Fix more potential leaks in aesgcm_download

This commit is contained in:
Michael Vetter
2025-03-06 14:27:13 +01:00
parent 43bbb16e8e
commit b5f0cc0bd4
4 changed files with 46 additions and 23 deletions

View File

@@ -64,8 +64,8 @@ aesgcm_file_get(void* userdata)
{
AESGCMDownload* aesgcm_dl = (AESGCMDownload*)userdata;
char* https_url = NULL;
char* fragment = NULL;
auto_char char* https_url = NULL;
auto_char char* fragment = NULL;
// Convert the aesgcm:// URL to a https:// URL and extract the encoded key
// and tag stored in the URL fragment.
@@ -79,8 +79,8 @@ aesgcm_file_get(void* userdata)
// Create a temporary file used for storing the ciphertext that is to be
// retrieved from the https:// URL.
gchar* tmpname = NULL;
gint tmpfd;
auto_gchar char* tmpname = NULL;
auto_gfd gint tmpfd = 0;
if ((tmpfd = g_file_open_tmp("profanity.XXXXXX", &tmpname, NULL)) == -1) {
http_print_transfer_update(aesgcm_dl->window, aesgcm_dl->id,
"Downloading '%s' failed: Unable to create "
@@ -91,7 +91,7 @@ aesgcm_file_get(void* userdata)
}
// Open the target file for storing the cleartext.
FILE* outfh = fopen(aesgcm_dl->filename, "wb");
auto_FILE FILE* outfh = fopen(aesgcm_dl->filename, "wb");
if (outfh == NULL) {
http_print_transfer_update(aesgcm_dl->window, aesgcm_dl->id,
"Downloading '%s' failed: Unable to open "
@@ -115,16 +115,13 @@ aesgcm_file_get(void* userdata)
http_file_get(http_dl); // TODO(wstrm): Verify result.
FILE* tmpfh = fopen(tmpname, "rb");
auto_FILE FILE* tmpfh = fopen(tmpname, "rb");
if (tmpfh == NULL) {
http_print_transfer_update(aesgcm_dl->window, aesgcm_dl->id,
"Downloading '%s' failed: Unable to open "
"temporary file at '%s' for reading (%s).",
aesgcm_dl->url, tmpname,
g_strerror(errno));
if (fclose(outfh) == EOF) {
cons_show_error(g_strerror(errno));
}
return NULL;
}
@@ -132,11 +129,6 @@ aesgcm_file_get(void* userdata)
crypt_res = omemo_decrypt_file(tmpfh, outfh,
http_dl->bytes_received, fragment);
if (fclose(tmpfh) == EOF) {
cons_show_error(g_strerror(errno));
}
close(tmpfd);
remove(tmpname);
g_free(tmpname);
@@ -147,13 +139,6 @@ aesgcm_file_get(void* userdata)
https_url, gcry_strerror(crypt_res));
}
if (fclose(outfh) == EOF) {
cons_show_error(g_strerror(errno));
}
free(https_url);
free(fragment);
if (aesgcm_dl->cmd_template != NULL) {
gchar** argv = format_call_external_argv(aesgcm_dl->cmd_template,
aesgcm_dl->filename,