Browse Source

fix pkt_normalizer: null deref on alloc fail, mtu underflow, unchecked pn_buf_renew in loop

congestion
Evgeny 5 months ago
parent
commit
5aa9bdbd64
  1. 9
      src/pkt_normalizer.c

9
src/pkt_normalizer.c

@ -30,7 +30,6 @@ struct PKTNORM* pn_init(struct ETCP_CONN* etcp) {
struct PKTNORM* pn = u_calloc(1, sizeof(struct PKTNORM)); struct PKTNORM* pn = u_calloc(1, sizeof(struct PKTNORM));
if (!pn) { if (!pn) {
pn->alloc_errors++;
DEBUG_ERROR(DEBUG_CATEGORY_NORMALIZER, "pn_init: calloc failed"); DEBUG_ERROR(DEBUG_CATEGORY_NORMALIZER, "pn_init: calloc failed");
return NULL; return NULL;
} }
@ -40,7 +39,12 @@ struct PKTNORM* pn_init(struct ETCP_CONN* etcp) {
pn->etcp = etcp; pn->etcp = etcp;
pn->ua = etcp->instance->ua; pn->ua = etcp->instance->ua;
pn->frag_size = etcp->mtu - ACK_REZERV - UDP_HDR_SIZE - UDP_SC_HDR_SIZE; // Use MTU as fixed packet size (adjust if headers need subtraction) pn->frag_size = etcp->mtu - ACK_REZERV - UDP_HDR_SIZE - UDP_SC_HDR_SIZE;
int min_frag = UDP_HDR_SIZE + UDP_SC_HDR_SIZE + ACK_REZERV;
if (etcp->mtu < min_frag || pn->frag_size > etcp->mtu) {
DEBUG_ERROR(DEBUG_CATEGORY_NORMALIZER, "pn_init: MTU %d too small (min %d)", etcp->mtu, min_frag);
pn->frag_size = etcp->mtu;
}
pn->tx_wait_time = 10; pn->tx_wait_time = 10;
pn->input = queue_new(pn->ua, 0, 0, 0, "pn_input"); // No hash needed pn->input = queue_new(pn->ua, 0, 0, 0, "pn_input"); // No hash needed
@ -298,6 +302,7 @@ static void etcp_input_ready_cb(struct ll_queue* q, void* arg) {
pn->data_ptr += remain; pn->data_ptr += remain;
in_ptr += remain; in_ptr += remain;
pn_buf_renew(pn); pn_buf_renew(pn);
if (!pn->data) goto exit;
} }
exit: exit:

Loading…
Cancel
Save