refactor: optimize hash table iterations and fix security issues #58

- refactor(core): replace g_hash_table_get_keys with g_hash_table_iter_init
  * Eliminates temporary GList allocations
  * Improves iteration performance
  * Affected: connection.c, cmd_defs.c, cmd_funcs.c, omemo.c, gpg.c,
    disco.c, form.c, autocompleters.c, capabilities.c, callbacks.c

- fix(xmpp): correct queued_messages loop in connection.c:1031
  * Remove incorrect NULL check that prevented message storage
  * calloc zeros array, causing loop to skip immediately
  * Fixes dropped messages during reconnection with SM enabled

- fix(ui): prevent format string vulnerabilities in cons_show calls
  * Replace cons_show(variable) with cons_show("%s", variable)
  * Protects against format string attacks if variables contain %
  * Updated instances across cmd_funcs.c, connection.c, ox.c,
    console.c, core.c
This commit is contained in:
2025-11-10 18:51:16 +03:00
parent b2ce06923e
commit 58dd89be40
13 changed files with 143 additions and 177 deletions

View File

@@ -152,7 +152,7 @@ cons_bad_cmd_usage(const char* const cmd)
g_string_printf(msg, "Invalid usage, see '/help %s' for details.", &cmd[1]);
cons_show("");
cons_show(msg->str);
cons_show("%s", msg->str);
g_string_free(msg, TRUE);
}
@@ -773,7 +773,7 @@ cons_show_disco_info(const char* jid, GSList* identities, GSList* features)
if (identity->category) {
identity_str = g_string_append(identity_str, identity->category);
}
cons_show(identity_str->str);
cons_show("%s", identity_str->str);
g_string_free(identity_str, TRUE);
identities = g_slist_next(identities);
}
@@ -1019,7 +1019,7 @@ cons_show_account(ProfAccount* account)
}
curr = curr->next;
}
cons_show(manual->str);
cons_show("%s", manual->str);
g_string_free(manual, TRUE);
}
if (g_list_length(account->otr_opportunistic) > 0) {
@@ -1032,7 +1032,7 @@ cons_show_account(ProfAccount* account)
}
curr = curr->next;
}
cons_show(opportunistic->str);
cons_show("%s", opportunistic->str);
g_string_free(opportunistic, TRUE);
}
if (g_list_length(account->otr_always) > 0) {
@@ -1045,7 +1045,7 @@ cons_show_account(ProfAccount* account)
}
curr = curr->next;
}
cons_show(always->str);
cons_show("%s", always->str);
g_string_free(always, TRUE);
}
@@ -2297,7 +2297,7 @@ cons_show_themes(GSList* themes)
} else {
cons_show("Available themes:");
while (themes) {
cons_show(themes->data);
cons_show("%s", themes->data);
themes = g_slist_next(themes);
}
}
@@ -2315,7 +2315,7 @@ cons_show_scripts(GSList* scripts)
} else {
cons_show("Scripts:");
while (scripts) {
cons_show(scripts->data);
cons_show("%s", scripts->data);
scripts = g_slist_next(scripts);
}
}