Compare commits

..

2 Commits

Author SHA1 Message Date
f2918f5aaf fix(xmpp): log resolved key instead of possibly-NULL jid
All checks were successful
CI Code / Check spelling (pull_request) Successful in 16s
CI Code / Check coding style (pull_request) Successful in 1m9s
CI Code / Linux (ubuntu) (pull_request) Successful in 4m46s
CI Code / Linux (debian) (pull_request) Successful in 9m6s
CI Code / Code Coverage (pull_request) Successful in 9m50s
CI Code / Linux (arch) (pull_request) Successful in 13m16s
2026-07-28 22:03:15 +03:00
2c8bd867b9 fix(xmpp): treat disco#info result without 'from' as from the server
All checks were successful
CI Code / Check spelling (pull_request) Successful in 15s
CI Code / Check coding style (pull_request) Successful in 23s
CI Code / Code Coverage (pull_request) Successful in 3m8s
CI Code / Linux (debian) (pull_request) Successful in 4m56s
CI Code / Linux (ubuntu) (pull_request) Successful in 8m5s
CI Code / Linux (arch) (pull_request) Successful in 14m29s
RFC 6120 §8.1.2.1: a stanza received over a c2s stream without a 'from'
attribute must be treated as coming from the server itself. The
on-connect disco#info handler passed the absent attribute as NULL into
connection_features_received(), where g_str_hash() dereferenced the NULL
key and crashed (remotely triggerable DoS on connect).

Substitute connection_get_domain() at both disco#info handler
boundaries, and make connection_features_received() and
connection_get_features() NULL-safe as defense in depth. Add a stabber
regression test answering the on-connect disco#info with a from-less
result.

Fixes #168
2026-07-27 13:01:21 +00:00

Diff Content Not Available