From f0d77360766e7d8fe8ad1d911acd3b6d369dd24b Mon Sep 17 00:00:00 2001 From: Aditya Patwardhan Date: Mon, 29 Jun 2026 13:49:38 +0530 Subject: [PATCH] fix(protocomm): roll back transport endpoint on alloc failure In protocomm_add_endpoint_internal(), the transport-specific endpoint is registered via pc->add_endpoint() before the protocomm_ep_t bookkeeping node is allocated. If that calloc() fails, the function returned ESP_ERR_NO_MEM without unregistering the transport endpoint, leaking a URI/handler registration that has no matching protocomm endpoint and can never be removed via protocomm_remove_endpoint(). Unregister the transport endpoint on the allocation-failure path. Closes SEC-582 --- components/protocomm/src/common/protocomm.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/components/protocomm/src/common/protocomm.c b/components/protocomm/src/common/protocomm.c index 824d59f0a7f..a92607e7938 100644 --- a/components/protocomm/src/common/protocomm.c +++ b/components/protocomm/src/common/protocomm.c @@ -99,6 +99,9 @@ static esp_err_t protocomm_add_endpoint_internal(protocomm_t *pc, const char *ep ep = (protocomm_ep_t *) calloc(1, sizeof(protocomm_ep_t)); if (!ep) { ESP_LOGE(TAG, "Error allocating endpoint resource"); + if (pc->remove_endpoint) { + pc->remove_endpoint(ep_name); + } return ESP_ERR_NO_MEM; }