Skip to content

Fix null-packet dereference in DTX sequence initialization - #2189

Open
vingarzan wants to merge 1 commit into
sipwise:masterfrom
vingarzan:fix/dtx-null-packet-sequence
Open

vingarzan wants to merge 1 commit into
sipwise:masterfrom
vingarzan:fix/dtx-null-packet-sequence

Conversation

@vingarzan

Copy link
Copy Markdown

Hey folks,

DTMF suppression can pass a null packet into __buffer_dtx() before the output RTP sequence is initialized. Dereferencing packet->p.seq then causes a segmentation fault.

This patch defers sequence initialization until the first real packet arrives, while preserving discard tracking.

The regression test reproduces the crash on unpatched master and verifies that suppressed audio stays silent and subsequent audio uses the correct sequence numbers. All 12 unit tests and 4,143 daemon assertions passed; existing extended DTX failures were unchanged from master.

Cheers!

Copilot AI balanced review requested due to automatic review settings October 3, 2026 12:22

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

CN-based synthetic DTX can transmit from sequence zero before the first real packet resets the sequence.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Fixes a null dereference during DTX sequence initialization and adds regression coverage.

Changes:

  • Initializes output sequencing only from non-null packets.
  • Adds and registers a DTX/DTMF regression test.
File Description
daemon/​codec.c Guards sequence initialization against null packets.
t/​auto-daemon-tests-dtx-dtmf.pl Tests suppressed DTMF before initial audio.
t/​Makefile Registers the new daemon test.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread daemon/codec.c

if (!mp->ssrc_out->seq_set) {
// Discard entries have no packet; initialize sequencing with the first real packet.
if (packet && !mp->ssrc_out->seq_set) {
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants