fix(protocol): release Data charge to its owning session

Data charged against a ProtocolSession kept only the charge amount, so
data_destroy released it from whatever session was thread-locally bound
at destroy time. Destroying a received Data on another thread, after the
session was unbound, or while a different session was bound leaked the
originating session's budget and underflowed the other's.

Add Data.owner, set it whenever protocol_receive_data_limited charges a
session, and have data_destroy release against that owner directly via
the newly-exported protocol_release_memory_for_session. Uncharged Data
(owner NULL) keeps the previous bound-session fallback.

Add a unit test proving a Data acquired on session A is released to A
even when unrelated session B is bound at destroy time.
This commit is contained in:
2026-09-13 10:05:38 +02:00
parent 9242e86772
commit 5d3c43305e
5 changed files with 71 additions and 3 deletions
+1
View File
@@ -1157,6 +1157,7 @@ static int send_append(const Client* client, File* file, Config* config,
tail_view.data = (char*)file->data->data + off;
tail_view.size = tail_len;
tail_view.protocol_charge = 0;
tail_view.owner = NULL;
ok = send_data(fd, &tail_view);
}
return ok ? 0 : -1;