Don't pass NULL to strcmp()

There are places where code relies on well-formed stanzas and expects
that ns attribute is always present. Check whether ns NULL or not before
passing it to strcmp().

Fixes #121.
This commit is contained in:
Dmitry Podgorny
2018-07-30 20:38:43 +03:00
parent 0e6b0ef84d
commit a13ba65cfb
2 changed files with 25 additions and 13 deletions

View File

@@ -219,6 +219,7 @@ static int _handle_features(xmpp_conn_t * const conn,
void * const userdata) void * const userdata)
{ {
xmpp_stanza_t *child, *mech; xmpp_stanza_t *child, *mech;
const char *ns;
char *text; char *text;
/* remove the handler that detects missing stream:features */ /* remove the handler that detects missing stream:features */
@@ -228,8 +229,10 @@ static int _handle_features(xmpp_conn_t * const conn,
if (!conn->secured) { if (!conn->secured) {
if (!conn->tls_disabled) { if (!conn->tls_disabled) {
child = xmpp_stanza_get_child_by_name(stanza, "starttls"); child = xmpp_stanza_get_child_by_name(stanza, "starttls");
if (child && (strcmp(xmpp_stanza_get_ns(child), XMPP_NS_TLS) == 0)) if (child) {
conn->tls_support = 1; ns = xmpp_stanza_get_ns(child);
conn->tls_support = ns != NULL && strcmp(ns, XMPP_NS_TLS) == 0;
}
} else { } else {
conn->tls_support = 0; conn->tls_support = 0;
} }
@@ -237,11 +240,15 @@ static int _handle_features(xmpp_conn_t * const conn,
/* check for SASL */ /* check for SASL */
child = xmpp_stanza_get_child_by_name(stanza, "mechanisms"); child = xmpp_stanza_get_child_by_name(stanza, "mechanisms");
if (child && (strcmp(xmpp_stanza_get_ns(child), XMPP_NS_SASL) == 0)) { ns = child ? xmpp_stanza_get_ns(child) : NULL;
if (child && ns && strcmp(ns, XMPP_NS_SASL) == 0) {
for (mech = xmpp_stanza_get_children(child); mech; for (mech = xmpp_stanza_get_children(child); mech;
mech = xmpp_stanza_get_next(mech)) { mech = xmpp_stanza_get_next(mech)) {
if (xmpp_stanza_get_name(mech) && strcmp(xmpp_stanza_get_name(mech), "mechanism") == 0) { if (xmpp_stanza_get_name(mech) && strcmp(xmpp_stanza_get_name(mech), "mechanism") == 0) {
text = xmpp_stanza_get_text(mech); text = xmpp_stanza_get_text(mech);
if (text == NULL)
continue;
if (strcasecmp(text, "PLAIN") == 0) if (strcasecmp(text, "PLAIN") == 0)
conn->sasl_support |= SASL_MASK_PLAIN; conn->sasl_support |= SASL_MASK_PLAIN;
else if (strcasecmp(text, "DIGEST-MD5") == 0) else if (strcasecmp(text, "DIGEST-MD5") == 0)
@@ -871,7 +878,8 @@ static int _handle_features_sasl(xmpp_conn_t * const conn,
xmpp_stanza_t * const stanza, xmpp_stanza_t * const stanza,
void * const userdata) void * const userdata)
{ {
xmpp_stanza_t *bind, *session, *iq, *res, *text; xmpp_stanza_t *bind, *session, *iq, *res, *text, *opt;
const char *ns;
char *resource; char *resource;
/* remove missing features handler */ /* remove missing features handler */
@@ -880,18 +888,21 @@ static int _handle_features_sasl(xmpp_conn_t * const conn,
/* we are expecting <bind/> and <session/> since this is a /* we are expecting <bind/> and <session/> since this is a
XMPP style connection */ XMPP style connection */
/* check whether resource binding is required */
bind = xmpp_stanza_get_child_by_name(stanza, "bind"); bind = xmpp_stanza_get_child_by_name(stanza, "bind");
if (bind && strcmp(xmpp_stanza_get_ns(bind), XMPP_NS_BIND) == 0) { if (bind) {
/* resource binding is required */ ns = xmpp_stanza_get_ns(bind);
conn->bind_required = 1; conn->bind_required = ns != NULL && strcmp(ns, XMPP_NS_BIND) == 0;
} }
/* check whether session establishment is required */
session = xmpp_stanza_get_child_by_name(stanza, "session"); session = xmpp_stanza_get_child_by_name(stanza, "session");
if (session && strcmp(xmpp_stanza_get_ns(session), XMPP_NS_SESSION) == 0) { if (session) {
/* session establishment might be required */ ns = xmpp_stanza_get_ns(session);
xmpp_stanza_t *opt = xmpp_stanza_get_child_by_name(session, "optional"); opt = xmpp_stanza_get_child_by_name(session, "optional");
if (!opt) if (!opt)
conn->session_required = 1; conn->session_required = ns != NULL &&
strcmp(ns, XMPP_NS_SESSION) == 0;
} }
/* if bind is required, go ahead and start it */ /* if bind is required, go ahead and start it */

View File

@@ -809,10 +809,11 @@ xmpp_stanza_t *xmpp_stanza_get_child_by_ns(xmpp_stanza_t * const stanza,
const char * const ns) const char * const ns)
{ {
xmpp_stanza_t *child; xmpp_stanza_t *child;
const char *child_ns;
for (child = stanza->children; child; child = child->next) { for (child = stanza->children; child; child = child->next) {
if (xmpp_stanza_get_ns(child) && child_ns = xmpp_stanza_get_ns(child);
strcmp(ns, xmpp_stanza_get_ns(child)) == 0) if (child_ns && strcmp(ns, child_ns) == 0)
break; break;
} }