Commit Graph

30156 Commits

Author SHA1 Message Date
George Joseph
4392cc4a61 Merge "AST-2017-010: Fix cdr_object_update_party_b_userfield_cb() buf overrun" into 15 2017-11-08 08:26:58 -06:00
Jenkins2
85057a9ee5 Merge "res_pjproject.c: Fix ast_strdup() alloc failure." into 15 2017-11-08 07:39:02 -06:00
Kevin Harwell
1fe507a237 AST-2017-011 - res_pjsip_session: session leak when a call is rejected
A previous commit made it so when an invite session transitioned into a
disconnected state destruction of the Asterisk pjsip session object was
postponed until either a transport error occurred or the event timer
expired. However, if a call was rejected (for instance a 488) before the
session was fully established the event timer may not have been initiated,
or it was canceled without triggering either of the session finalizing states
mentioned above.

Really the only time destruction of the session should be delayed is when a
BYE is being transacted. This is because it's possible in some cases for the
session to be disconnected, but the BYE is still transacting.

This patch makes it so the session object always gets released (no more
memory leak) when the pjsip session is in a disconnected state. Except when
the method is a BYE. Then it waits until a transport error occurs or an event
timeout.

ASTERISK-27345 #close

Reported by: Corey Farrell

Change-Id: I1e724737b758c20ac76d19d3611e3d2876ae10ed
2017-11-08 05:49:21 -07:00
Richard Mudgett
5f501b339e AST-2017-010: Fix cdr_object_update_party_b_userfield_cb() buf overrun
cdr_object_update_party_b_userfield_cb() could overrun the fixed buffer if
the supplied string is too long.  The long string could be supplied by
external means using the CDR(userfield) function.

This may seem reminiscent to AST-2017-001 (ASTERISK_26897) and it is.  The
earlier patch fixed the buffer overrun for Party A's userfield while this
patch fixes the same thing for Party B's userfield.

ASTERISK-27337

Change-Id: I0fa767f65ecec7e676ca465306ff9e0edbf3b652
2017-11-08 05:40:34 -07:00
George Joseph
a1f21934b7 AST-2017-009: pjproject: Add validation of numeric header values
Parsing the numeric header fields like cseq, ttl, port, etc. all
had the potential to overflow, either causing unintended values to
be captured or, if the values were subsequently converted back to
strings, a buffer overrun.  To address this, new "strto" functions
have been created that do range checking and those functions are
used wherever possible in the parser.

 * Created pjlib/include/limits.h and pjlib/include/compat/limits.h
   to either include the system limits.h or define common numeric
   limits if there is no system limits.h.

 * Created strto*_validate functions in sip_parser that take bounds
   and on failure call the on_str_parse_error function which prints
   an error message and calls PJ_THROW.

 * Updated sip_parser to validate the numeric fields.

 * Fixed an issue in sip_transport that prevented error messages
   from being properly displayed.

 * Added "volatile" to some variables referenced in PJ_CATCH blocks
   as the optimizer was sometimes optimizing them away.

 * Fixed length calculation in sip_transaction/create_tsx_key_2543
   to account for signed ints being 11 characters, not 9.

ASTERISK-27319
Reported by: Youngsung Kim at LINE Corporation

Change-Id: I48de2e4ccf196990906304e8d7061f4ffdd772ff
2017-11-08 05:25:40 -07:00
Joshua Colp
85155b3cf5 Merge "res_pjsip_exten_state: Check for vector append failure." into 15 2017-11-08 04:59:08 -06:00
Joshua Colp
33e42b2067 Merge "res_stasis: Fix multiple leaks." into 15 2017-11-08 04:57:13 -06:00
Joshua Colp
37afdcde2c Merge "res_pjsip_outbound_registration: Fix leak on vector add failure." into 15 2017-11-08 04:56:50 -06:00
Jenkins2
1f09784d28 Merge "res_pjsip: Avoid crash when contact uri is empty string" into 15 2017-11-08 00:14:13 -06:00
Jenkins2
446b3ea862 Merge "res_pjsip: Fix leak on error in ast_sip_auth_vector_init." into 15 2017-11-07 22:34:47 -06:00
Jenkins2
82f85f954e Merge "stream: Return error from ast_stream_topology_set_stream." into 15 2017-11-07 21:50:52 -06:00
Corey Farrell
a7d21fec65 res_pjsip_pubsub: Fix multiple leaks on failure to append vectors.
Change-Id: I68ece0073ea79667ca41eb10405f516f1d30d482
2017-11-07 22:38:00 -05:00
Corey Farrell
a03f200358 res_pjsip_history: Fix multiple leaks on vector append failure.
Change-Id: I41e8d5183ace284095cc721f3b1fb32ade3f940f
2017-11-07 22:31:02 -05:00
Corey Farrell
31244fc277 res_pjsip_session: Fix multiple leaks.
* Pre-initialize cloned media state vectors to final size to ensure
  vector errors cannot happen later in the clone initialization.
* Release session_media on vector replace failure in
  ast_sip_session_media_state_add.
* Release clone and media_state in ast_sip_session_refresh if we fail to
  append to the stream topology, return an error.

Change-Id: Ib5ffc9b198683fa7e9bf166d74d30c1334c23acb
2017-11-07 22:26:34 -05:00
Jenkins2
43d450c58b Merge "res_pjsip_config_wizard: Fix leaks and add check for malloc failure." into 15 2017-11-07 19:22:02 -06:00
Joshua Colp
1f86ddeaa9 Merge "res_stasis_playback: Check for failure to append vector." into 15 2017-11-07 18:41:42 -06:00
Joshua Colp
33db2eefe5 Merge "CLI: Remove unused internal command." into 15 2017-11-07 18:31:46 -06:00
Jenkins2
410872b8ef Merge "test_sorcery_memory_cache_thrash: Handle error from vector append." into 15 2017-11-07 17:22:43 -06:00
Joshua Colp
d1d793d411 Merge "stasis: Release object if vector append fails." into 15 2017-11-07 16:37:15 -06:00
Joshua Colp
d253092064 Merge "Messaging: Report error on failure to register tech or handler." into 15 2017-11-07 16:05:56 -06:00
Joshua Colp
0553ee1b9e Merge "res_ari_events: Fix use after free / double-free of JSON message." into 15 2017-11-07 15:59:42 -06:00
Joshua Colp
afc53cbe1c Merge "PBX: Handle errors from AST_VECTOR_APPEND." into 15 2017-11-07 15:23:21 -06:00
Jenkins2
6cf44ee48e Merge "format_cap: Fix leak on AST_VECTOR_APPEND error." into 15 2017-11-07 14:09:15 -06:00
Richard Mudgett
de656d8c66 res_pjsip_registrar.c: Fix AOR and pjproject group deadlock.
One of the patches for ASTERISK_27147 introduced a deadlock regression.
When the connection oriented transport shut down, the code attempted to
remove the associated contact.  However, that same transport had just
requested a registration that we hadn't responded to yet.  Depending
upon timing we could deadlock.

* Made send the REGISTER response after we completed processing the
request contacts and released the AOR lock to avoid the deadlock.

ASTERISK-27391

Change-Id: I89a90f87cb7a02facbafb44c75d8845f93417364
2017-11-07 13:01:15 -05:00
Joshua Colp
aa52a18e67 Merge "res_pjsip: Ignore empty TLS configuration" into 15 2017-11-07 11:51:05 -06:00
Corey Farrell
17136aacc0 res_pjsip_session: Check for errors from ast_stream_topology_set_stream.
Free memory and return error if ast_stream_topology_set_stream fails.

Change-Id: I9f4dbf44bed627243d2f1dd8aea2eab6c38a028d
2017-11-07 12:41:02 -05:00
Corey Farrell
dd73524bf6 res_pjsip_t38: Better error checking for t38_create_media_state.
Change-Id: I81b2587427c6982aa3e2a3f9ad69cce8d316eb10
2017-11-07 12:36:47 -05:00
Corey Farrell
9284ed1df1 stream: Return error from ast_stream_topology_set_stream.
ast_stream_topology_set_stream had suppressed error codes from
AST_VECTOR_APPEND.  The result of AST_VECTOR_APPEND needs to be returned
to the caller so they can take appropriate action on the stream.

Change-Id: I6c0d12755743eadba1357f6153526cc055592856
2017-11-07 11:28:58 -05:00
Corey Farrell
e876c47fac res_stasis: Fix multiple leaks.
* res/stasis/app.c JSON passed to app_send needs to be released.
* res/stasis_message.c: objects leak if vector append fails.

Change-Id: I8dd5385b9f50a5cadf2b1d16efecffd6ddb4db4a
2017-11-07 11:24:45 -05:00
Jenkins2
7fc3399d6d Merge "tcptls: Print notice when TLS is enabled but not configured." into 15 2017-11-07 09:45:22 -06:00
Aaron An
4c4772472e res_pjsip: Avoid crash when contact uri is empty string
Asterisk will crash if contact uri is invalid, so contact_apply_handler
should check if the uri is NULL or empty.

ASTERISK-27393 #close
Reported-by: Aaron An
Tested-by: AaronAn

Change-Id: Ia0309bdc6b697c73c9c736e1caec910b77ca69f5
2017-11-07 10:33:17 -05:00
Joshua Colp
cac4dd360d Merge "stasis: Remove silly use of RAII_VAR in stasis_forward_all." into 15 2017-11-07 09:13:30 -06:00
Jenkins2
cb589bc4f0 Merge "stasis_channels.c: Remove a very silly RAII_VAR()." into 15 2017-11-07 08:25:25 -06:00
Jenkins2
d39e97f4b3 Merge "stasis/app.c: Optimize stasis_app_get_debug_by_name()" into 15 2017-11-07 07:46:14 -06:00
Joshua Colp
7ccac5e088 Merge "Fix ast_(v)asprintf() malloc failure usage conditions." into 15 2017-11-07 07:14:15 -06:00
Richard Mudgett
abb77faae7 res_pjproject.c: Fix ast_strdup() alloc failure.
Change-Id: I74688038e7afe3a279359cce53aadb28ade51ead
2017-11-07 08:11:20 -05:00
Jenkins2
c25fd6c982 Merge "RTP Engine: Deal with errors returned from AST_VECTOR_REPLACE." into 15 2017-11-07 06:19:10 -06:00
Corey Farrell
0e147cbf9e res_pjsip_outbound_registration: Fix leak on vector add failure.
Change-Id: I774b88b3c9da41edd4dc8d78f095481f52f2bd46
2017-11-06 18:56:25 -05:00
Corey Farrell
032c657ee9 res_pjsip_exten_state: Check for vector append failure.
Release reference to publisher if we fail to add it to the vector.

Change-Id: I64dff3f481b67b9884f37cadba7a5ccf23d084f3
2017-11-06 18:52:03 -05:00
Corey Farrell
c88bacaa0d res_pjsip_config_wizard: Fix leaks and add check for malloc failure.
wizard_apply_handler():
- Free host if we fail to add it to the vector.

wizard_mapped_observer():
- Check for otw allocation failure.
- Free otw if we fail to add it to the vector.

Change-Id: Ib5d3bcabbd9c24dd8a3c9cc692a794a5f60243ad
2017-11-06 18:46:45 -05:00
Corey Farrell
a8d6d8b4c1 res_stasis_playback: Check for failure to append vector.
Free resources and return error if we fail to append the vector in
stasis_app_control_play_uri.

Change-Id: I22c4a90dd859b253f2850c6511de48b25609422b
2017-11-06 18:39:25 -05:00
Corey Farrell
4ca1cdfd49 test_sorcery_memory_cache_thrash: Handle error from vector append.
Cleanup resources when we fail to append the vector and report test
failure.

Change-Id: I6eb41586fd11dee8c0dfe35e91cb465a4cab7298
2017-11-06 18:35:19 -05:00
Corey Farrell
849d49d91c res_pjsip: Fix leak on error in ast_sip_auth_vector_init.
Change-Id: Ib0fc7a18f3135ca8990c3984c9e15f6d26e556e8
2017-11-06 18:31:43 -05:00
Corey Farrell
df6a2d3760 res_pjproject: Handle error from adding to the buildopts vector.
Change-Id: I076c7bd207c7989a23005395ce1735392657be65
2017-11-06 18:20:17 -05:00
Corey Farrell
67ac6812ee res_ari_events: Fix use after free / double-free of JSON message.
When stasis_app_message_handler needs to queue a message for a later
connection it needs to bump the message reference so it doesn't get
freed when the caller releases it's reference.

Change-Id: I82696df8fe723b3365c15c3f7089501da8daa892
2017-11-06 18:15:58 -05:00
Corey Farrell
595e60cc27 stasis: Release object if vector append fails.
Change-Id: I3e5cc669169aab6175ddfaf7486edeaeb4fdcfb1
2017-11-06 16:36:47 -05:00
Corey Farrell
ba3ef46847 RTP Engine: Deal with errors returned from AST_VECTOR_REPLACE.
Check for errors from AST_VECTOR_REPLACE and clean memory if needed.

Change-Id: I124d15cc1d645f85a72a1279f623c1993b304b0b
2017-11-06 16:22:54 -05:00
Corey Farrell
a85b762894 PBX: Handle errors from AST_VECTOR_APPEND.
This resolves potentials leaks on AST_VECTOR_APPEND error in:
* ast_context_add_include2
* ast_context_add_switch2
* ast_context_add_ignorepat2

Change-Id: Ib60e95c4f622fa3b832d87227c0523a695d736b6
2017-11-06 16:18:18 -05:00
Corey Farrell
66d7c8495a Messaging: Report error on failure to register tech or handler.
Message tech and handler registrations use a vector which could fail to
expand.  If it does log and error and return error.

Change-Id: I593a8de81a07fb0452e9b0efd5d4018b77bca6f4
2017-11-06 16:13:49 -05:00
Corey Farrell
c27df36f11 format_cap: Fix leak on AST_VECTOR_APPEND error.
format_cap_framed_init can fail on AST_VECTOR_APPEND.  This should
report failure to the caller and clean the newly allocated frame.

Change-Id: Ica0661235bf09497bf23d844ceb01f21b41a55b0
2017-11-06 16:12:05 -05:00