* Fix memory leaks in prpc_sockpath and prpc_main_loop
prpc_sockpath allocated home via ppath_home but never freed it before
returning. prpc_main_loop had three early-return paths that leaked
sockpath before the normal free at bind() success.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Fix memory leaks and bad-free in cache and crypto sector log
pcache.c: cache_timer and pcache_clean called pmem_free(he->value)
directly instead of he->free(he->value), skipping the registered free
callback. This caused all cached SSL connections, TLS sessions, and
crypto decoders to leak their internal mbedtls state on eviction and
shutdown. Same bug fixed in pcache_clean_oneof.
pfscrypto.c: ptree_for_each_element_call_safe passed bare free() to
free psync_sector_inlog_t nodes, but those are allocated via pmem_malloc
which prepends a 16-byte header. Add free_sector_inlog() helper that
calls pmem_free and use it at both call sites.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Fix bad-free in psync_interval_tree_free
Interval tree nodes are allocated via pmem_malloc, which prepends a
16-byte header. Passing bare free() to ptree_for_each_element_call_safe
freed the wrong address. Add free_interval_tree_node() helper that uses
pmem_free and use it in psync_interval_tree_free.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Fix bad-free in pcache callbacks using pmem-allocated values
pcache_add callers in ppagecache.c and pfstasks.c registered bare
free() as the eviction callback, but the stored values were allocated
with pmem_malloc/pmem_malloc_array which prepends a 16-byte header.
After the pcache_clean fix that now correctly invokes callbacks, these
bad-frees became fatal. Replace with static helpers that call pmem_free
with the correct subsystem.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Fix memory leaks in pfs_reopen_file_for_writing and clean_uploads_for_task
pfs.c: encsymkey from pcryptofolder_filencoder_key_get was freed on all
error paths in pfs_reopen_file_for_writing but not on the success path
that returns 1 after ppagecache_copy_to_file_locked.
pfsupload.c: fr from psql_fetchall_int was never freed in
clean_uploads_for_task; add pmem_free after the upload loop.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Fix spurious 'not mounted' error on FUSE3 shutdown
In FUSE3 mode, pfs_do_stop called fuse_unmount followed by fuse_exit.
The FUSE thread then called fuse_destroy, which tried to unmount again,
producing "fusermount3: not mounted".
For FUSE3, fuse_exit is sufficient to stop the loop; fuse_destroy handles
the unmount. Restrict the explicit fuse_unmount call to FUSE2 only.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Levi Neely <lkn@darkstar.example.net>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
prpc.c:
- on_request: fix total_size computation. The original formula
sizeof(uint32_t)+sizeof(uint64_t)+response->length had two bugs:
(1) sizeof(uint32_t)+sizeof(uint64_t)=12 but offsetof(rpc_message_t,value)=16
due to struct alignment padding between the uint32_t type and uint64_t length
fields; and (2) respond() was storing full message size in response->length,
double-counting the header. Fix: use offsetof(rpc_message_t,value)+response->length,
consistent with readResponse() in rpcclient.cpp which reads a fixed header_size
of offsetof(rpc_message_t,value) bytes then reads msg->length payload bytes.
- respond: store payload length only in response->length (value_length+1),
not full message size, to match the client protocol expectation.
- prpc_init: add null check on malloc return value.
- prpc_register: restore old handler table and return -1 if prpc_init fails.
papi.c:
- papi_result_thread: add missing MAX_API_RESPONSE_SIZE guard (present in
papi_result but absent here), preventing server-controlled unbounded malloc.
- papi_result, papi_result_thread: add null checks on malloc before passing
pointer to psock_readall.
- papi_result_async: add MAX_API_RESPONSE_SIZE check and malloc null check
on reader->respsize path.
- calc_ret_len: add _NEED_DATA(1) guard before ARRAY and HASH while-loop
conditions; empty containers with datalen=0 caused out-of-bounds read.
Co-authored-by: Levi Neely <lkn@darkstar.example.net>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
cbidx = request->type - 20 computed before checking lower bound.
If request->type < calbacks_lower_band, cbidx wraps to large value
causing out-of-bounds array access.
Move bounds check before subtraction and use calbacks_lower_band
instead of hardcoded 20.
Fixes GH #235
Co-authored-by: Levi Neely <lkn@darkstar.example.net>
* another stupid macro gone
* more stupid macros gone. moved util functions from plibs to putil
* remaining plist and ptask functions moved to appropriate namespaces
* dead code beleted!
* bugfixes
* move sql functions to psql.c
* move sort functions into ppagecache
* psql namespace
* change plibs.h include to pdbg.h
* cleanup includes