]> dgit.raspbian.org Git - dovecot.git/commitdiff
[PATCH 2/2] login-common: Avoid array_front() panic on empty forward_fields array
authorTimo Sirainen <timo.sirainen@open-xchange.com>
Sun, 3 May 2026 16:24:38 +0000 (16:24 +0000)
committerNoah Meyerhans <noahm@debian.org>
Wed, 16 Sep 2026 19:06:35 +0000 (15:06 -0400)
sasl_server_auth_request_info_fill() and proxy_redirect_reauth()
NUL-terminate the forward_fields array via array_append_zero() +
array_pop_back() and then call array_front() to hand the C array to
the auth client. array_front() asserts when the array is empty, so a
created-but-empty forward_fields array crashes login.

The empty-array case is no longer reachable from
client_forward_decode_base64() after the previous commit, but guard
defensively here as well: any future caller that creates the array
without populating it should not be able to panic the process.

Gbp-Pq: Name 0002-login-common-Avoid-array_front-panic-on-empty-forwar.patch

src/login-common/client-common-auth.c
src/login-common/sasl-server.c

index 0b226497c60a1fd92e29676ac43c9e4be0324de9..36ed7211a76804ccfb7827d04693e39972d873c6 100644 (file)
@@ -490,7 +490,7 @@ proxy_redirect_reauth(struct client *client, const char *destuser,
        t_array_init(&info.extra_fields, N_ELEMENTS(extra_fields));
        array_append(&info.extra_fields, extra_fields,
                     N_ELEMENTS(extra_fields));
-       if (array_is_created(&client->forward_fields)) {
+       if (array_not_empty(&client->forward_fields)) {
                array_append_zero(&client->forward_fields);
                array_pop_back(&client->forward_fields);
                info.forward_fields = array_front(&client->forward_fields);
index f02262c00f78b95299e90c940808d42e72b206dc..88d46e7c6898d754b4824a1267031c25a212fe61 100644 (file)
@@ -534,7 +534,7 @@ int sasl_server_auth_request_info_fill(struct client *client,
        info_r->real_remote_port = client->real_remote_port;
        if (client->client_id != NULL)
                info_r->client_id = str_c(client->client_id);
-       if (array_is_created(&client->forward_fields)) {
+       if (array_not_empty(&client->forward_fields)) {
                array_append_zero(&client->forward_fields);
                array_pop_back(&client->forward_fields);
                info_r->forward_fields = array_front(&client->forward_fields);