Conversation
…a config save HwTools::setup() runs after every web UI save that does not require a restart, and it clears tempSensorInit. The next updateTemperatures() then enters the init branch again with sensorCount still set from the previous run: it deletes the tempSensors array and immediately searches it for matching addresses, dereferencing freed memory. On ESP8266 this shows up as an exception 28 (LoadProhibited) in isSensorAddressEqual() on the first temperature read after saving, e.g. changing MQTT settings on a device with a DS18B20 attached. Keep the old array alive while matching, move surviving entries into the new array, and free the rest. Also use delete[] for the array.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
HwTools::setup()runs after every web UI save that does not require a restart (seeAmsWebServer::handleSave), and it clearstempSensorInit. The nextupdateTemperatures()therefore enters the init branch again whilesensorCountis still set from the previous run. That branch deleted thetempSensorsarray and then searched it for matching addresses, dereferencing freed memory.On ESP8266 this reproduces as an exception 28 (LoadProhibited) in
isSensorAddressEqual()on the first temperature read after saving, for example after changing MQTT settings on a device with a DS18B20 attached. Stack from the crash:Fix
Keep the old array alive while matching addresses, move surviving entries into the new array, free entries for sensors that are gone, and use
delete[]for the array.Tested
ESP8266 (D1 mini), one DS18B20 on GPIO14, v2.5.7 and current main. Saving MQTT settings crashed the device every time before; after the fix the save completes and the sensor keeps reporting.