security: add per-client pending sample limit in PulseAudio protocol

There was no limit on concurrent PLAY_SAMPLE operations per client.
Each creates a PipeWire stream, allowing a client to exhaust server
resources. Add a MAX_PENDING_SAMPLES (64) limit per client.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
Wim Taymans 2026-04-29 17:19:08 +02:00
parent 138e30df38
commit 807b93fb05
3 changed files with 11 additions and 1 deletions

View file

@ -43,6 +43,7 @@
#define MAX_CLIENTS 64u
#define MAX_STREAMS 64u
#define MAX_OPERATIONS 64u
#define MAX_PENDING_SAMPLES 64u
#define MODULE_INDEX_MASK 0xfffffffu
#define MODULE_FLAG (1u << 29)