Files
FastSync/tests
TapTap 6d47d93fd7 fix(config): validate received counts before publishing them
The config_receive_{basis,skip,idmap}_count helpers wrote the
peer-controlled int through the Config member before range-checking it.
An over-cap basis_count therefore left config->basis_count huge while
config->basis_dirs was still NULL; config_receive()'s error path then
called config_delete(), whose basis loop dereferenced NULL and crashed
the daemon before authentication.

Read each count into a local, validate, and only then assign, leaving the
member untouched on failure.  config_delete() also guards the basis loop
with the array pointer as defense in depth.

Add a regression test that feeds over-cap basis/idmap/skip counts and
asserts rejection without crashing, plus a direct config_delete() check
on the partial (count set, array NULL) state.
2026-09-13 11:05:57 +02:00
..
2026-06-10 16:58:35 +02:00
2026-06-10 16:58:35 +02:00
2026-06-10 16:58:35 +02:00
2026-08-16 09:37:28 +02:00
2026-06-10 16:58:35 +02:00
2026-06-10 16:58:35 +02:00
2026-08-16 09:37:28 +02:00