Compare commits

..

1 Commits

Author SHA1 Message Date
a283c4e7b4 fix(xmpp): treat disco#info result without 'from' as from the server
All checks were successful
CI Code / Check spelling (pull_request) Successful in 14s
CI Code / Check coding style (pull_request) Successful in 24s
CI Code / Linux (ubuntu) (pull_request) Successful in 8m29s
CI Code / Linux (debian) (pull_request) Successful in 8m53s
CI Code / Code Coverage (pull_request) Successful in 9m7s
CI Code / Linux (arch) (pull_request) Successful in 12m11s
RFC 6120 §8.1.2.1: a stanza received over a c2s stream without a 'from'
attribute must be treated as coming from the server itself. The
on-connect disco#info handler passed the absent attribute as NULL into
connection_features_received(), where g_str_hash() dereferenced the NULL
key and crashed (remotely triggerable DoS on connect).

Substitute connection_get_domain() at both disco#info handler
boundaries, and make connection_features_received() and
connection_get_features() NULL-safe as defense in depth. Add a stabber
regression test answering the on-connect disco#info with a from-less
result.

Fixes #168
2026-07-21 09:09:49 +03:00
6 changed files with 45 additions and 16 deletions

View File

@@ -658,15 +658,6 @@ connection_request_features(void)
/* We don't record it as a requested feature to avoid triggering th
* sv_ev_connection_features_received too soon */
iq_disco_info_request_onconnect(conn.domain);
const char* barejid = connection_get_barejid();
if (barejid && g_strcmp0(barejid, conn.domain) != 0) {
if (!g_hash_table_contains(conn.features_by_jid, barejid)) {
g_hash_table_insert(conn.features_by_jid, strdup(barejid),
g_hash_table_new_full(g_str_hash, g_str_equal, free, NULL));
}
iq_disco_info_request_onconnect(barejid); // XEP-0163: PEP services announce features on the account's bare JID
}
}
void
@@ -762,7 +753,11 @@ void
connection_features_received(const char* const jid)
{
log_info("[CONNECTION] connection_features_received %s", jid);
if (g_hash_table_remove(conn.requested_features, jid) && g_hash_table_size(conn.requested_features) == 0) {
const char* key = jid ? jid : conn.domain; // g_str_hash crashes on NULL; NULL 'from' means the server (RFC 6120 §8.1.2.1)
if (!key) {
return;
}
if (g_hash_table_remove(conn.requested_features, key) && g_hash_table_size(conn.requested_features) == 0) {
sv_ev_connection_features_received();
}
}
@@ -770,7 +765,11 @@ connection_features_received(const char* const jid)
GHashTable*
connection_get_features(const char* const jid)
{
return g_hash_table_lookup(conn.features_by_jid, jid);
const char* key = jid ? jid : conn.domain;
if (!key || !conn.features_by_jid) {
return NULL;
}
return g_hash_table_lookup(conn.features_by_jid, key);
}
GList*

View File

@@ -2314,6 +2314,7 @@ _disco_info_response_id_handler(xmpp_stanza_t* const stanza, void* const userdat
log_debug("Received disco#info response from: %s", from);
} else {
log_debug("Received disco#info response");
from = connection_get_domain(); // RFC 6120 §8.1.2.1: no 'from' means the server itself
}
// handle error responses
@@ -2397,6 +2398,7 @@ _disco_info_response_id_handler_onconnect(xmpp_stanza_t* const stanza, void* con
log_debug("Received disco#info response from: %s", from);
} else {
log_debug("Received disco#info response");
from = connection_get_domain(); // RFC 6120 §8.1.2.1: no 'from' means the server itself
}
// handle error responses

View File

@@ -446,21 +446,18 @@ _omemo_receive_devicelist(xmpp_stanza_t* const stanza, void* const userdata)
GList* device_list = NULL;
if (g_strcmp0(type, STANZA_TYPE_ERROR) == 0) {
log_error("[OMEMO] can't get OMEMO device list");
xmpp_stanza_t* error = xmpp_stanza_get_child_by_name(stanza, "error");
if (!error) {
log_error("[OMEMO] missing error element in device list response");
return 1;
}
// a missing node is signalled via legacy code='404' or the RFC 6120 <item-not-found/> condition
const char* code = xmpp_stanza_get_attribute(error, "code");
if (g_strcmp0(code, "404") == 0
|| xmpp_stanza_get_child_by_name_and_ns(error, STANZA_NAME_ITEM_NOT_FOUND, STANZA_NS_STANZAS)) {
log_debug("[OMEMO] no devicelist node for %s, bootstrapping an empty one", from);
if (g_strcmp0(code, "404") == 0) {
omemo_set_device_list(from, NULL);
return 1;
}
log_error("[OMEMO] can't get OMEMO device list");
}
xmpp_stanza_t* root = NULL;

View File

@@ -173,6 +173,7 @@ main(int argc, char* argv[])
PROF_FUNC_TEST(disco_info_without_name),
PROF_FUNC_TEST(disco_items_without_name),
PROF_FUNC_TEST(disco_info_service_unavailable),
PROF_FUNC_TEST(disco_info_result_no_from),
/* Roster management - add/remove/rename contacts */
PROF_FUNC_TEST(sends_new_item),

View File

@@ -396,6 +396,35 @@ disco_items_without_name(void **state)
prof_timeout_reset();
}
void
disco_info_result_no_from(void **state)
{
/*
* Test that a disco#info result without a 'from' attribute is treated as
* coming from the server itself (RFC 6120 §8.1.2.1). The on-connect
* disco#info handler used to crash on such responses (issue #168).
*/
stbbr_for_query("http://jabber.org/protocol/disco#info",
"<iq to='stabber@localhost/profanity' type='result'>"
"<query xmlns='http://jabber.org/protocol/disco#info'>"
"<identity category='server' type='im' name='NoFromServer'/>"
"<feature var='urn:xmpp:ping'/>"
"</query>"
"</iq>"
);
/* the on-connect disco#info gets the same from-less response */
prof_connect();
prof_input("/disco info");
prof_timeout(10);
/* client survived and attributed the response to the server */
assert_true(prof_output_exact("Service discovery info for localhost"));
assert_true(prof_output_regex("NoFromServer.*im.*server"));
prof_timeout_reset();
}
void
disco_info_service_unavailable(void **state)
{

View File

@@ -17,3 +17,4 @@ void disco_info_multiple_identities(void **state);
void disco_info_without_name(void **state);
void disco_items_without_name(void **state);
void disco_info_service_unavailable(void **state);
void disco_info_result_no_from(void **state);