Author: Andy Green Date: Sun Sep 06 08:40:57 2026 +0100 web: clear last_bps slots around free, fixes F-006 In saiw_dedup_and_queue(), a failed malloc after free(pss->last_bps[idx]) left the freed pointer stored, so the next dedup memcmp read freed heap and LWS_CALLBACK_CLOSED later freed it a second time. NULL the slot (and its length) between the free and the new allocation, and NULL the slots in the CLOSED cleanup loop after freeing as well. diff --git a/src/web/w-comms.c b/src/web/w-comms.c index 9300272..83abb12 100644 --- a/src/web/w-comms.c +++ b/src/web/w-comms.c @@ -745,8 +745,11 @@ http_resp: lws_sul_cancel(&pss->sul_overview); for (n = 0; n < 4; n++) { - if (pss->last_bps[n]) + if (pss->last_bps[n]) { free(pss->last_bps[n]); + pss->last_bps[n] = NULL; + pss->last_bps_len[n] = 0; + } } lwsac_free(&pss->logs_ac); diff --git a/src/web/w-ws-browser.c b/src/web/w-ws-browser.c index 0941c6b..7491697 100644 --- a/src/web/w-ws-browser.c +++ b/src/web/w-ws-browser.c @@ -1911,6 +1911,8 @@ saiw_dedup_and_queue(struct pss *pss, int idx, struct sai_dyn_buf *d) changed = 0; } else { free(pss->last_bps[idx]); + pss->last_bps[idx] = NULL; + pss->last_bps_len[idx] = 0; pss->last_bps[idx] = malloc(d->len - LWS_PRE); if (pss->last_bps[idx]) { memcpy(pss->last_bps[idx], d->buf + LWS_PRE, d->len - LWS_PRE);