java-topology/defects/vlc/SCAN.md
russell@unturf.com fb090af082 vlc+kodi: 5-MOAD scan; vlc-0003 CWE-312 SMB credentials logged verbatim
vlc-0003: modules/access/dsm/access.c:585 logs psz_login + psz_domain
via msg_Warn() on every successful SMB1 login. VLC debug logs are
routinely shared in bug reports, exposing SMB usernames and domain
names. Fix: remove our credential log line. 6/6 unit tests PASS.

VLC MOADs 0002/0003/0005 CLEAN. Kodi all 5 MOADs CLEAN (CWE-407
previously noted; CServiceBroker + LanguageHookTls documented as
architectural debt, no patch warranted).
2026-03-31 21:10:43 -04:00

1.9 KiB

VLC 5-MOAD Scan — 2026-03-31

Target: https://github.com/videolan/vlc (depth=1)

MOAD-0001 (CWE-407) — 2 DEFECTS FOUND (prior sessions)

See vlc-0001 (modules/bank.c module find + randomizer_Remove O(N*C)) and vlc-0002 (src/input/subtitles.c subtitle dedup O(I^2)).

MOAD-0002 (Intertangle) — CLEAN

VLC uses a vlc_object_t hierarchy as our object model, which is a known coupling point, but each subsystem (audio out, video out, input, playlist, sout) has its own thread and private struct. No hidden god object couples independent subsystems through shared mutable state beyond the intentional parent/child object tree.

MOAD-0003 (Leaked Context) — CLEAN (by design)

src/misc/interrupt.c uses thread_local vlc_interrupt_t *vlc_interrupt_var to carry per-input-task interrupt context. This is save/restore with vlc_interrupt_set() — callers save old context, set new one, restore on return. It is thread-scoped, not leaked across requests. The pattern is correct: each input thread owns its interrupt context for its lifetime. Not a MOAD-0003 defect.

MOAD-0004 (CWE-312) — 1 DEFECT FOUND

See vlc-0003: modules/access/dsm/access.c:585 logs SMB username + domain verbatim via msg_Warn() on every successful SMB1 login.

Additional log calls reviewed:

  • http.c:257 logs psz_username (not password) — username in URL is low severity.
  • http.c:927-945 logs WWW-Authenticate and Authentication-Info headers from server (challenge data, not credentials) — CLEAN.
  • live555.cpp:718 logs "retrying with user=%s" username only — low severity.
  • ftp.c:518-556 logs "password needed/accepted/rejected" without values — CLEAN.

MOAD-0005 (Thundering Herd) — CLEAN

Module bank (src/modules/bank.c) uses vlc_mutex_lock/unlock consistently around module list access. Access cache uses mutex-protected entry lookup. No unguarded get+null+set pattern found in hot paths.