From 61ca2600ca83923be9a8a5657fc70bdb26b03723 Mon Sep 17 00:00:00 2001 From: theMackabu Date: Sun, 29 Mar 2026 19:22:36 -0700 Subject: [PATCH] fix segfault on freed filename --- include/http/http1_writer.h | 1 + src/http/http1_parser.c | 12 ++++++------ src/http/http1_writer.c | 7 +++++++ src/main.c | 10 ++++++++-- 4 files changed, 22 insertions(+), 8 deletions(-) diff --git a/include/http/http1_writer.h b/include/http/http1_writer.h index 56adbac..ddd20a9 100644 --- a/include/http/http1_writer.h +++ b/include/http/http1_writer.h @@ -26,6 +26,7 @@ bool ant_http1_buffer_appendfv(ant_http1_buffer_t *buf, const char *fmt, va_list const char *ant_http1_default_status_text(int status); char *ant_http1_buffer_take(ant_http1_buffer_t *buf, size_t *len_out); +char *ant_http1_buffer_take_cstr(ant_http1_buffer_t *buf); bool ant_http1_write_basic_response( ant_http1_buffer_t *buf, diff --git a/src/http/http1_parser.c b/src/http/http1_parser.c index 09fd1cb..91cf719 100644 --- a/src/http/http1_parser.c +++ b/src/http/http1_parser.c @@ -30,8 +30,8 @@ static bool parser_copy_header(parser_ctx_t *ctx) { ant_http_header_t *hdr = calloc(1, sizeof(*hdr)); if (!hdr) return false; - hdr->name = ant_http1_buffer_take(&ctx->header_field, NULL); - hdr->value = ant_http1_buffer_take(&ctx->header_value, NULL); + hdr->name = ant_http1_buffer_take_cstr(&ctx->header_field); + hdr->value = ant_http1_buffer_take_cstr(&ctx->header_value); if (!hdr->name || !hdr->value) { free(hdr->name); free(hdr->value); @@ -153,8 +153,8 @@ ant_http1_parse_result_t ant_http1_parse_request( if (out->consumed_len == 0) ctx.req.consumed_len = len; else ctx.req.consumed_len = out->consumed_len; - ctx.req.method = ant_http1_buffer_take(&ctx.method, NULL); - ctx.req.target = ant_http1_buffer_take(&ctx.target, NULL); + ctx.req.method = ant_http1_buffer_take_cstr(&ctx.method); + ctx.req.target = ant_http1_buffer_take_cstr(&ctx.target); ctx.req.body = (uint8_t *)ant_http1_buffer_take(&ctx.body, &ctx.req.body_len); if (!ctx.req.method || !ctx.req.target) { parser_ctx_free(&ctx); @@ -263,8 +263,8 @@ ant_http1_parse_result_t ant_http1_conn_parser_execute( if (consumed_out && *consumed_out == 0) *consumed_out = len; cp->ctx.req.consumed_len = consumed_out ? *consumed_out : len; - cp->ctx.req.method = ant_http1_buffer_take(&cp->ctx.method, NULL); - cp->ctx.req.target = ant_http1_buffer_take(&cp->ctx.target, NULL); + cp->ctx.req.method = ant_http1_buffer_take_cstr(&cp->ctx.method); + cp->ctx.req.target = ant_http1_buffer_take_cstr(&cp->ctx.target); cp->ctx.req.body = (uint8_t *)ant_http1_buffer_take(&cp->ctx.body, &cp->ctx.req.body_len); if (!cp->ctx.req.method || !cp->ctx.req.target) diff --git a/src/http/http1_writer.c b/src/http/http1_writer.c index 21cc63f..2a94e8f 100644 --- a/src/http/http1_writer.c +++ b/src/http/http1_writer.c @@ -96,6 +96,13 @@ char *ant_http1_buffer_take(ant_http1_buffer_t *buf, size_t *len_out) { return data; } +char *ant_http1_buffer_take_cstr(ant_http1_buffer_t *buf) { + if (!buf) return NULL; + if (!ant_http1_buffer_reserve(buf, 1)) return NULL; + buf->data[buf->len] = '\0'; + return ant_http1_buffer_take(buf, NULL); +} + void ant_http1_buffer_free(ant_http1_buffer_t *buf) { free(buf->data); buf->data = NULL; diff --git a/src/main.c b/src/main.c index a320799..d9f57d2 100644 --- a/src/main.c +++ b/src/main.c @@ -317,7 +317,9 @@ static void eval_code(ant_t *js, const char *script, size_t len, const char *tag static int execute_module(ant_t *js, const char *filename) { char *use_path_owned = NULL; + const char *use_path = filename; + const char *stable_use_path = filename; ant_value_t ns = 0; ant_value_t specifier = 0; @@ -336,14 +338,18 @@ static int execute_module(ant_t *js, const char *filename) { if (use_path_owned) use_path = use_path_owned; specifier = js_esm_make_file_url(js, use_path); } + + const char *interned = intern_string(use_path, strlen(use_path)); + if (interned) stable_use_path = interned; + else stable_use_path = use_path; js_set(js, js_glob(js), "__filename", js_mkstr(js, filename, strlen(filename)) ); - js_set_filename(js, use_path); - js_setup_import_meta(js, use_path); + js_set_filename(js, stable_use_path); + js_setup_import_meta(js, stable_use_path); ns = js_esm_import_sync(js, specifier); free(use_path_owned); -- 2.51.2