Compare commits

..

1 Commits

Author SHA1 Message Date
a283c4e7b4 fix(xmpp): treat disco#info result without 'from' as from the server
All checks were successful
CI Code / Check spelling (pull_request) Successful in 14s
CI Code / Check coding style (pull_request) Successful in 24s
CI Code / Linux (ubuntu) (pull_request) Successful in 8m29s
CI Code / Linux (debian) (pull_request) Successful in 8m53s
CI Code / Code Coverage (pull_request) Successful in 9m7s
CI Code / Linux (arch) (pull_request) Successful in 12m11s
RFC 6120 §8.1.2.1: a stanza received over a c2s stream without a 'from'
attribute must be treated as coming from the server itself. The
on-connect disco#info handler passed the absent attribute as NULL into
connection_features_received(), where g_str_hash() dereferenced the NULL
key and crashed (remotely triggerable DoS on connect).

Substitute connection_get_domain() at both disco#info handler
boundaries, and make connection_features_received() and
connection_get_features() NULL-safe as defense in depth. Add a stabber
regression test answering the on-connect disco#info with a from-less
result.

Fixes #168
2026-07-21 09:09:49 +03:00
8 changed files with 4 additions and 77 deletions

View File

@@ -87,7 +87,6 @@ theme_init(const char* const theme_name)
g_hash_table_insert(defaults, strdup("main.help.header"), strdup("default"));
g_hash_table_insert(defaults, strdup("main.trackbar"), strdup("default"));
g_hash_table_insert(defaults, strdup("error"), strdup("red"));
g_hash_table_insert(defaults, strdup("warning"), strdup("yellow"));
g_hash_table_insert(defaults, strdup("incoming"), strdup("yellow"));
g_hash_table_insert(defaults, strdup("mention"), strdup("yellow"));
g_hash_table_insert(defaults, strdup("trigger"), strdup("yellow"));
@@ -704,9 +703,6 @@ theme_attrs(theme_item_t attrs)
case THEME_ERROR:
_theme_prep_fgnd("error", lookup_str, &bold);
break;
case THEME_WARNING:
_theme_prep_fgnd("warning", lookup_str, &bold);
break;
case THEME_INCOMING:
_theme_prep_fgnd("incoming", lookup_str, &bold);
break;

View File

@@ -23,7 +23,6 @@ typedef enum {
THEME_SPLASH,
THEME_HELP_HEADER,
THEME_ERROR,
THEME_WARNING,
THEME_INCOMING,
THEME_MENTION,
THEME_TRIGGER,

View File

@@ -25,8 +25,6 @@
#include "ui/ui.h"
#include "xmpp/xmpp.h"
extern char** environ;
typedef struct EditorContext
{
gchar* filename;
@@ -142,22 +140,6 @@ launch_editor(gchar* initial_content, void (*callback)(gchar* content, void* dat
GSource* sigchld_warmup = g_child_watch_source_new(getpid());
g_source_unref(sigchld_warmup);
// Build the editor's env without LINES/COLUMNS pre-fork, so the child only
// reassigns environ instead of calling unsetenv() between fork and exec.
// The editor's (n)curses then reads the live window via ioctl(TIOCGWINSZ).
gsize env_len = 0;
while (environ[env_len]) {
env_len++;
}
gchar** editor_env = g_new0(gchar*, env_len + 1);
gsize env_kept = 0;
for (gsize i = 0; i < env_len; i++) {
if (g_str_has_prefix(environ[i], "LINES=") || g_str_has_prefix(environ[i], "COLUMNS=")) {
continue;
}
editor_env[env_kept++] = environ[i];
}
pid_t pid = fork();
if (pid == -1) {
log_error("[Editor] Failed to fork: %s", strerror(errno));
@@ -166,14 +148,12 @@ launch_editor(gchar* initial_content, void (*callback)(gchar* content, void* dat
ui_resize();
cons_show_error("Failed to start editor: %s", strerror(errno));
g_strfreev(editor_argv);
g_free(editor_env);
g_free(ctx->filename);
g_free(ctx);
return TRUE;
} else if (pid == 0) {
// Child process: Inherits TTY from parent
environ = editor_env; // live TIOCGWINSZ size, not the inherited LINES/COLUMNS
// SIGTSTP=SIG_DFL lets vim's :stop / Ctrl-Z work; profanity catches
// the STOPPED state via editor_check_stopped() and drops to the shell.
signal(SIGINT, SIG_DFL);
@@ -190,7 +170,6 @@ launch_editor(gchar* initial_content, void (*callback)(gchar* content, void* dat
editor_pid = pid;
g_child_watch_add((GPid)pid, _editor_exit_cb, ctx);
g_strfreev(editor_argv);
g_free(editor_env); // array only; strings are borrowed from environ
return FALSE;
}

View File

@@ -155,20 +155,6 @@ cons_show_error(const char* const msg, ...)
cons_alert(NULL);
}
void
cons_show_warning(const char* const msg, ...)
{
va_list arg;
va_start(arg, msg);
GString* fmt_msg = g_string_new(NULL);
g_string_vprintf(fmt_msg, msg, arg);
win_println(wins_get_console(), THEME_WARNING, "-", "Warning: %s", fmt_msg->str);
g_string_free(fmt_msg, TRUE);
va_end(arg);
cons_alert(NULL);
}
void
cons_show_tlscert_summary(const TLSCertificate* cert)
{

View File

@@ -252,8 +252,6 @@ G_GNUC_PRINTF(1, 2)
void cons_debug(const char* const msg, ...);
G_GNUC_PRINTF(1, 2)
void cons_show_error(const char* const cmd, ...);
G_GNUC_PRINTF(1, 2)
void cons_show_warning(const char* const msg, ...);
void cons_show_contacts(GSList* list);
void cons_show_roster(GSList* list);
void cons_show_roster_group(const char* const group, GSList* list);

View File

@@ -749,21 +749,14 @@ connection_get_user(void)
return connection_get_jid()->localpart;
}
// NULL 'from' means the server (RFC 6120 §8.1.2.1)
static const char*
_get_from_via_jid(const char* const jid)
{
return jid ? jid : conn.domain;
}
void
connection_features_received(const char* const jid)
{
const char* key = _get_from_via_jid(jid);
log_info("[CONNECTION] connection_features_received %s", jid);
const char* key = jid ? jid : conn.domain; // g_str_hash crashes on NULL; NULL 'from' means the server (RFC 6120 §8.1.2.1)
if (!key) {
return;
}
log_info("[CONNECTION] connection_features_received %s", key);
if (g_hash_table_remove(conn.requested_features, key) && g_hash_table_size(conn.requested_features) == 0) {
sv_ev_connection_features_received();
}
@@ -772,7 +765,7 @@ connection_features_received(const char* const jid)
GHashTable*
connection_get_features(const char* const jid)
{
const char* key = _get_from_via_jid(jid);
const char* key = jid ? jid : conn.domain;
if (!key || !conn.features_by_jid) {
return NULL;
}

View File

@@ -49,18 +49,6 @@ expect_any_cons_show_error(void)
expect_any(cons_show_error, output);
}
void
expect_cons_show_warning(char* expected)
{
expect_string(cons_show_warning, output, expected);
}
void
expect_any_cons_show_warning(void)
{
expect_any(cons_show_warning, output);
}
void
expect_win_println(char* message)
{
@@ -857,16 +845,6 @@ cons_show_error(const char* const cmd, ...)
va_end(args);
}
void
cons_show_warning(const char* const msg, ...)
{
va_list args;
va_start(args, msg);
vsnprintf(output, sizeof(output), msg, args);
check_expected(output);
va_end(args);
}
void
cons_show_contacts(GSList* list)
{

View File

@@ -10,6 +10,4 @@ void expect_cons_show(char* expected);
void expect_any_cons_show(void);
void expect_cons_show_error(char* expected);
void expect_any_cons_show_error(void);
void expect_cons_show_warning(char* expected);
void expect_any_cons_show_warning(void);
void expect_win_println(char* message);