Author: Andy Green Date: Wed Sep 30 22:05:53 2026 +0100 server: ignore builder platforms that have no name A builder that sent a platform without "name" or "platform", eg, one that misread its own conf, crashed sai-server: the platform upsert dereferences both as strings. Skip such platforms, like the ones with unsafe names. Co-Authored-By: Claude Opus 5.5 diff --git a/src/server/s-ws-builder.c b/src/server/s-ws-builder.c index bb0de25..f3b8ded 100644 --- a/src/server/s-ws-builder.c +++ b/src/server/s-ws-builder.c @@ -1002,6 +1002,17 @@ sais_ws_json_rx_builder(struct vhd *vhd, struct pss *pss, uint8_t *buf, size_t b esc_pcon[192], esc_sai_hash[192], esc_lws_hash[192], esc_peer_ip[96]; + /* + * A platform the builder couldn't name (eg, + * from a conf it misread) is no use to us, + * and everything below needs the names + */ + if (!build->name || !build->platform) { + lwsl_notice("%s: ignoring builder plat " + "with no name\n", __func__); + continue; + } + if (sai_str_has_shell_metachars(build->name) || sai_str_has_shell_metachars(build->platform) || (build->pcon &&