fix 5.2 audit findings on Windows: F-PROC-1 injection, F-MEM-5 UAF, F-PROC-2 restart race, F-PROC-3, F5, F6

This commit is contained in:
2026-08-16 12:29:42 +07:00
parent 54b7a7a6ac
commit 761b48e41f
9 changed files with 134 additions and 69 deletions
+25 -3
View File
@@ -7,6 +7,24 @@
#include <iostream>
#include <vector>
// F-PROC-1 (audit 5.2): Windows CRT command-line parsing escape for an
// argument inside double quotes. A path containing a double quote would
// otherwise break out of --path "..." and inject arbitrary argv (e.g.
// `" && calc`). Metacharacters (& | > <) are inert here: CreateProcessA
// does not run a shell.
static std::string quote_arg(const std::string& s) {
std::string out = "\"";
size_t bs = 0;
for (char c : s) {
if (c == '\\') { ++bs; continue; }
if (c == '"') { out.append(bs * 2 + 1, '\\'); out += '"'; bs = 0; }
else { out.append(bs, '\\'); out += c; bs = 0; }
}
out.append(bs * 2, '\\');
out += '"';
return out;
}
static bool proc_alive(HANDLE h) {
#ifdef _WIN32
if (!h) return false;
@@ -72,8 +90,12 @@ bool SandboxVst3Host::spawnChild() {
std::string hostExe = (slash == std::string::npos)
? "plugin_host.exe"
: dir.substr(0, slash + 1) + "plugin_host.exe";
std::string cmd = "\"" + hostExe + "\" --open --shm " + shmName_ +
" --path \"" + path_ + "\" --sr " + std::to_string((int)sampleRate_) +
// F-PROC-1: lpApplicationName = hostExe (exe path is never parsed as
// command line), and the VST path goes through quote_arg so a hostile
// path cannot inject extra arguments.
std::string cmd = "--open --shm " + shmName_ +
" --path " + quote_arg(path_) +
" --sr " + std::to_string((int)sampleRate_) +
" --block " + std::to_string(block_) +
" --parent " + std::to_string((unsigned long)GetCurrentProcessId());
std::cerr << "[SandboxVst3Host] spawn ch=" << channel_ << " " << cmd << std::endl;
@@ -83,7 +105,7 @@ bool SandboxVst3Host::spawnChild() {
PROCESS_INFORMATION pi = {};
std::vector<char> buf(cmd.begin(), cmd.end());
buf.push_back('\0');
if (!CreateProcessA(nullptr, buf.data(), nullptr, nullptr, FALSE,
if (!CreateProcessA(hostExe.c_str(), buf.data(), nullptr, nullptr, FALSE,
CREATE_NO_WINDOW, nullptr, nullptr, &si, &pi)) {
std::cerr << "[SandboxVst3Host] CreateProcessA failed err=" << (int)GetLastError()
<< " ch=" << channel_ << std::endl;