fix(ui,db): harden NULL handling, fix CWE-134, optimize iterations

security(CWE-134): fix format string injections + add CI check
fix(ui): subwindow lifecycle, newwin/newpad guards, fallback timestamps
fix(db): sqlite cleanup on failures, sqlite3_close_v2
fix(xmpp): queued_messages loop, barejid leak
perf(core): g_hash_table_iter_init instead of g_hash_table_get_keys
refactor(ui): CLAMP macro in _check_subwin_width
test: XEP-0012 and XEP-0045 functional tests

Author: jabber.developer2
Closes #58, #85
This commit is contained in:
2026-02-06 19:27:40 +01:00
parent f8826b7c79
commit 467222d0ca
36 changed files with 656 additions and 238 deletions

View File

@@ -148,7 +148,7 @@ connection_init(void)
if (string_to_verbosity(v, &verbosity, &err_msg)) {
xmpp_ctx_set_verbosity(conn.xmpp_ctx, verbosity);
} else {
cons_show(err_msg);
cons_show("%s", err_msg);
}
conn.xmpp_conn = xmpp_conn_new(conn.xmpp_ctx);
@@ -638,22 +638,18 @@ gboolean
connection_supports(const char* const feature)
{
gboolean ret = FALSE;
GList* jids = g_hash_table_get_keys(conn.features_by_jid);
GHashTableIter iter;
gpointer key, value;
GList* curr = jids;
while (curr) {
char* jid = curr->data;
GHashTable* features = g_hash_table_lookup(conn.features_by_jid, jid);
g_hash_table_iter_init(&iter, conn.features_by_jid);
while (g_hash_table_iter_next(&iter, &key, &value)) {
GHashTable* features = (GHashTable*)value;
if (features && g_hash_table_lookup(features, feature)) {
ret = TRUE;
break;
}
curr = g_list_next(curr);
}
g_list_free(jids);
return ret;
}
@@ -664,22 +660,17 @@ connection_jid_for_feature(const char* const feature)
return NULL;
}
GList* jids = g_hash_table_get_keys(conn.features_by_jid);
GHashTableIter iter;
gpointer key, value;
GList* curr = jids;
while (curr) {
char* jid = curr->data;
GHashTable* features = g_hash_table_lookup(conn.features_by_jid, jid);
g_hash_table_iter_init(&iter, conn.features_by_jid);
while (g_hash_table_iter_next(&iter, &key, &value)) {
GHashTable* features = (GHashTable*)value;
if (features && g_hash_table_lookup(features, feature)) {
g_list_free(jids);
return jid;
return (const char*)key;
}
curr = g_list_next(curr);
}
g_list_free(jids);
return NULL;
}
@@ -1034,7 +1025,7 @@ _connection_handler(xmpp_conn_t* const xmpp_conn, const xmpp_conn_event_t status
conn.sm_state = xmpp_conn_get_sm_state(conn.xmpp_conn);
if (send_queue_len > 0 && prefs_get_boolean(PREF_STROPHE_SM_RESEND)) {
conn.queued_messages = calloc(send_queue_len + 1, sizeof(*conn.queued_messages));
for (int n = 0; n < send_queue_len && conn.queued_messages[n]; ++n) {
for (int n = 0; n < send_queue_len; ++n) {
conn.queued_messages[n] = xmpp_conn_send_queue_drop_element(conn.xmpp_conn, XMPP_QUEUE_OLDEST);
}
} else if (send_queue_len > 0) {
@@ -1189,12 +1180,13 @@ connection_debug_print_features()
continue;
}
GList* feature_keys = g_hash_table_get_keys(features);
for (GList* l = feature_keys; l != NULL; l = l->next) {
const char* feature = (const char*)l->data;
GHashTableIter feature_iter;
gpointer feature_key, feature_value;
g_hash_table_iter_init(&feature_iter, features);
while (g_hash_table_iter_next(&feature_iter, &feature_key, &feature_value)) {
const char* feature = (const char*)feature_key;
log_debug("%s:\t%s", jid, feature);
}
g_list_free(feature_keys);
}
log_debug("=== End of Features ===");