Browse Source

fix: SIGSEGV in tcp_proxy_client_destroy — abort pcbs before lwip destroy

Move lwip_tcp_destroy after pcb cleanup to avoid aborting pcbs
with already-freed context. Add state != CLOSED guard to tcp_abort.
etcp-inflight-fix
Evgeny 4 months ago
parent
commit
4ba790b921
  1. 7
      src/proxy/tcp_proxy_client.c

7
src/proxy/tcp_proxy_client.c

@ -588,12 +588,11 @@ void tcp_proxy_client_destroy(struct tcp_proxy_client* p) {
udp_proxy_destroy(p->inst);
icmp_proxy_destroy(p->inst);
if (p->lwip) { lwip_tcp_destroy(p->lwip); p->lwip = NULL; }
struct tcp_proxy_client_conn* pc = p->conns;
while (pc) {
struct tcp_proxy_client_conn* next = pc->next;
if (pc->pcb) { tcp_arg(pc->pcb, NULL); tcp_abort(pc->pcb); pc->pcb = NULL; }
if (pc->pcb && pc->pcb->state != CLOSED) { tcp_arg(pc->pcb, NULL); tcp_abort(pc->pcb); }
pc->pcb = NULL;
if (pc->to_lwip) {
struct ll_entry *e;
while ((e = queue_data_get(pc->to_lwip))) { queue_dgram_free(e); queue_entry_free(e); }
@ -605,6 +604,8 @@ void tcp_proxy_client_destroy(struct tcp_proxy_client* p) {
}
p->conns = NULL;
if (p->lwip) { lwip_tcp_destroy(p->lwip); p->lwip = NULL; }
if (p->tun) tun_close(p->tun);
if (p->entry_pool) memory_pool_destroy(p->entry_pool);
u_free(p);

Loading…
Cancel
Save