Skip to content

Fix double-free crash in socket_client_task on disconnect - #75

Open
MichaelEFlip wants to merge 1 commit into
nebkat:masterfrom
MichaelEFlip:fix-socket-double-free
Open

MichaelEFlip wants to merge 1 commit into
nebkat:masterfrom
MichaelEFlip:fix-socket-double-free

Conversation

@MichaelEFlip

Copy link
Copy Markdown

When the socket client successfully connects, connect_message is freed at line 93. On subsequent disconnection, execution falls through to the _error label which calls free(connect_message) again. This corrupts the heap allocator (TLSF), triggering an assertion failure: "!block_is_free(block) && block already marked as free" causing a panic reboot.

The crash was confirmed via core dump analysis (task: socket_client_t, heap_tlsf.c:866) and reproduced by stopping the remote TCP endpoint — the device crashed on every disconnect/reconnect cycle.
Fix: set connect_message = NULL after the first free, making the second free(NULL) a safe no-op.

When the socket client successfully connects, connect_message is freed at line 93. On subsequent disconnection, execution falls through to the _error label which calls free(connect_message) again. This corrupts the heap allocator (TLSF), triggering an assertion failure: "!block_is_free(block) && block already marked as free" causing a panic reboot.

The crash was confirmed via core dump analysis (task: socket_client_t, heap_tlsf.c:866) and reproduced by stopping the remote TCP endpoint — the device crashed on every disconnect/reconnect cycle.
Fix: set connect_message = NULL after the first free, making the second free(NULL) a safe no-op.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant