Skip to content

negotiate_sspi_auth: Fix crash in FormatMessage() (#2510) - #2513

Open
squidadm wants to merge 1 commit into
squid-cache:v7from
squidadm:v7-backport-pr2510
Open

squidadm wants to merge 1 commit into
squid-cache:v7from
squidadm:v7-backport-pr2510

Conversation

@squidadm

@squidadm squidadm commented Oct 2, 2026

Copy link
Copy Markdown
Collaborator

When FormatMessage() fails, negotiate_sspi_auth reports the failure
with

SEND2("NA * Windows error: %s", GetLastError());

GetLastError() returns a DWORD, so %s makes printf() -- and debug(),
through SEND2 -- treat the error number as a pointer and read from
it. The helper crashes on this path instead of answering Squid with
NA.

By then GetLastError() no longer holds the error being reported
either: FormatMessage() has replaced it with its own failure code,
ERROR_MR_MID_NOT_FOUND (317). Save the error before calling
FormatMessage(), and report that saved code when Windows has no
message text for it. When text is available, the existing path
still sends it.

Print the number with %lu and cast it to unsigned long. DWORD is
unsigned int on Cygwin, where the SSPI helpers are built, and
unsigned long on MinGW, so no single conversion without a cast fits
both. src/windows_service.cc prints GetLastError() the same way, to
keep the two in sync.

Found building 7.7 on Cygwin, where GCC 14 warns: format '%s' expects
argument of type 'char*', but argument 2 has type 'DWORD'. With this
change the file compiles with no format warnings under -Wall -Wextra
-Wformat=2 on Cygwin, and windows_service.cc's line compiles without
format warnings on MinGW GCC 16 even with -Wformat-signedness.

When FormatMessage() fails, negotiate_sspi_auth reports the failure
with

    SEND2("NA * Windows error: %s", GetLastError());

GetLastError() returns a DWORD, so %s makes printf() -- and debug(),
through SEND2 -- treat the error number as a pointer and read from
it. The helper crashes on this path instead of answering Squid with
NA.

By then GetLastError() no longer holds the error being reported
either: FormatMessage() has replaced it with its own failure code,
ERROR_MR_MID_NOT_FOUND (317). Save the error before calling
FormatMessage(), and report that saved code when Windows has no
message text for it. When text is available, the existing path
still sends it.

Print the number with %lu and cast it to unsigned long. DWORD is
unsigned int on Cygwin, where the SSPI helpers are built, and
unsigned long on MinGW, so no single conversion without a cast fits
both. src/windows_service.cc prints GetLastError() the same way, to
keep the two in sync.

Found building 7.7 on Cygwin, where GCC 14 warns: format '%s' expects
argument of type 'char*', but argument 2 has type 'DWORD'. With this
change the file compiles with no format warnings under -Wall -Wextra
-Wformat=2 on Cygwin, and windows_service.cc's line compiles without
format warnings on MinGW GCC 16 even with -Wformat-signedness.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants