Branch: refs/heads/master
  Home:   https://github.com/OpenSIPS/opensips
  Commit: 3aeb82f8411d97153c0e0908be27c17152dc17ca
      
https://github.com/OpenSIPS/opensips/commit/3aeb82f8411d97153c0e0908be27c17152dc17ca
  Author: Yury Kirsanov <[email protected]>
  Date:   2026-09-11 (Fri, 11 Sep 2026)

  Changed paths:
    M modules/rtp_relay/rtp_relay_ctx.c

  Log Message:
  -----------
  rtp_relay: give the caller its own copy of the route engine's body

rtp_relay_route_fill_body() returned the script's return value by
assignment, but script_return_set() stores that value in a single pkg
allocation with an inline buffer (v->val.rs.s = v->buf), so val.rs.s
points 32 bytes into a block the core owns and frees itself.

The callers of the offer/answer engine hooks take ownership of the body
they get back: rtp_relay_reinvite() pkg_free()s it, and the reply path
hands it to replace_lump_rpl() with LUMP_RPL_NODUP, which frees it too.
The rtpengine engine already honours that contract, filling the body
from bencode_dictionary_get_str_dup(). The route engine did not, so the
first of those frees ran on an interior pointer and f_malloc read the
fragment header from inside the allocation's own header, ending in a
SIGSEGV in fm_remove_free(). check_double_free() cannot catch it:
frag_seems_valid() only tests that f->pf lies inside the block, and here
f->pf reads val.rs.s, which is the pointer being freed.

Duplicate the value into the caller's str instead. Also drop the second
rtp_relay_replace_body() in rtp_relay_route_offer(): the message body is
already replaced inside rtp_relay_route_fill_body() using a copy of its
own, and now that the caller owns the returned buffer, passing it to a
lump as well would make the message free it a second time.


  Commit: 1a7425ee9e503a9b32d87e0d2ab46648aa51ee26
      
https://github.com/OpenSIPS/opensips/commit/1a7425ee9e503a9b32d87e0d2ab46648aa51ee26
  Author: Razvan Crainea <[email protected]>
  Date:   2026-09-23 (Wed, 23 Sep 2026)

  Changed paths:
    M modules/rtp_relay/rtp_relay_ctx.c

  Log Message:
  -----------
  rtp_relay: release route body on node copy failure


  Commit: cc302893896bb6bb824713bf22849fc178cc1db8
      
https://github.com/OpenSIPS/opensips/commit/cc302893896bb6bb824713bf22849fc178cc1db8
  Author: Răzvan Crainea <[email protected]>
  Date:   2026-09-23 (Wed, 23 Sep 2026)

  Changed paths:
    M modules/rtp_relay/rtp_relay_ctx.c

  Log Message:
  -----------
  Merge pull request #4256 from Lt-Flash/fix/rtp-relay-route-body-ownership

rtp_relay: give the caller its own copy of the route engine's body


Compare: 
https://github.com/OpenSIPS/opensips/compare/1e5f9ddaca4f...cc302893896b

To unsubscribe from these emails, change your notification settings at 
https://github.com/OpenSIPS/opensips/settings/notifications

_______________________________________________
Devel mailing list
[email protected]
http://lists.opensips.org/cgi-bin/mailman/listinfo/devel

Reply via email to