mirror of
https://git.jabber.space/devs/cproof.git
synced 2026-07-23 02:56:21 +00:00
fix(ui,db): harden NULL handling, fix CWE-134, optimize iterations
security(CWE-134): fix format string injections + add CI check fix(ui): subwindow lifecycle, newwin/newpad guards, fallback timestamps fix(db): sqlite cleanup on failures, sqlite3_close_v2 fix(xmpp): queued_messages loop, barejid leak perf(core): g_hash_table_iter_init instead of g_hash_table_get_keys refactor(ui): CLAMP macro in _check_subwin_width test: XEP-0012 and XEP-0045 functional tests Author: jabber.developer2 Closes #58, #85
This commit is contained in:
@@ -171,16 +171,15 @@ caps_get_features(void)
|
||||
{
|
||||
GList* result = NULL;
|
||||
|
||||
GList* features_as_list = g_hash_table_get_keys(prof_features);
|
||||
GList* curr = features_as_list;
|
||||
while (curr) {
|
||||
result = g_list_append(result, strdup(curr->data));
|
||||
curr = g_list_next(curr);
|
||||
GHashTableIter iter;
|
||||
gpointer key, value;
|
||||
g_hash_table_iter_init(&iter, prof_features);
|
||||
while (g_hash_table_iter_next(&iter, &key, &value)) {
|
||||
result = g_list_append(result, strdup((char*)key));
|
||||
}
|
||||
g_list_free(features_as_list);
|
||||
|
||||
GList* plugin_features = plugins_get_disco_features();
|
||||
curr = plugin_features;
|
||||
GList* curr = plugin_features;
|
||||
while (curr) {
|
||||
result = g_list_append(result, strdup(curr->data));
|
||||
curr = g_list_next(curr);
|
||||
|
||||
@@ -148,7 +148,7 @@ connection_init(void)
|
||||
if (string_to_verbosity(v, &verbosity, &err_msg)) {
|
||||
xmpp_ctx_set_verbosity(conn.xmpp_ctx, verbosity);
|
||||
} else {
|
||||
cons_show(err_msg);
|
||||
cons_show("%s", err_msg);
|
||||
}
|
||||
conn.xmpp_conn = xmpp_conn_new(conn.xmpp_ctx);
|
||||
|
||||
@@ -638,22 +638,18 @@ gboolean
|
||||
connection_supports(const char* const feature)
|
||||
{
|
||||
gboolean ret = FALSE;
|
||||
GList* jids = g_hash_table_get_keys(conn.features_by_jid);
|
||||
GHashTableIter iter;
|
||||
gpointer key, value;
|
||||
|
||||
GList* curr = jids;
|
||||
while (curr) {
|
||||
char* jid = curr->data;
|
||||
GHashTable* features = g_hash_table_lookup(conn.features_by_jid, jid);
|
||||
g_hash_table_iter_init(&iter, conn.features_by_jid);
|
||||
while (g_hash_table_iter_next(&iter, &key, &value)) {
|
||||
GHashTable* features = (GHashTable*)value;
|
||||
if (features && g_hash_table_lookup(features, feature)) {
|
||||
ret = TRUE;
|
||||
break;
|
||||
}
|
||||
|
||||
curr = g_list_next(curr);
|
||||
}
|
||||
|
||||
g_list_free(jids);
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
@@ -664,22 +660,17 @@ connection_jid_for_feature(const char* const feature)
|
||||
return NULL;
|
||||
}
|
||||
|
||||
GList* jids = g_hash_table_get_keys(conn.features_by_jid);
|
||||
GHashTableIter iter;
|
||||
gpointer key, value;
|
||||
|
||||
GList* curr = jids;
|
||||
while (curr) {
|
||||
char* jid = curr->data;
|
||||
GHashTable* features = g_hash_table_lookup(conn.features_by_jid, jid);
|
||||
g_hash_table_iter_init(&iter, conn.features_by_jid);
|
||||
while (g_hash_table_iter_next(&iter, &key, &value)) {
|
||||
GHashTable* features = (GHashTable*)value;
|
||||
if (features && g_hash_table_lookup(features, feature)) {
|
||||
g_list_free(jids);
|
||||
return jid;
|
||||
return (const char*)key;
|
||||
}
|
||||
|
||||
curr = g_list_next(curr);
|
||||
}
|
||||
|
||||
g_list_free(jids);
|
||||
|
||||
return NULL;
|
||||
}
|
||||
|
||||
@@ -1034,7 +1025,7 @@ _connection_handler(xmpp_conn_t* const xmpp_conn, const xmpp_conn_event_t status
|
||||
conn.sm_state = xmpp_conn_get_sm_state(conn.xmpp_conn);
|
||||
if (send_queue_len > 0 && prefs_get_boolean(PREF_STROPHE_SM_RESEND)) {
|
||||
conn.queued_messages = calloc(send_queue_len + 1, sizeof(*conn.queued_messages));
|
||||
for (int n = 0; n < send_queue_len && conn.queued_messages[n]; ++n) {
|
||||
for (int n = 0; n < send_queue_len; ++n) {
|
||||
conn.queued_messages[n] = xmpp_conn_send_queue_drop_element(conn.xmpp_conn, XMPP_QUEUE_OLDEST);
|
||||
}
|
||||
} else if (send_queue_len > 0) {
|
||||
@@ -1189,12 +1180,13 @@ connection_debug_print_features()
|
||||
continue;
|
||||
}
|
||||
|
||||
GList* feature_keys = g_hash_table_get_keys(features);
|
||||
for (GList* l = feature_keys; l != NULL; l = l->next) {
|
||||
const char* feature = (const char*)l->data;
|
||||
GHashTableIter feature_iter;
|
||||
gpointer feature_key, feature_value;
|
||||
g_hash_table_iter_init(&feature_iter, features);
|
||||
while (g_hash_table_iter_next(&feature_iter, &feature_key, &feature_value)) {
|
||||
const char* feature = (const char*)feature_key;
|
||||
log_debug("%s:\t%s", jid, feature);
|
||||
}
|
||||
g_list_free(feature_keys);
|
||||
}
|
||||
|
||||
log_debug("=== End of Features ===");
|
||||
|
||||
@@ -437,18 +437,7 @@ form_get_form_type_field(DataForm* form)
|
||||
gboolean
|
||||
form_tag_exists(DataForm* form, const char* const tag)
|
||||
{
|
||||
GList* tags = g_hash_table_get_keys(form->tag_to_var);
|
||||
GList* curr = tags;
|
||||
while (curr) {
|
||||
if (g_strcmp0(curr->data, tag) == 0) {
|
||||
g_list_free(tags);
|
||||
return TRUE;
|
||||
}
|
||||
curr = g_list_next(curr);
|
||||
}
|
||||
|
||||
g_list_free(tags);
|
||||
return FALSE;
|
||||
return g_hash_table_contains(form->tag_to_var, tag);
|
||||
}
|
||||
|
||||
form_field_type_t
|
||||
|
||||
@@ -868,7 +868,7 @@ _handle_error(xmpp_stanza_t* const stanza)
|
||||
g_string_append(log_msg, " error=");
|
||||
g_string_append(log_msg, err_msg);
|
||||
|
||||
log_info(log_msg->str);
|
||||
log_info("%s", log_msg->str);
|
||||
|
||||
g_string_free(log_msg, TRUE);
|
||||
|
||||
|
||||
@@ -326,7 +326,7 @@ _ox_metadata_result(xmpp_stanza_t* const stanza, void* const userdata)
|
||||
|
||||
if (fingerprint) {
|
||||
if (strlen(fingerprint) == KEYID_LENGTH) {
|
||||
cons_show(fingerprint);
|
||||
cons_show("%s", fingerprint);
|
||||
} else {
|
||||
cons_show("OX: Wrong char size of public key");
|
||||
log_error("[OX] Wrong chat size of public key %s", fingerprint);
|
||||
|
||||
@@ -455,7 +455,7 @@ _presence_error_handler(xmpp_stanza_t* const stanza)
|
||||
g_string_append(log_msg, " error=");
|
||||
g_string_append(log_msg, err_msg);
|
||||
|
||||
log_info(log_msg->str);
|
||||
log_info("%s", log_msg->str);
|
||||
|
||||
g_string_free(log_msg, TRUE);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user