Branch: refs/heads/master
Home: https://github.com/OpenSIPS/opensips
Commit: bd1e957022bcd31202c1822f9f9ea1196c2c1929
https://github.com/OpenSIPS/opensips/commit/bd1e957022bcd31202c1822f9f9ea1196c2c1929
Author: weygo <[email protected]>
Date: 2026-09-15 (Tue, 15 Sep 2026)
Changed paths:
M modules/rtpengine/bencode.c
Log Message:
-----------
bencode: fully initialize the buffer before the first allocation
If __bencode_piece_new() fails (pkg memory exhausted),
bencode_buffer_init() returns -1 having only assigned buf->pieces,
leaving free_list and error with their previous (garbage) values.
Callers, which cannot distinguish the failure stage, routinely run
bencode_buffer_free() on the returned error - and the free routine
starts by dereferencing buf->free_list, producing undefined behaviour
(reading a garbage pointer and calling through it).
Zero the whole struct up front: on the failure path the buffer is now
an empty, safely freeable object (both loops in bencode_buffer_free()
simply do not run), while on the success path all three fields are
explicitly assigned, so behaviour is unchanged.
Commit: 82cff17e696edc767b861f11ca7a043a50f99560
https://github.com/OpenSIPS/opensips/commit/82cff17e696edc767b861f11ca7a043a50f99560
Author: weygo <[email protected]>
Date: 2026-09-15 (Tue, 15 Sep 2026)
Changed paths:
M modules/rtpengine/rtpengine.c
Log Message:
-----------
rtpengine: fix heap corruption when caching delete statistics
When a delete reply carrying statistics is processed for a context
that already has stats cached, the code did:
rtpe_stats_free(ctx->stats);
pkg_free(&(ctx->stats->buf));
but buf is an embedded bencode_buffer_t inside struct rtpe_stats -
the second member, after dict - so &ctx->stats->buf is an interior
pointer, not the address pkg_malloc() returned. Freeing it corrupts
the pkg allocator's free lists.
On top of that, ctx->stats itself was not NULLed afterwards, so the
code right below kept using it (writing through ctx->stats->buf =
...) - a dangling pointer write into memory handed back to the
allocator.
Keep the rtpe_stats_free() call (it releases the json string and the
buffer's inner pieces, so the struct can be safely reused once the
three fields are overwritten just below) and drop the bogus
pkg_free(): rtpe_ctx_free() eventually frees the struct itself using
its real base address.
Triggers on the second delete-with-stats reply processed on the same
message context, e.g. a call re-invited through rtpengine again.
Commit: d37af6651b1698b318ff3343ff8cc4d4a2f87e74
https://github.com/OpenSIPS/opensips/commit/d37af6651b1698b318ff3343ff8cc4d4a2f87e74
Author: weygo <[email protected]>
Date: 2026-09-15 (Tue, 15 Sep 2026)
Changed paths:
M modules/rtpengine/rtpengine.c
Log Message:
-----------
rtpengine: close the async reply fd exactly once, and not the node index
Two fd lifecycle bugs in resume_async_send_rtpe_command():
1. The unix branch closes the fd right after read(). But every return
path of this function sets async_status = ASYNC_DONE_CLOSE_FD, so
the async framework (tm/async.c:180, async.c:242) closes the same
fd again right after the resume function returns - a plain double
close, which hits an unrelated descriptor whenever the fd number
gets reused in between.
2. The UDP error branch calls RTPE_IO_ERROR_CLOSE(param->node->idx).
The macro expands to close(_fd) followed by (_fd) = -1, so on its
EPIPE/EBADF branch it:
- closes() whatever descriptor happens to carry the node's array
index number - for the first nodes of a set that is one of the
stdio descriptors (idx 0, 1 or 2);
- overwrites the shared-memory node->idx with -1, turning every
later rtpe_socks[node->idx] access into an out-of-bounds array
access.
Both are fixed by dropping the manual close attempts and leaving the
fd exclusively to the framework, which already guarantees the close
through ASYNC_DONE_CLOSE_FD on all paths.
Commit: 1073a43abdf471076169a4e1c64651156b5bc22d
https://github.com/OpenSIPS/opensips/commit/1073a43abdf471076169a4e1c64651156b5bc22d
Author: weygo <[email protected]>
Date: 2026-09-15 (Tue, 15 Sep 2026)
Changed paths:
M modules/rtpengine/rtpengine.c
Log Message:
-----------
rtpengine: check the pkg_malloc() result of the async buffer
rtpe_function_call_async() does not check the bencbuf allocation
result before passing it on: on pkg memory exhaustion the very first
touch of the buffer (bencode_buffer_init()) dereferences the NULL
pointer and crashes the worker.
No resources have been allocated at that point, so a plain early
return is sufficient.
Commit: 5dd98a2c880c32f5eae8e1b962bd9bbf1f50bda6
https://github.com/OpenSIPS/opensips/commit/5dd98a2c880c32f5eae8e1b962bd9bbf1f50bda6
Author: Razvan Crainea <[email protected]>
Date: 2026-09-23 (Wed, 23 Sep 2026)
Changed paths:
M modules/rtpengine/rtpengine.c
Log Message:
-----------
rtpengine: initialize async buffer before early cleanup
Commit: a85720cb22e914cdf4dfcee004df0ee8ee624793
https://github.com/OpenSIPS/opensips/commit/a85720cb22e914cdf4dfcee004df0ee8ee624793
Author: Răzvan Crainea <[email protected]>
Date: 2026-09-23 (Wed, 23 Sep 2026)
Changed paths:
M modules/rtpengine/bencode.c
M modules/rtpengine/rtpengine.c
Log Message:
-----------
Merge pull request #4263 from zbyslb/rtpengine-bugfixes
rtpengine/bencode: heap corruption, double close, wrong-fd close and OOM crash
fixes
Compare:
https://github.com/OpenSIPS/opensips/compare/f88b87756185...a85720cb22e9
To unsubscribe from these emails, change your notification settings at
https://github.com/OpenSIPS/opensips/settings/notifications
_______________________________________________
Devel mailing list
[email protected]
http://lists.opensips.org/cgi-bin/mailman/listinfo/devel