Files
ppsspp/Common
Henrik RydgårdandClaude Sonnet 5 37cea65e0e WebsocketServer: cap message size, avoid UB on empty-vector payloads
ReadFrame() accepted a 64-bit client-supplied payload length with only
a top-bit check, and ReadPending() immediately resized a buffer by it
before any data had arrived - a single frame claiming a huge length
(reachable via the WebSocket debugger endpoint) could trigger a
multi-exabyte allocation attempt. Now rejected up front (both the
single frame and the fragmented-message total) against a 64MB cap.

Also replaced &payload[0]/&vector[0] with .data() in the send/receive
paths - operator[] on a possibly-empty vector (e.g. an empty PING) is
UB even when the result is never dereferenced.

Co-Authored-By: Claude Sonnet 5 <[email protected]>
Claude-Session: https://claude.ai/code/session_01L4QAoxV2KY7ek4PcZw3WvY
2026-08-10 11:26:24 +02:00
..
2026-08-10 04:59:55 -04:00
…
…
…
2026-01-30 14:10:32 +01:00
2026-03-30 11:34:19 -06:00
2026-07-30 10:03:15 +02:00
2026-07-29 14:42:24 +02:00
2026-06-02 17:16:45 +02:00
…
2026-05-16 10:40:08 +02:00
…
…
2026-07-27 21:33:14 +02:00
2026-07-27 18:37:28 +02:00