nano_attachment: fix crash when the configuration is loaded - #73
Open
jclab-joseph wants to merge 1 commit into
Open
nano_attachment: fix crash when the configuration is loaded#73jclab-joseph wants to merge 1 commit into
jclab-joseph wants to merge 1 commit into
Conversation
A stray comma between two adjacent string literals ended the configuration
log's format string one part early, so "async mode: %u" was passed as the first
variadic argument instead of being concatenated onto the format. That shifted
every argument by one: the %s for the failure mode received the debug level
instead, and printf dereferenced that integer as a pointer.
The attachment died of SIGSEGV inside vsnprintf as soon as the agent connected
and configuration first loaded, so it never finished registering. With the
debug level at 2, the pointer it walked was 0x2:
openappsec#1 strnlen (s=0x2 <error: Cannot access memory at address 0x2>)
openappsec#2 printf_core (fmt="Successfully loaded configuration. inspection mode: ...")
openappsec#5 write_dbg_impl
openappsec#6 init_attachment_config
openappsec#8 InitNanoAttachment
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
jclab-joseph
force-pushed
the
fix/write-dbg
branch
from
August 18, 2026 13:39
f83e98e to
0ac7f33
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A stray comma between two adjacent string literals ended the configuration log's format string one part early, so "async mode: %u" was passed as the first variadic argument instead of being concatenated onto the format. That shifted every argument by one: the %s for the failure mode received the debug level instead, and printf dereferenced that integer as a pointer.
The attachment died of SIGSEGV inside vsnprintf as soon as the agent connected and configuration first loaded, so it never finished registering. With the debug level at 2, the pointer it walked was 0x2: