security: harden untrusted-input handling (issue #148)
All checks were successful
CI Code / Check spelling (pull_request) Successful in 18s
CI Code / Check coding style (pull_request) Successful in 47s
CI Code / Linux (debian) (pull_request) Successful in 9m33s
CI Code / Linux (ubuntu) (pull_request) Successful in 9m41s
CI Code / Code Coverage (pull_request) Successful in 8m3s
CI Code / Linux (arch) (pull_request) Successful in 11m0s

T02: guard the receive-path handlers that dereferenced jid_create()
without a NULL check — MUC join errors, subscribed/unsubscribed
presence and, with silence.non-roster enabled, every incoming message.
A stanza with a missing or malformed 'from' crashed the client. The
XEP-0280 carbon path carried the same class twice: the forwarded
message's 'from' was handed to xmpp_jid_bare(), which dereferences the
jid it is given, and a malformed 'to' left the carbon dispatch
dereferencing a NULL jid_create() result (REQ-INP-01)

T11: restrict /url open and /url save to http, https and aesgcm, so a
received file:, javascript: or data: URL is refused (REQ-INP-06); spawn
terminal-notifier through g_spawn_async with an argv instead of
building a shell command for system() (REQ-INP-07); apply the XEP-0359
disco gate to MAM result ids, as live stanza-ids already do
(REQ-INP-05); replace control and bidi-reordering characters in
incoming message bodies with U+FFFD before they reach the terminal, the
logs and the database, keeping LRM/RLM for legitimate RTL text. That
pass now runs on every display path: the OX one, where the call had
been left commented out since the feature landed, and outgoing carbons,
whose body is forwarded by the server (REQ-INP-08); cover JID
part-length boundaries and invalid UTF-8 (REQ-INP-02)

T10: replace strcpy/strcat/alloca and sprintf with g_strdup_printf and
g_snprintf (REQ-MEM-03); allocate the OMEMO key buffers with g_malloc
so a failed allocation cannot reach the following memcpy (REQ-MEM-04);
remove the variable-length arrays and enforce -Werror=vla. Two of them
were sized from remote input: the disco#info feature count and a chat
message word length. The flag also caught a one-past-the-end write and
a leak in the plugin autocompleter bindings (REQ-MEM-09). The OX
receive path leaked every decrypted body, dropping the pointer instead
of freeing it, and a failed strdup no longer costs the message body
This commit is contained in:
2026-07-30 12:27:37 +03:00
parent d914e42ff6
commit afd9d84723
32 changed files with 554 additions and 111 deletions

View File

@@ -247,14 +247,16 @@ caps_add_by_ver(const char* const ver, EntityCapabilities* caps)
if (caps->features) {
GSList* curr_feature = caps->features;
int num = g_slist_length(caps->features);
const gchar* features_list[num];
int curr = 0;
// the feature count comes from a disco#info response, keep it off the stack
guint num = g_slist_length(caps->features);
const gchar** features_list = g_malloc_n(num, sizeof(*features_list));
guint curr = 0;
while (curr_feature) {
features_list[curr++] = curr_feature->data;
curr_feature = g_slist_next(curr_feature);
}
g_key_file_set_string_list(cache, ver, "features", features_list, num);
g_free(features_list);
}
_save_cache();