open
https://gitlab.synchro.net/main/sbbs/-/work_items/1273
## Summary
SyncTERM segfaults when adding the first entry under **Settings → Web Lists** when `settings.webgets` is initially `NULL`.
I reproduced the crash on Linux x86_64 from current source and traced it with GDB to `fn_Menu_webLists()` in `src/syncterm/wren_bind_menu_settings.c`.
## Environment
- Linux x86_64
- SyncTERM built from current source
- Debug build
- Wayland / Hyprland
- OpenSSL 3 backend
- No existing SyncTERM configuration files were present when initially reproduced
## Steps to Reproduce
1. Start SyncTERM with no existing Web Lists.
2. Open **Settings → Web Lists**.
3. Add the first Web List, for example:
**Name:** `SyncTERM BBS List`
**URL:** `
http://syncterm.bbsdev.net/syncterm.lst`
4. SyncTERM segfaults when the Web Lists menu refreshes.
## GDB Findings
The crash occurs in `fn_Menu_webLists()`:
```text id="a8qyr2"
wren_bind_menu_settings.c:1477
wrenSetSlotString(vm, 2, settings.webgets[i]->name);
```
At the time of the crash:
```text id="02em0s"
i = 1
```
GDB showed that the first entry was valid:
```text id="z06fmb"
settings.webgets[0]->name
"SyncTERM BBS List"
settings.webgets[0]->value
"
http://syncterm.bbsdev.net/syncterm.lst"
```
However, `settings.webgets[1]` contained an invalid/garbage pointer. Attempting to access:
```text id="qljnvk"
settings.webgets[1]->name
```
failed because the pointer was invalid.
## Root Cause
`web_list_count()` expects `settings.webgets` to be a NULL-terminated array.
During the first Web List insertion:
```text id="a46c3w"
settings.webgets == NULL
count == 0
index == 0
```
The insertion code allocates:
```c id="e78lxv"
named_string_t **items = realloc(settings.webgets,
(count + 2) * sizeof(*items));
```
The existing code then performs:
```c id="v5vk2g"
settings.webgets = items;
memmove(&items[index + 1], &items[index],
(count - index + 1) * sizeof(*items));
items[index] = entry;
```
For the first insertion, `realloc(NULL, ...)` creates new uninitialized storage.
The subsequent `memmove()` effectively copies the uninitialized `items[0]` value into `items[1]`.
`items[0]` is then replaced with the valid new entry, but `items[1]` remains an invalid pointer instead of the NULL terminator expected by `web_list_count()`.
When the Web Lists menu refreshes, `web_list_count()` walks into this invalid second pointer, which is eventually dereferenced and causes the segfault.
## Fix
Initializing the NULL terminator before the existing `memmove()` fixes the problem:
```diff id="nc2kqk"
settings.webgets = items;
+ items[count] = NULL;
memmove(&items[index + 1], &items[index],
(count - index + 1) * sizeof(*items));
items[index] = entry;
```
This preserves the existing insertion logic while ensuring the array has a valid NULL terminator before it is moved.
## Testing
I rebuilt SyncTERM with the one-line change above and tested it on the same system that reproduced the crash.
Results:
- Adding the first Web List succeeds without a segfault.
- Adding a second Web List succeeds.
- The Web Lists menu continues operating normally.
- The patched SyncTERM binary operates normally after installation.
The crash was reproduced under GDB, the invalid second pointer was confirmed directly, and the minimal one-line fix was rebuilt and successfully tested.
--- SBBSecho 3.38-Linux
* Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)