dict_set_bin() is handling the pointer that it passed inconsistently. Depending on the errors that can occur, the pointer passed to the dict can be free'd, but there is no guarantee. It is cleaner to have the caller free the pointer that allocated it and dict_set_bin() returned an error. When dict_set_bin() returned success, the given pointer will be free'd when dict_unref() calls data_destroy(). Many callers of dict_set_bin() already take care of free'ing the pointer on error. The ones that did not, are corrected with this change too. Change-Id: I39a4f7ebc0cae6d403baba99307d7ce408f25966 BUG: 1242280 Signed-off-by: Niels de Vos <> Reviewed-on: Tested-by: Gluster Build System <> Reviewed-by: jiffin tony Thottan <> Reviewed-by: Raghavendra G <> Tested-by: NetBSD Build System <>
@@ -1345,8 +1345,10 @@ br_stub_getxattr_cbk (call_frame_t *frame, void *cookie, xlator_t *this,
op_errno = EINVAL;
ret = dict_set_bin (xattr, GLUSTERFS_GET_OBJECT_SIGNATURE,
(void *)sign, totallen);
- if (ret < 0)
+ if (ret < 0) {
+ GF_FREE (sign);
goto delkeys;
+ }
op_errno = 0;
op_ret = totallen;