Project homepage Mailing List  Warmcat.com  API Docs  Github Mirror 
    npro  
 Modern all-safe Rust Network Protocol library supporting h1, h2, h3, ws, wt sans-IO and with socket IO + tls
git clone https://npro.rs/repo/npro
 
root / assets / tc-mingw32.svg
Author[]Andy Green <andy@warmcat.com> 2026-09-06 07:40 UTC
Committer[]Andy Green <andy@warmcat.com> 2026-09-06 07:40 UTC
Treeabc68faa883dc32fdd132f99c78eff9ecc90adee   Raw Patch
 
web: clear last_bps slots around free, fixes F-006
web: clear last_bps slots around free, fixes F-006

In saiw_dedup_and_queue(), a failed malloc after free(pss->last_bps[idx])
left the freed pointer stored, so the next dedup memcmp read freed heap
and LWS_CALLBACK_CLOSED later freed it a second time.  NULL the slot
(and its length) between the free and the new allocation, and NULL the
slots in the CLOSED cleanup loop after freeing as well.
diff --git a/src/web/w-comms.c b/src/web/w-comms.c index 9300272..83abb12 100644 --- a/src/web/w-comms.c +++ b/src/web/w-comms.c @@ -745,8 +745,11 @@ http_resp: lws_sul_cancel(&pss->sul_overview); for (n = 0; n < 4; n++) { - if (pss->last_bps[n]) + if (pss->last_bps[n]) { free(pss->last_bps[n]); + pss->last_bps[n] = NULL; + pss->last_bps_len[n] = 0; + } } lwsac_free(&pss->logs_ac); diff --git a/src/web/w-ws-browser.c b/src/web/w-ws-browser.c index 0941c6b..7491697 100644 --- a/src/web/w-ws-browser.c +++ b/src/web/w-ws-browser.c @@ -1911,6 +1911,8 @@ saiw_dedup_and_queue(struct pss *pss, int idx, struct sai_dyn_buf *d) changed = 0; } else { free(pss->last_bps[idx]); + pss->last_bps[idx] = NULL; + pss->last_bps_len[idx] = 0; pss->last_bps[idx] = malloc(d->len - LWS_PRE); if (pss->last_bps[idx]) { memcpy(pss->last_bps[idx], d->buf + LWS_PRE, d->len - LWS_PRE);
Page fetched 0s ago, creation time: 10ms (vhost etag hits: 0%, cache hits: 0%)