security: harden untrusted-input handling (issue #148)
All checks were successful
CI Code / Check spelling (pull_request) Successful in 14s
CI Code / Check coding style (pull_request) Successful in 26s
CI Code / Code Coverage (pull_request) Successful in 3m29s
CI Code / Linux (debian) (pull_request) Successful in 5m13s
CI Code / Linux (ubuntu) (pull_request) Successful in 5m16s
CI Code / Linux (arch) (pull_request) Successful in 7m34s

T02: guard the receive-path handlers that dereferenced jid_create()
without a NULL check — MUC join errors, subscribed/unsubscribed
presence and, with silence.non-roster enabled, every incoming message.
A stanza with a missing or malformed 'from' crashed the client
(REQ-INP-01)

T11: restrict /url open and /url save to http, https and aesgcm, so a
received file:, javascript: or data: URL is refused (REQ-INP-06); spawn
terminal-notifier through g_spawn_async with an argv instead of
building a shell command for system() (REQ-INP-07); apply the XEP-0359
disco gate to MAM result ids, as live stanza-ids already do
(REQ-INP-05); replace control and bidi-reordering characters in
incoming message bodies with U+FFFD before they reach the terminal, the
logs and the database, keeping LRM/RLM for legitimate RTL text
(REQ-INP-08); cover JID part-length boundaries and invalid UTF-8
(REQ-INP-02)

T10: replace strcpy/strcat/alloca and sprintf with g_strdup_printf and
g_snprintf (REQ-MEM-03); allocate the OMEMO key buffers with g_malloc
so a failed allocation cannot reach the following memcpy (REQ-MEM-04);
remove the variable-length arrays and enforce -Werror=vla. Two of them
were sized from remote input: the disco#info feature count and a chat
message word length. The flag also caught a one-past-the-end write and
a leak in the plugin autocompleter bindings (REQ-MEM-09)
This commit is contained in:
2026-07-30 12:27:37 +03:00
parent d914e42ff6
commit 250703a0bf
30 changed files with 415 additions and 78 deletions

View File

@@ -1384,3 +1384,43 @@ str_xml_sanitize__strips_illegal_characters(void** state)
assert_string_equal("UTF-8: üñîçøðé and more", res5);
g_free(res5);
}
void
neutralize_untrusted_keeps_plain_text(void** state)
{
gchar* result = str_neutralize_untrusted("hello world\ttabbed\nnewline");
assert_string_equal("hello world\ttabbed\nnewline", result);
g_free(result);
}
void
neutralize_untrusted_replaces_escape_sequence(void** state)
{
gchar* result = str_neutralize_untrusted("safe\x1b[31mred");
assert_string_equal("safe\xef\xbf\xbd[31mred", result);
g_free(result);
}
void
neutralize_untrusted_replaces_bidi_override(void** state)
{
// U+202E RIGHT-TO-LEFT OVERRIDE
gchar* result = str_neutralize_untrusted("file\xe2\x80\xaegnp.exe");
assert_string_equal("file\xef\xbf\xbdgnp.exe", result);
g_free(result);
}
void
neutralize_untrusted_keeps_rtl_marks(void** state)
{
// U+200F RIGHT-TO-LEFT MARK is legitimate in RTL text
gchar* result = str_neutralize_untrusted("\xe2\x80\x8fשלום");
assert_string_equal("\xe2\x80\x8fשלום", result);
g_free(result);
}
void
neutralize_untrusted_handles_null(void** state)
{
assert_null(str_neutralize_untrusted(NULL));
}