• SyncTERM: Segfault when adding first Web List due to missing NULL term

    From Jerry Reed@1:103/705 to GitLab issue in main/sbbs on Wed Sep 30 08:58:24 2026
    open https://gitlab.synchro.net/main/sbbs/-/work_items/1273

    ## Summary

    SyncTERM segfaults when adding the first entry under **Settings → Web Lists** when `settings.webgets` is initially `NULL`.

    I reproduced the crash on Linux x86_64 from current source and traced it with GDB to `fn_Menu_webLists()` in `src/syncterm/wren_bind_menu_settings.c`.

    ## Environment

    - Linux x86_64
    - SyncTERM built from current source
    - Debug build
    - Wayland / Hyprland
    - OpenSSL 3 backend
    - No existing SyncTERM configuration files were present when initially reproduced

    ## Steps to Reproduce

    1. Start SyncTERM with no existing Web Lists.
    2. Open **Settings → Web Lists**.
    3. Add the first Web List, for example:

    **Name:** `SyncTERM BBS List`
    **URL:** `http://syncterm.bbsdev.net/syncterm.lst`

    4. SyncTERM segfaults when the Web Lists menu refreshes.

    ## GDB Findings

    The crash occurs in `fn_Menu_webLists()`:

    ```text id="a8qyr2"
    wren_bind_menu_settings.c:1477

    wrenSetSlotString(vm, 2, settings.webgets[i]->name);
    ```

    At the time of the crash:

    ```text id="02em0s"
    i = 1
    ```

    GDB showed that the first entry was valid:

    ```text id="z06fmb"
    settings.webgets[0]->name
    "SyncTERM BBS List"

    settings.webgets[0]->value
    "http://syncterm.bbsdev.net/syncterm.lst"
    ```

    However, `settings.webgets[1]` contained an invalid/garbage pointer. Attempting to access:

    ```text id="qljnvk"
    settings.webgets[1]->name
    ```

    failed because the pointer was invalid.

    ## Root Cause

    `web_list_count()` expects `settings.webgets` to be a NULL-terminated array.

    During the first Web List insertion:

    ```text id="a46c3w"
    settings.webgets == NULL
    count == 0
    index == 0
    ```

    The insertion code allocates:

    ```c id="e78lxv"
    named_string_t **items = realloc(settings.webgets,
    (count + 2) * sizeof(*items));
    ```

    The existing code then performs:

    ```c id="v5vk2g"
    settings.webgets = items;

    memmove(&items[index + 1], &items[index],
    (count - index + 1) * sizeof(*items));

    items[index] = entry;
    ```

    For the first insertion, `realloc(NULL, ...)` creates new uninitialized storage.

    The subsequent `memmove()` effectively copies the uninitialized `items[0]` value into `items[1]`.

    `items[0]` is then replaced with the valid new entry, but `items[1]` remains an invalid pointer instead of the NULL terminator expected by `web_list_count()`.

    When the Web Lists menu refreshes, `web_list_count()` walks into this invalid second pointer, which is eventually dereferenced and causes the segfault.

    ## Fix

    Initializing the NULL terminator before the existing `memmove()` fixes the problem:

    ```diff id="nc2kqk"
    settings.webgets = items;
    + items[count] = NULL;
    memmove(&items[index + 1], &items[index],
    (count - index + 1) * sizeof(*items));
    items[index] = entry;
    ```

    This preserves the existing insertion logic while ensuring the array has a valid NULL terminator before it is moved.

    ## Testing

    I rebuilt SyncTERM with the one-line change above and tested it on the same system that reproduced the crash.

    Results:

    - Adding the first Web List succeeds without a segfault.
    - Adding a second Web List succeeds.
    - The Web Lists menu continues operating normally.
    - The patched SyncTERM binary operates normally after installation.

    The crash was reproduced under GDB, the invalid second pointer was confirmed directly, and the minimal one-line fix was rebuilt and successfully tested.
    --- SBBSecho 3.38-Linux
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Rob Swindell@1:103/705 to GitLab note in main/sbbs on Wed Sep 30 13:39:48 2026
    https://gitlab.synchro.net/main/sbbs/-/work_items/1273#note_10536

    The correct place to file bug reports against SyncTERM is: https://sourceforge.net/p/syncterm/tickets/
    --- SBBSecho 3.38-Linux
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)