Branch: refs/heads/master
Home: https://github.com/OpenSIPS/opensips
Commit: 3aeb82f8411d97153c0e0908be27c17152dc17ca
https://github.com/OpenSIPS/opensips/commit/3aeb82f8411d97153c0e0908be27c17152dc17ca
Author: Yury Kirsanov <[email protected]>
Date: 2026-09-11 (Fri, 11 Sep 2026)
Changed paths:
M modules/rtp_relay/rtp_relay_ctx.c
Log Message:
-----------
rtp_relay: give the caller its own copy of the route engine's body
rtp_relay_route_fill_body() returned the script's return value by
assignment, but script_return_set() stores that value in a single pkg
allocation with an inline buffer (v->val.rs.s = v->buf), so val.rs.s
points 32 bytes into a block the core owns and frees itself.
The callers of the offer/answer engine hooks take ownership of the body
they get back: rtp_relay_reinvite() pkg_free()s it, and the reply path
hands it to replace_lump_rpl() with LUMP_RPL_NODUP, which frees it too.
The rtpengine engine already honours that contract, filling the body
from bencode_dictionary_get_str_dup(). The route engine did not, so the
first of those frees ran on an interior pointer and f_malloc read the
fragment header from inside the allocation's own header, ending in a
SIGSEGV in fm_remove_free(). check_double_free() cannot catch it:
frag_seems_valid() only tests that f->pf lies inside the block, and here
f->pf reads val.rs.s, which is the pointer being freed.
Duplicate the value into the caller's str instead. Also drop the second
rtp_relay_replace_body() in rtp_relay_route_offer(): the message body is
already replaced inside rtp_relay_route_fill_body() using a copy of its
own, and now that the caller owns the returned buffer, passing it to a
lump as well would make the message free it a second time.
Commit: 1a7425ee9e503a9b32d87e0d2ab46648aa51ee26
https://github.com/OpenSIPS/opensips/commit/1a7425ee9e503a9b32d87e0d2ab46648aa51ee26
Author: Razvan Crainea <[email protected]>
Date: 2026-09-23 (Wed, 23 Sep 2026)
Changed paths:
M modules/rtp_relay/rtp_relay_ctx.c
Log Message:
-----------
rtp_relay: release route body on node copy failure
Commit: cc302893896bb6bb824713bf22849fc178cc1db8
https://github.com/OpenSIPS/opensips/commit/cc302893896bb6bb824713bf22849fc178cc1db8
Author: Răzvan Crainea <[email protected]>
Date: 2026-09-23 (Wed, 23 Sep 2026)
Changed paths:
M modules/rtp_relay/rtp_relay_ctx.c
Log Message:
-----------
Merge pull request #4256 from Lt-Flash/fix/rtp-relay-route-body-ownership
rtp_relay: give the caller its own copy of the route engine's body
Compare:
https://github.com/OpenSIPS/opensips/compare/1e5f9ddaca4f...cc302893896b
To unsubscribe from these emails, change your notification settings at
https://github.com/OpenSIPS/opensips/settings/notifications
_______________________________________________
Devel mailing list
[email protected]
http://lists.opensips.org/cgi-bin/mailman/listinfo/devel