Where: src/shared/file_receive.c:241-248 (new_size > MAX_RECEIVE_FILE_SIZE), :281-288 (data_create failure). Other NULL paths correctly set *failed.
Problem: These two paths send STATUS_ERROR and return NULL WITHOUT *failed=true. Caller receive_incremental_check (474-492) then treats delta as "not attempted", sends STATUS_NEXT and blocks in receive_data_limited waiting for a body the client will never send -> protocol desync, up-to-60s timeout, confusing mid-stream abort.
Fix: Set *failed=true on every return NULL in receive_delta_file after signature is sent (or restructure to an enum).
Unit test required driving the oversized/corrupt delta path.
Found by bug hunt + code review of `dev` (9f8b588).
**Where:** src/shared/file_receive.c:241-248 (new_size > MAX_RECEIVE_FILE_SIZE), :281-288 (data_create failure). Other NULL paths correctly set *failed.
**Problem:** These two paths send STATUS_ERROR and return NULL WITHOUT *failed=true. Caller receive_incremental_check (474-492) then treats delta as "not attempted", sends STATUS_NEXT and blocks in receive_data_limited waiting for a body the client will never send -> protocol desync, up-to-60s timeout, confusing mid-stream abort.
**Fix:** Set *failed=true on every return NULL in receive_delta_file after signature is sent (or restructure to an enum).
Unit test required driving the oversized/corrupt delta path.
Fixed on dev via fix/receiver-correctness (14c064a) + hardening commit f7c6c91: *failed now set on every NULL return in receive_delta_file (incl. oversize + data_create paths); incremental oversize branch no longer double-sends STATUS_ERROR.
CI run #461: all jobs green (lint, build-and-test, sanitizers address+undefined, fuzz-build, coverage, valgrind). Unit 25/25, integration 83 passed / 10 skipped / 1 xpassed. Closing.
**Resolved on `dev`** (HEAD f7c6c91).
Fixed on dev via fix/receiver-correctness (14c064a) + hardening commit f7c6c91: *failed now set on every NULL return in receive_delta_file (incl. oversize + data_create paths); incremental oversize branch no longer double-sends STATUS_ERROR.
CI run #461: all jobs green (lint, build-and-test, sanitizers address+undefined, fuzz-build, coverage, valgrind). Unit 25/25, integration 83 passed / 10 skipped / 1 xpassed. Closing.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found by bug hunt + code review of
dev(9f8b588).Where: src/shared/file_receive.c:241-248 (new_size > MAX_RECEIVE_FILE_SIZE), :281-288 (data_create failure). Other NULL paths correctly set *failed.
Problem: These two paths send STATUS_ERROR and return NULL WITHOUT *failed=true. Caller receive_incremental_check (474-492) then treats delta as "not attempted", sends STATUS_NEXT and blocks in receive_data_limited waiting for a body the client will never send -> protocol desync, up-to-60s timeout, confusing mid-stream abort.
Fix: Set *failed=true on every return NULL in receive_delta_file after signature is sent (or restructure to an enum).
Unit test required driving the oversized/corrupt delta path.
Resolved on
dev(HEADf7c6c91).Fixed on dev via fix/receiver-correctness (
14c064a) + hardening commitf7c6c91: *failed now set on every NULL return in receive_delta_file (incl. oversize + data_create paths); incremental oversize branch no longer double-sends STATUS_ERROR.CI run #461: all jobs green (lint, build-and-test, sanitizers address+undefined, fuzz-build, coverage, valgrind). Unit 25/25, integration 83 passed / 10 skipped / 1 xpassed. Closing.