diff --git a/pclsync/papi.c b/pclsync/papi.c index 88ddb45..ced472f 100644 --- a/pclsync/papi.c +++ b/pclsync/papi.c @@ -201,6 +201,7 @@ static ssize_t calc_ret_len(unsigned char **restrict data, int unsigned cnt; cnt = 0; ret = sizeof(binresult); + _NEED_DATA(1); while (**data != RPARAM_END) { r = calc_ret_len(data, datalen, strcnt); if (r == -1) @@ -218,6 +219,7 @@ static ssize_t calc_ret_len(unsigned char **restrict data, int unsigned cnt; cnt = 0; ret = sizeof(binresult); + _NEED_DATA(1); while (**data != RPARAM_END) { r = calc_ret_len(data, datalen, strcnt); if (r == -1) @@ -405,6 +407,10 @@ binresult *papi_result(psock_t *sock) { } data = (unsigned char *)malloc(ressize); + if (!data) { + pdbg_logf(D_ERROR, "Failed to allocate %u bytes for API response", ressize); + return NULL; + } if (pdbg_unlikely(psock_readall(sock, data, ressize) != ressize)) { free(data); @@ -424,7 +430,16 @@ binresult *papi_result_thread(psock_t *sock) { if (pdbg_unlikely(psock_readall_thread( sock, &ressize, sizeof(uint32_t)) != sizeof(uint32_t))) return NULL; + if (ressize > MAX_API_RESPONSE_SIZE) { + pdbg_logf(D_WARNING, "API response size %u exceeds limit %u, rejecting", + ressize, MAX_API_RESPONSE_SIZE); + return NULL; + } data = (unsigned char *)malloc(ressize); + if (!data) { + pdbg_logf(D_ERROR, "Failed to allocate %u bytes for API response", ressize); + return NULL; + } if (pdbg_unlikely(psock_readall_thread(sock, data, ressize) != ressize)) { free(data); @@ -467,8 +482,17 @@ again: reader->state = 1; reader->bytesread = 0; reader->bytestoread = reader->respsize; + if (reader->respsize > MAX_API_RESPONSE_SIZE) { + pdbg_logf(D_WARNING, "API response size %u exceeds limit %u, rejecting", + reader->respsize, MAX_API_RESPONSE_SIZE); + reader->result = NULL; + papi_rdr_alloc(reader); + return ASYNC_RES_READY; + } reader->data = (unsigned char *)malloc(reader->respsize); if (!reader->data) { + pdbg_logf(D_ERROR, "Failed to allocate %u bytes for API response", + reader->respsize); reader->result = NULL; papi_rdr_alloc(reader); return ASYNC_RES_READY; diff --git a/pclsync/prpc.c b/pclsync/prpc.c index 1c0cf89..49ab50b 100644 --- a/pclsync/prpc.c +++ b/pclsync/prpc.c @@ -36,6 +36,7 @@ */ #include +#include #include #include #include @@ -108,7 +109,7 @@ static void on_request(void *lpvParam) { if (request) { respond(request, response); - ssize_t total_size = sizeof(uint32_t) + sizeof(uint64_t) + response->length; + ssize_t total_size = offsetof(rpc_message_t, value) + response->length; ssize_t bytes_written = write(*sockfd, response, total_size); if (bytes_written == -1) { @@ -229,7 +230,7 @@ static void respond(rpc_message_t *request, rpc_message_t *response) { response->value[value_length] = '\0'; pdbg_logf(D_WARNING, "Response message truncated to fit buffer"); } - response->length = sizeof(rpc_message_t) + value_length + 1; + response->length = value_length + 1; } void prpc_main_loop() { @@ -297,6 +298,11 @@ int prpc_register(int cmdid, prpc_handler h) { if (cmdid > (calbacks_lower_band + handlers_size)) { handlers_size = cmdid - calbacks_lower_band + 1; prpc_init(); + if (!handlers) { + handlers = handlers_old; + handlers_size = handlers_size_old; + return -1; + } memcpy(handlers, handlers_old, handlers_size_old * sizeof(prpc_handler)); free(handlers_old); @@ -307,6 +313,10 @@ int prpc_register(int cmdid, prpc_handler h) { void prpc_init() { handlers = (prpc_handler *)malloc(sizeof(prpc_handler) * handlers_size); + if (!handlers) { + pdbg_logf(D_ERROR, "Failed to allocate handler table"); + return; + } memset(handlers, 0, sizeof(prpc_handler) * handlers_size); }