From 4ba790b921d4b94278f12d6f4ef7c64e6e288e36 Mon Sep 17 00:00:00 2001 From: Evgeny Date: Thu, 4 Jun 2026 00:02:47 +0300 Subject: [PATCH] =?UTF-8?q?fix:=20SIGSEGV=20in=20tcp=5Fproxy=5Fclient=5Fde?= =?UTF-8?q?stroy=20=E2=80=94=20abort=20pcbs=20before=20lwip=20destroy?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Move lwip_tcp_destroy after pcb cleanup to avoid aborting pcbs with already-freed context. Add state != CLOSED guard to tcp_abort. --- src/proxy/tcp_proxy_client.c | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/src/proxy/tcp_proxy_client.c b/src/proxy/tcp_proxy_client.c index d49f5904..da6402d7 100644 --- a/src/proxy/tcp_proxy_client.c +++ b/src/proxy/tcp_proxy_client.c @@ -588,12 +588,11 @@ void tcp_proxy_client_destroy(struct tcp_proxy_client* p) { udp_proxy_destroy(p->inst); icmp_proxy_destroy(p->inst); - if (p->lwip) { lwip_tcp_destroy(p->lwip); p->lwip = NULL; } - struct tcp_proxy_client_conn* pc = p->conns; while (pc) { struct tcp_proxy_client_conn* next = pc->next; - if (pc->pcb) { tcp_arg(pc->pcb, NULL); tcp_abort(pc->pcb); pc->pcb = NULL; } + if (pc->pcb && pc->pcb->state != CLOSED) { tcp_arg(pc->pcb, NULL); tcp_abort(pc->pcb); } + pc->pcb = NULL; if (pc->to_lwip) { struct ll_entry *e; while ((e = queue_data_get(pc->to_lwip))) { queue_dgram_free(e); queue_entry_free(e); } @@ -605,6 +604,8 @@ void tcp_proxy_client_destroy(struct tcp_proxy_client* p) { } p->conns = NULL; + if (p->lwip) { lwip_tcp_destroy(p->lwip); p->lwip = NULL; } + if (p->tun) tun_close(p->tun); if (p->entry_pool) memory_pool_destroy(p->entry_pool); u_free(p);