Author: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Wed Sep 17 15:37:49 2025 +0100 Fix path corruption in sai_deletion_worker The sai_deletion_worker function was using the same buffer as both a source and destination in an lws_snprintf call. This is undefined behavior and resulted in a corrupted path being generated for directory deletion, with the home directory path being prepended twice. This was fixed by using a separate buffer for the output of lws_snprintf, which is the correct way to handle this and avoids the buffer overlap. diff --git a/src/builder/b-sai.c b/src/builder/b-sai.c index 75d35a7..e6222f6 100644 --- a/src/builder/b-sai.c +++ b/src/builder/b-sai.c @@ -104,10 +104,16 @@ sai_deletion_worker(const char *home_dir) if (!p) continue; - lws_snprintf(path, sizeof(path), "%s/jobs/%s", home_dir, path); + { + char full_path[PATH_MAX]; + + lws_snprintf(full_path, sizeof(full_path), "%s/jobs/%s", + home_dir, path); - if (lws_dir(path, NULL, lws_dir_rm_rf_cb)) - lwsl_err("%s: failed to delete %s\n", __func__, path); + if (lws_dir(full_path, NULL, lws_dir_rm_rf_cb)) + lwsl_err("%s: failed to delete %s\n", __func__, + full_path); + } } return 0;