Author: Andy Green Date: Sun Sep 06 07:28:51 2026 +0100 web: drop browser-originated loadreport and unhandled rx schemas, fixes F-001 An unauthenticated browser could send {"schema":"com.warmcat.sai.loadreport"} on /sai/browse*: the schema is in the browser rx map (index 8) but had no case in the switch in saiw_ws_json_rx_browser(), so control fell into default: assert(0) and aborted the whole sai-web process for all users. Handle it explicitly: load reports originate from builders and are only ever broadcast by us towards browsers, so a browser sending one is dropped with a log rather than forwarded (sai-server does not accept this schema on the web link and would tear it down trying to decode it). The default arm now logs and drops instead of asserting, so a future map entry without a case above cannot be turned into a remote crash either; the unused include is removed. diff --git a/src/web/w-ws-browser.c b/src/web/w-ws-browser.c index ec842ca..3ac9dc2 100644 --- a/src/web/w-ws-browser.c +++ b/src/web/w-ws-browser.c @@ -29,7 +29,6 @@ #include #include #include -#include #include #include "w-private.h" @@ -1097,9 +1096,26 @@ saiw_ws_json_rx_browser(struct vhd *vhd, struct pss *pss, uint8_t *buf, case SAIM_WS_BROWSER_RX_PTYDATA: break; + /* + * Load reports flow builder -> server -> us -> browsers; a browser + * sending one is meaningless. Drop it locally rather than forward + * it, sai-server does not accept this schema on the web link and + * would tear the link down trying to decode it. + */ + case SAIM_WS_BROWSER_RX_LOADREPORT: + lwsl_notice("%s: dropping loadreport from browser\n", __func__); + goto ok; + default: - assert(0); - break; + /* + * No schema in the map today reaches here. If one is added + * to the map without a case above, log and drop it rather + * than assert (remote-crashable) or forward an unknown + * schema on the server link. + */ + lwsl_notice("%s: unhandled schema index %d from browser, dropping\n", + __func__, a.top_schema_index); + goto ok; } sai_ss_queue_frag_on_buflist_REQUIRES_LWS_PRE(vhd->h_ss_websrv,