All checks were successful
CI Code / Check spelling (pull_request) Successful in 14s
CI Code / Check coding style (pull_request) Successful in 24s
CI Code / Linux (ubuntu) (pull_request) Successful in 8m29s
CI Code / Linux (debian) (pull_request) Successful in 8m53s
CI Code / Code Coverage (pull_request) Successful in 9m7s
CI Code / Linux (arch) (pull_request) Successful in 12m11s
RFC 6120 §8.1.2.1: a stanza received over a c2s stream without a 'from' attribute must be treated as coming from the server itself. The on-connect disco#info handler passed the absent attribute as NULL into connection_features_received(), where g_str_hash() dereferenced the NULL key and crashed (remotely triggerable DoS on connect). Substitute connection_get_domain() at both disco#info handler boundaries, and make connection_features_received() and connection_get_features() NULL-safe as defense in depth. Add a stabber regression test answering the on-connect disco#info with a from-less result. Fixes #168
21 lines
759 B
C
21 lines
759 B
C
/* test_disco.h
|
|
*
|
|
* Functional tests for /disco command (XEP-0030 Service Discovery)
|
|
*/
|
|
|
|
void disco_info_shows_identity(void **state);
|
|
void disco_info_shows_features(void **state);
|
|
void disco_info_to_server(void **state);
|
|
void disco_info_to_jid(void **state);
|
|
void disco_info_not_found(void **state);
|
|
void disco_items_shows_items(void **state);
|
|
void disco_items_empty_result(void **state);
|
|
void disco_requires_connection(void **state);
|
|
void disco_items_to_jid(void **state);
|
|
void disco_info_empty_result(void **state);
|
|
void disco_info_multiple_identities(void **state);
|
|
void disco_info_without_name(void **state);
|
|
void disco_items_without_name(void **state);
|
|
void disco_info_service_unavailable(void **state);
|
|
void disco_info_result_no_from(void **state);
|