fix: OTR/presence/OMEMO correctness, stanza-id disco gate, build hardening
All checks were successful
CI Code / Check spelling (push) Successful in 17s
CI Code / Check coding style (push) Successful in 32s
CI Code / Code Coverage (push) Successful in 3m45s
CI Code / Linux (debian) (push) Successful in 4m42s
CI Code / Linux (ubuntu) (push) Successful in 4m49s
CI Code / Linux (arch) (push) Successful in 6m25s
All checks were successful
CI Code / Check spelling (push) Successful in 17s
CI Code / Check coding style (push) Successful in 32s
CI Code / Code Coverage (push) Successful in 3m45s
CI Code / Linux (debian) (push) Successful in 4m42s
CI Code / Linux (ubuntu) (push) Successful in 4m49s
CI Code / Linux (arch) (push) Successful in 6m25s
- OTR: strip the whitespace tag by shifting the full message tail incl. the NUL, not tag_length bytes, so the body is no longer duplicated for messages longer than the tag. - presence: snapshot the resource fields before connection_add_available_resource() takes ownership, removing a use-after-free in the own-presence path. - OMEMO: propagate _omemo_finalize_identity_load() failure on connect (log + cons_show_error + stop) instead of leaving OMEMO silently unavailable. - OMEMO: guard NULL fingerprint decode in _omemo_fingerprint_decode / omemo_is_trusted_identity / omemo_trust and log every decode failure instead of failing silently. - stanza-id: gate XEP-0359 dedup on disco urn:xmpp:sid:0 (the `by` JID or its domain), falling back to no-dedup when caps are unknown; add functional tests for trusted vs untrusted server. - accounts: narrow the group-name sanitizer to the characters GKeyFile forbids in headers ([ ] \n \r), keeping `=` and `#`, so read/write stays symmetric. - build: re-introduce compiler/sanitizer flags in a Pikaur-safe form (opt-in sanitizers, -Wsign-compare) and fix the resulting -Wsign-compare warnings (incl. proftest _mkdir_recursive).fix: OTR/presence/OMEMO correctness, stanza-id disco gate, build hardening Author: jabber.developer2 <jabber.developer2@jabber.space>
This commit is contained in:
@@ -621,15 +621,20 @@ _available_handler(xmpp_stanza_t* const stanza)
|
||||
}
|
||||
|
||||
if (g_strcmp0(xmpp_presence->jid->barejid, my_jid->barejid) == 0) {
|
||||
connection_add_available_resource(resource);
|
||||
// Copy what we read before connection_add_available_resource() takes ownership.
|
||||
Resource* resource_for_roster = resource_copy(resource);
|
||||
auto_gchar gchar* resource_name = g_strdup(resource->name);
|
||||
auto_gchar gchar* resource_status = resource->status ? g_strdup(resource->status) : NULL;
|
||||
int resource_priority = resource->priority;
|
||||
resource_presence_t resource_presence = resource->presence;
|
||||
connection_add_available_resource(resource);
|
||||
sv_ev_contact_online(xmpp_presence->jid->barejid, resource_for_roster, xmpp_presence->last_activity, pgpsig);
|
||||
const char* account_name = session_get_account_name();
|
||||
int max_sessions = accounts_get_max_sessions(account_name);
|
||||
if (max_sessions > 0) {
|
||||
auto_gchar gchar* cur_resource = accounts_get_resource(account_name);
|
||||
int res_count = connection_count_available_resources();
|
||||
if (res_count > max_sessions && g_strcmp0(cur_resource, resource->name)) {
|
||||
if (res_count > max_sessions && g_strcmp0(cur_resource, resource_name)) {
|
||||
ProfWin* console = wins_get_console();
|
||||
ProfWin* current_window = wins_get_current();
|
||||
auto_gchar gchar* message = g_strdup_printf("Max sessions alarm! (%d/%d devices in use)", res_count, max_sessions);
|
||||
@@ -639,14 +644,14 @@ _available_handler(xmpp_stanza_t* const stanza)
|
||||
}
|
||||
notify(message, 10000, "Security alert");
|
||||
|
||||
const char* resource_presence = string_from_resource_presence(resource->presence);
|
||||
win_print(console, THEME_DEFAULT, "|", "New device info: \n %s (%d), %s", resource->name, resource->priority, resource_presence);
|
||||
const char* resource_presence_str = string_from_resource_presence(resource_presence);
|
||||
win_print(console, THEME_DEFAULT, "|", "New device info: \n %s (%d), %s", resource_name, resource_priority, resource_presence_str);
|
||||
|
||||
if (resource->status) {
|
||||
win_append(console, THEME_DEFAULT, ", \"%s\"", resource->status);
|
||||
if (resource_status) {
|
||||
win_append(console, THEME_DEFAULT, ", \"%s\"", resource_status);
|
||||
}
|
||||
win_appendln(console, THEME_DEFAULT, "");
|
||||
auto_jid Jid* jidp = jid_create_from_bare_and_resource(my_jid->barejid, resource->name);
|
||||
auto_jid Jid* jidp = jid_create_from_bare_and_resource(my_jid->barejid, resource_name);
|
||||
EntityCapabilities* caps = caps_lookup(jidp->fulljid);
|
||||
|
||||
if (caps) {
|
||||
|
||||
Reference in New Issue
Block a user