Browse Source

uasync: replace raw socket_node pointer with index-based handle — fix UAF after realloc

chatgui
Evgeny 3 months ago
parent
commit
8962f58ea4
  1. 18
      lib/u_async.c

18
lib/u_async.c

@ -675,14 +675,16 @@ void* uasync_add_socket(struct UASYNC* ua, int fd, socket_callback_t read_cbk, s
}
#endif
// Return pointer to the socket node as ID
return &ua->sockets->sockets[index];
// Return index-based handle
return (void*)(uintptr_t)(index + 1);
}
err_t uasync_remove_socket(struct UASYNC* ua, void* s_id) {
if (!ua || !s_id) return ERR_FAIL;
struct socket_node* node = (struct socket_node*)s_id;
int i = (int)(uintptr_t)s_id - 1;
if (i < 0 || i >= ua->sockets->capacity) return ERR_FAIL;
struct socket_node* node = &ua->sockets->sockets[i];
if (!node->active || node->fd < 0) return ERR_FAIL;
int fd = node->fd;
@ -736,7 +738,7 @@ void* uasync_add_socket_t(struct UASYNC* ua, socket_t sock, socket_t_callback_t
}
#endif
return &ua->sockets->sockets[index];
return (void*)(uintptr_t)(index + 1); /* +1: index 0 ≠ NULL */
}
// Remove socket by socket_t
@ -774,7 +776,9 @@ err_t uasync_remove_socket_t(struct UASYNC* ua, socket_t sock) {
err_t uasync_set_socket_read(struct UASYNC* ua, void* s_id, int enable) {
if (!ua || !s_id) return ERR_FAIL;
struct socket_node* node = (struct socket_node*)s_id;
int i = (int)(uintptr_t)s_id - 1;
if (i < 0 || i >= ua->sockets->capacity) return ERR_FAIL;
struct socket_node* node = &ua->sockets->sockets[i];
if (!node->active || node->fd < 0) return ERR_FAIL;
int val = enable ? 1 : 0;
@ -811,7 +815,9 @@ err_t uasync_set_socket_read(struct UASYNC* ua, void* s_id, int enable) {
err_t uasync_set_socket_write(struct UASYNC* ua, void* s_id, int enable) {
if (!ua || !s_id) return ERR_FAIL;
struct socket_node* node = (struct socket_node*)s_id;
int i = (int)(uintptr_t)s_id - 1;
if (i < 0 || i >= ua->sockets->capacity) return ERR_FAIL;
struct socket_node* node = &ua->sockets->sockets[i];
if (!node->active || node->fd < 0) return ERR_FAIL;
int val = enable ? 1 : 0;

Loading…
Cancel
Save