Project homepage Mailing List  Warmcat.com  API Docs  Github Mirror 
    npro  
 Modern all-safe Rust Network Protocol library supporting h1, h2, h3, ws, wt sans-IO and with socket IO + tls
git clone https://npro.rs/repo/npro
 
root / assets / freebsd-12.svg
Author[]Andy Green <andy@warmcat.com> 2026-09-06 06:28 UTC
Committer[]Andy Green <andy@warmcat.com> 2026-09-06 06:28 UTC
Treeb6d81e26a6361d1fe90dfb04f49909b3edc185d5   Raw Patch
 
web: drop browser-originated loadreport and unhandled rx schemas, fixes F-001
web: drop browser-originated loadreport and unhandled rx schemas, fixes F-001

An unauthenticated browser could send {"schema":"com.warmcat.sai.loadreport"}
on /sai/browse*: the schema is in the browser rx map (index 8) but had no
case in the switch in saiw_ws_json_rx_browser(), so control fell into
default: assert(0) and aborted the whole sai-web process for all users.

Handle it explicitly: load reports originate from builders and are only
ever broadcast by us towards browsers, so a browser sending one is dropped
with a log rather than forwarded (sai-server does not accept this schema
on the web link and would tear it down trying to decode it).

The default arm now logs and drops instead of asserting, so a future map
entry without a case above cannot be turned into a remote crash either;
the unused <assert.h> include is removed.
diff --git a/src/web/w-ws-browser.c b/src/web/w-ws-browser.c index ec842ca..3ac9dc2 100644 --- a/src/web/w-ws-browser.c +++ b/src/web/w-ws-browser.c @@ -29,7 +29,6 @@ #include <libwebsockets.h> #include <string.h> #include <signal.h> -#include <assert.h> #include <time.h> #include "w-private.h" @@ -1097,9 +1096,26 @@ saiw_ws_json_rx_browser(struct vhd *vhd, struct pss *pss, uint8_t *buf, case SAIM_WS_BROWSER_RX_PTYDATA: break; + /* + * Load reports flow builder -> server -> us -> browsers; a browser + * sending one is meaningless. Drop it locally rather than forward + * it, sai-server does not accept this schema on the web link and + * would tear the link down trying to decode it. + */ + case SAIM_WS_BROWSER_RX_LOADREPORT: + lwsl_notice("%s: dropping loadreport from browser\n", __func__); + goto ok; + default: - assert(0); - break; + /* + * No schema in the map today reaches here. If one is added + * to the map without a case above, log and drop it rather + * than assert (remote-crashable) or forward an unknown + * schema on the server link. + */ + lwsl_notice("%s: unhandled schema index %d from browser, dropping\n", + __func__, a.top_schema_index); + goto ok; } sai_ss_queue_frag_on_buflist_REQUIRES_LWS_PRE(vhd->h_ss_websrv,
Page fetched 0s ago, creation time: 2ms (vhost etag hits: 0%, cache hits: 0%)