Separated assignment from condition so rep contains Call() return value.
Removed incorrect wrapper that prevented state checks from executing.
Now rep values 10/11/12 properly set state.
Fixes#180
Co-authored-by: Levi Neely <lkn@darkstar.example.net>
* Fix pcl-6nb.1: readResponse buffer over-read in rpcclient.cpp
Replace malloc'd receive buffer with stack array, fix the broken
validation (msg->length compared against POVERLAY_BUFSIZE rather
than max_value_size which excluded the header), fix the payload-read
loop target (msg->length already includes the header, so the old
`header_size + msg->length` limit over-read), add the missing
`msg->length > total_read` guard before memcpy, and add EINTR
handling in the read loop. Eliminates heap over-read when the daemon
sends msg->length > POVERLAY_BUFSIZE.
Ref GH #184.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* Add readResponse validation tests (pcl-6nb)
Six socketpair-based test cases covering oversized msg->length,
total_read underrun, header underflow, truncated header, valid
message, and exact-boundary acceptance.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Levi Neely <lkn@darkstar.example.net>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
- Wrap std::stoull() in try/catch to prevent daemon crash on invalid folder ID
- Add proper read loop for RPC messages to handle partial reads
- Validate msg->length before memcpy to prevent heap over-read
- Handle daemon bugs gracefully (EOF before full message)
- Fix operator precedence in sync remove command
Fixes#205, #206
Co-authored-by: Levi Neely <lkn@darkstar.example.net>
- Add return statement in catch(...) block to prevent fallthrough
- Fix operator precedence in GetState() to capture Call() return value
Fixes#201, #202
Co-authored-by: Levi Neely <lkn@darkstar.example.net>
- DoD 5220.22-M compliant memory wipe replaces single-pass zero wipe
- Wipe in-memory request and response messages before freeing
- Wipe in-memory private keys and salt data before freeing
- Wipe all passwords on unlink / logout
- Wipe crypto password on all pcryptofolder_unlock return paths