https://osmocom.org/https://osmocom.org/favicon.ico?16647414092017-10-04T14:03:49ZOpen Source Mobile Communicationslibosmocore - Bug #2533: CTRL interface: disallow various unvalidated inputhttps://osmocom.org/issues/2533?journal_id=55302017-10-04T14:03:49Zneelsnhofmeyr@sysmocom.de
<ul><li><strong>Description</strong> updated (<a title="View differences" href="/journals/5530/diff?detail_id=8552">diff</a>)</li></ul> libosmocore - Bug #2533: CTRL interface: disallow various unvalidated inputhttps://osmocom.org/issues/2533?journal_id=108642018-08-20T15:48:29Zneelsnhofmeyr@sysmocom.de
<ul><li><strong>Status</strong> changed from <i>New</i> to <i>Resolved</i></li></ul><p>various strictness was merged a long time ago</p>
<pre>
Author: Neels Hofmeyr <neels@hofmeyr.de>
AuthorDate: Tue Sep 26 14:21:44 2017 +0200
Commit: Harald Welte <laforge@gnumonks.org>
CommitDate: Wed Dec 20 15:50:24 2017 +0000
ctrl: tighten CTRL input parsing
Validate that incoming CTRL commands...
- have decimal IDs,
- return error on trailing characters,
- have invalid characters in variable identifiers,
- send detailed error messages as reply to the requestor.
Adjust ctrl_test.{c,ok}, which best show the change in behavior.
Message handling causes log messages on stderr; previously, stderr was empty.
Add '[ignore]' in testsuite.at so that the nonempty stderr doesn't cause test
failures.
Change-Id: I96a9b6b6a3a5e0b80513aa9eaa727ae8c9c7d7a1
</pre>
<p>and this issue here is too vague to make any sense, really.</p>