branch: builds with gcc 16.1.1,
ctestunchanged frommaster(2 of 345 fail onmasteritself in this environment; #31 and #29 each fix one). The union of all the PRs: 0 errors under both gcc 16.1.1 and clang 22.1.8,ctest345/345 under each, and the whole suite under valgrind memcheck with--trace-children=yesgives 484 traced processes with no invalid access, no uninitialised value and no leak in any nifti binary.Coordination. Every line of every branch was compared, whitespace-normalised, against the diffs of the open PRs (#11, #21, #22, #23, #24). Where one of those already changes a line, the line was left alone, and the few deliberate overlaps are named in the text above. What survives is 17 compiler warnings, all of them on those lines: 9
-Wsign-conversion(5 infslio.cfor #22, 2 innifti2_io.cand 2 innifti_tester001.cfor #24) and 8-Wcalloc-transposed-argsinnifti_findhdrnameandnifti_findimgname, which #11 rewrites. No formatting changes appear anywhere, to stay clear of #10 and #12.One of a set of independent, single-purpose PRs. Each bases on
masterand can be merged on its own, in any order.The full set of PRs (35)
The union of all of them is on the fork as
all-changes, if you want to build and test the lot at once.CI and build
Configuration and documentation
Defects
Warning and check classes