• src/sbbs3/smbutil.c

    From Rob Swindell (on Debian Linux)@VERT to Git commit to main/sbbs/master on Wed May 6 22:36:56 2026
    https://gitlab.synchro.net/main/sbbs/-/commit/1fbe29cb3c13f8878731477d
    Modified Files:
    src/sbbs3/smbutil.c
    Log Message:
    smbutil: free idxbuf and unlock smbhdr on terminated abort in maint() (CID 644892)

    Five 'if (terminated) return;' sites in maint() leaked idxbuf (heap)
    and left the SMB header lock held. The deletion-execution loop also
    left the SMB-allocation file handles open. Mirror the existing
    "nothing to delete" cleanup before each early return.

    Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

    ---
    þ Synchronet þ Vertrauen þ Home of Synchronet þ [vert/cvs/bbs].synchro.net
  • From Rob Swindell (on Debian Linux)@VERT to Git commit to main/sbbs/master on Wed May 6 22:36:57 2026
    https://gitlab.synchro.net/main/sbbs/-/commit/7506c7bf8670aeacf982f282
    Modified Files:
    src/sbbs3/smbutil.c
    Log Message:
    smbutil: free datoffset on fread early-return in packmsgs() (CID 462184)

    Three bare 'return;' statements after the smb-header-rewrite reads
    leaked datoffset (allocated just above for the per-msg offset map).
    Free it before returning. Other resources at these sites (tmp file
    handles, smb header lock) are pre-existing leaks that Coverity did
    not flag and are out of scope for this CID.

    Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>

    ---
    þ Synchronet þ Vertrauen þ Home of Synchronet þ [vert/cvs/bbs].synchro.net
  • From Rob Swindell (on Debian Linux)@VERT to Git commit to main/sbbs/master on Thu Sep 24 21:22:49 2026
    https://gitlab.synchro.net/main/sbbs/-/commit/893817954cb42bd437b8c796
    Modified Files:
    src/sbbs3/smbutil.c
    Log Message:
    smbutil pack: free the space of a message it drops

    When pack drops a message whose data it can't copy, or for which it can't allocate a header, the data space already allocated for it in the packed
    base was left allocated with nothing referencing it: blocks lost until the
    next pack. Both skip paths were added by aee485f478 (reducing-28-isle, 2026-09-15).

    Pack only appends to the new .sdt and .sda, so the dropped message's data
    is always the last allocation in each; pack_drop_dat() truncates both back
    to where it started. smb_freemsgdat() isn't usable mid-pack: it unlocks
    the SMB header pack holds, and it truncates smb.sdt_fp, which is the
    original data file being read.

    For data shared with an earlier index, the extra reference is now added
    only once the header is allocated, so a header failure leaves nothing to
    undo.

    Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>

    ---
    þ Synchronet þ Vertrauen þ Home of Synchronet þ [vert/cvs/bbs].synchro.net