esp-idf icon indicating copy to clipboard operation
esp-idf copied to clipboard

Fix off-by-one/memory corruption in transport_ws (IDFGH-13767)

Open Sean-Der opened this issue 1 year ago • 1 comments

Read doesn't take NULL terminator into account

Resolves #14473

Description

Off-by-one caught by Valgrind

==5505== Invalid write of size 1
==5505==    at 0x1248BB: ws_connect (transport_ws.c:294)
==5505==    by 0x12293E: esp_transport_connect (transport.c:123)
==5505==    by 0x11F3D6: esp_websocket_client_task (esp_websocket_client.c:990)
==5505==    by 0x13581F: pthread_task (freertos_linux.c:210)
==5505==    by 0x4BBDA93: start_thread (pthread_create.c:447)
==5505==    by 0x4C4AA33: clone (clone.S:100)
==5505==  Address 0x4e45240 is 0 bytes after a block of size 1,024 alloc'd
==5505==    at 0x4846828: malloc (in /usr/libexec/valgrind/vgpreload_memcheck-amd64-linux.so)
==5505==    by 0x124DE5: esp_transport_ws_init (transport_ws.c:726)
==5505==    by 0x12001C: esp_websocket_client_create_transport (esp_websocket_client.c:492)
==5505==    by 0x1210E3: esp_websocket_client_start (esp_websocket_client.c:1132)
==5505==    by 0x119503: app_websocket() (websocket.cpp:201)
==5505==    by 0x11880B: main (main.cpp:27)

Related

Testing

Running with Valgrind results in no errors.


Checklist

Before submitting a Pull Request, please ensure the following:

  • [x] 🚨 This PR does not introduce breaking changes.
  • [x] All CI checks (GH Actions) pass.
  • [x] Documentation is updated as needed.
  • [x] Tests are updated or added as necessary.
  • [x] Code is well-commented, especially in complex areas.
  • [x] Git history is clean — commits are squashed to the minimum necessary.

Sean-Der avatar Sep 24 '24 14:09 Sean-Der

Warnings
:warning:

Some issues found for the commit messages in this PR:

  • the commit message "Fix off-by-one/memory corruption in transport_ws":
    • summary looks empty
    • type/action looks empty

Please fix these commit messages - here are some basic tips:

  • follow Conventional Commits style
  • correct format of commit message should be: <type/action>(<scope/component>): <summary>, for example fix(esp32): Fixed startup timeout issue
  • allowed types are: change,ci,docs,feat,fix,refactor,remove,revert,test
  • sufficiently descriptive message summary should be between 20 to 72 characters and start with upper case letter
  • avoid Jira references in commit messages (unavailable/irrelevant for our customers)

TIP: Install pre-commit hooks and run this check when committing (uses the Conventional Precommit Linter).

👋 Hello Sean-Der, we appreciate your contribution to this project!


📘 Please review the project's Contributions Guide for key guidelines on code, documentation, testing, and more.

🖊️ Please also make sure you have read and signed the Contributor License Agreement for this project.

Click to see more instructions ...


This automated output is generated by the PR linter DangerJS, which checks if your Pull Request meets the project's requirements and helps you fix potential issues.

DangerJS is triggered with each push event to a Pull Request and modify the contents of this comment.

Please consider the following:
- Danger mainly focuses on the PR structure and formatting and can't understand the meaning behind your code or changes.
- Danger is not a substitute for human code reviews; it's still important to request a code review from your colleagues.
- Resolve all warnings (⚠️ ) before requesting a review from human reviewers - they will appreciate it.
- To manually retry these Danger checks, please navigate to the Actions tab and re-run last Danger workflow.

Review and merge process you can expect ...


We do welcome contributions in the form of bug reports, feature requests and pull requests via this public GitHub repository.

This GitHub project is public mirror of our internal git repository

1. An internal issue has been created for the PR, we assign it to the relevant engineer.
2. They review the PR and either approve it or ask you for changes or clarifications.
3. Once the GitHub PR is approved, we synchronize it into our internal git repository.
4. In the internal git repository we do the final review, collect approvals from core owners and make sure all the automated tests are passing.
- At this point we may do some adjustments to the proposed change, or extend it by adding tests or documentation.
5. If the change is approved and passes the tests it is merged into the default branch.
5. On next sync from the internal git repository merged change will appear in this public GitHub repository.

Generated by :no_entry_sign: dangerJS against 7d397983b0fee4412bfb1b0bd4416d25e3f89c23

github-actions[bot] avatar Sep 24 '24 14:09 github-actions[bot]

I think this already been fixed by https://github.com/espressif/esp-idf/commit/53e63eb1251c26d748d3fcbe910c762b595f3943

bryghtlabs-richard avatar Dec 06 '24 17:12 bryghtlabs-richard

Great news!

Sean-Der avatar Dec 06 '24 19:12 Sean-Der