|
|
6bc0ad |
From 3f62e9fbd3de11df52184ca8dfcabfb7d1c0fdeb Mon Sep 17 00:00:00 2001
|
|
|
6bc0ad |
From: Robert Tiemann <rtie@gmx.de>
|
|
|
6bc0ad |
Date: Fri, 17 May 2019 12:43:04 +0200
|
|
|
6bc0ad |
Subject: [PATCH] Avoid possible crash when getting server properties.
|
|
|
6bc0ad |
|
|
|
6bc0ad |
The crash occurs when calling dls_device_get_all_props() for a content
|
|
|
6bc0ad |
directory server that we have not yet subscribed to (that is,
|
|
|
6bc0ad |
prv_cds_subscribed() returns FALSE in
|
|
|
6bc0ad |
prv_get_system_update_id_for_props()). This crash is caused by an
|
|
|
6bc0ad |
invalid GVariantBuilder passed to g_variant_builder_end() in
|
|
|
6bc0ad |
prv_get_sleeping_for_props(), leading to a NULL result pointer being
|
|
|
6bc0ad |
passed to dls_async_task_complete(). A GVariant is attempted to be
|
|
|
6bc0ad |
constructed from this NULL pointer in dls_task_complete().
|
|
|
6bc0ad |
|
|
|
6bc0ad |
Here is the call chain that leads to the crash:
|
|
|
6bc0ad |
|
|
|
6bc0ad |
dls_device_get_all_props()
|
|
|
6bc0ad |
prv_get_system_update_id_for_props()
|
|
|
6bc0ad |
gupnp_service_proxy_begin_action("GetSystemUpdateID") -> prv_system_update_id_for_props_cb()
|
|
|
6bc0ad |
prv_system_update_id_for_props_cb()
|
|
|
6bc0ad |
prv_get_sr_token_for_props()
|
|
|
6bc0ad |
prv_get_sleeping_for_props()
|
|
|
6bc0ad |
dls_async_task_complete()
|
|
|
6bc0ad |
cb_data->cb() -> prv_async_task_complete()
|
|
|
6bc0ad |
prv_async_task_complete()
|
|
|
6bc0ad |
dls_task_complete()
|
|
|
6bc0ad |
g_variant_new()
|
|
|
6bc0ad |
|
|
|
6bc0ad |
The crash was most likely observed when a device running Plex Media
|
|
|
6bc0ad |
Server was present on the network.
|
|
|
6bc0ad |
|
|
|
6bc0ad |
This commit moves the call of g_variant_builder_end() in
|
|
|
6bc0ad |
prv_system_update_id_for_props_cb() (which invalidates the
|
|
|
6bc0ad |
GVariantBuilder used later in prv_get_sleeping_for_props()) to the
|
|
|
6bc0ad |
error handling branch. This leaves the GVariantBuilder alone and
|
|
|
6bc0ad |
allows prv_get_sr_token_for_props() or one of its descendants to call
|
|
|
6bc0ad |
g_variant_builder_end() and complete the task.
|
|
|
6bc0ad |
---
|
|
|
6bc0ad |
libdleyna/server/device.c | 5 ++---
|
|
|
6bc0ad |
1 file changed, 2 insertions(+), 3 deletions(-)
|
|
|
6bc0ad |
|
|
|
6bc0ad |
diff --git a/libdleyna/server/device.c b/libdleyna/server/device.c
|
|
|
6bc0ad |
index d77dfbc2725b..8777da0ea2db 100644
|
|
|
6bc0ad |
--- a/libdleyna/server/device.c
|
|
|
6bc0ad |
+++ b/libdleyna/server/device.c
|
|
|
6bc0ad |
@@ -2256,15 +2256,14 @@ static void prv_system_update_id_for_props_cb(GUPnPServiceProxy *proxy,
|
|
|
6bc0ad |
DLS_SYSTEM_UPDATE_VAR,
|
|
|
6bc0ad |
g_variant_new_uint32(id));
|
|
|
6bc0ad |
|
|
|
6bc0ad |
- cb_data->task.result = g_variant_ref_sink(g_variant_builder_end(
|
|
|
6bc0ad |
- cb_task_data->vb));
|
|
|
6bc0ad |
-
|
|
|
6bc0ad |
on_complete:
|
|
|
6bc0ad |
|
|
|
6bc0ad |
if (!cb_data->error)
|
|
|
6bc0ad |
prv_get_sr_token_for_props(proxy, cb_data->task.target.device,
|
|
|
6bc0ad |
cb_data);
|
|
|
6bc0ad |
else {
|
|
|
6bc0ad |
+ cb_data->task.result = g_variant_ref_sink(g_variant_builder_end(
|
|
|
6bc0ad |
+ cb_task_data->vb));
|
|
|
6bc0ad |
(void) g_idle_add(dls_async_task_complete, cb_data);
|
|
|
6bc0ad |
g_cancellable_disconnect(cb_data->cancellable,
|
|
|
6bc0ad |
cb_data->cancel_id);
|
|
|
6bc0ad |
--
|
|
|
6bc0ad |
2.28.0
|
|
|
6bc0ad |
|