Code quality: Address Copilot review comments

All accesses to g_drdynvcs[] in chansrv.c have been checked for
unbounded access.
This commit is contained in:
matt335672
2026-08-13 11:37:11 +01:00
parent f4249b3ca6
commit a6d80e17ab
5 changed files with 17 additions and 13 deletions
+1 -1
View File
@@ -439,7 +439,7 @@ dyn_dechunker_process_first_chunk(struct dyn_dechunker *self,
}
else if (frag_size == total_size)
{
// This chunk ccontains all the data
// This chunk contains all the data
status = E_DYN_INLINE_CHUNK;
}
else
+1 -1
View File
@@ -50,7 +50,7 @@ enum vc_dechunker_status
};
/**
* Returned from dyn_dechunker_process_chunk() and
* Returned from dyn_dechunker_process_data_chunk() and
* Returned from dyn_dechunker_process_first_chunk()
*/
enum dyn_dechunker_status
+9 -5
View File
@@ -83,7 +83,6 @@ tbus g_exec_mutex;
tbus g_exec_sem;
int g_exec_pid = 0;
#define ARRAYSIZE(x) (sizeof(x)/sizeof(*(x)))
/* max total channel bytes size */
#define MAX_CHANNEL_BYTES (1 * 1024 * 1024 * 1024) /* 1 GB */
#define MAX_CHANNEL_FRAG_BYTES 1600
@@ -724,7 +723,7 @@ static int
process_message_drdynvc_data(struct stream *s)
{
struct chansrv_drdynvc *drdynvc;
int chan_id;
uint32_t chan_id;
struct stream *ls = NULL; // Set if the application to be called
int free_ls = 0; // Set if we need to clear ls when we're done
int rv = 0;
@@ -890,6 +889,10 @@ chansrv_drdynvc_close(int chan_id)
struct stream *s;
int error;
if (chan_id < 0 || chan_id >= DRDYNVC_CHANNEL_COUNT)
{
return 1;
}
s = trans_get_out_s(g_con_trans, 8192);
if (s == NULL)
{
@@ -1179,9 +1182,10 @@ my_trans_data_in(struct trans *trans)
/*****************************************************************************/
static struct trans *
get_api_trans_from_chan_id(int chan_id)
get_api_trans_from_chan_id(uint32_t chan_id)
{
return g_drdynvcs[chan_id].xrdp_api_trans;
return (chan_id >= DRDYNVC_CHANNEL_COUNT)
? NULL : g_drdynvcs[chan_id].xrdp_api_trans;
}
/*****************************************************************************/
@@ -1605,7 +1609,7 @@ api_con_trans_list_check_wait_objs(void)
chansrv_drdynvc_close(ad->chan_id);
}
for (drdynvc_index = 0;
drdynvc_index < (int) ARRAYSIZE(g_drdynvcs);
drdynvc_index < DRDYNVC_CHANNEL_COUNT;
drdynvc_index++)
{
if (g_drdynvcs[drdynvc_index].xrdp_api_trans == ltran)
+5 -5
View File
@@ -152,7 +152,7 @@ static const char frankenstein[] =
// The dynamic dechunker works on total data block sizes of 1600 bytes,
// including the block header as well.
// The FIRST block header is 6-12 bytes long, and the DATA block header
// is 5-8 bytes long. For simplicity we're assume a header size of 8
// is 5-8 bytes long. For simplicity we assume a header size of 8
// bytes, and hence a data size of 1592 bytes.
#define FRANKENSTEIN_DYN_CHUNK_SIZE 1592
@@ -202,10 +202,10 @@ START_TEST(test_vc_dechunker_bad_params)
ck_assert_ptr_ne(dc, NULL);
// vc_dechunker_free
vc_dechunker_free(NULL); // Musn't crash!
vc_dechunker_free(NULL); // Must not crash!
// vc_dechunker_get_stream
vc_dechunker_get_stream(NULL); // Musn't crash!
vc_dechunker_get_stream(NULL); // Must not crash!
// vc_dechunker_process_chunk
stat = vc_dechunker_process_chunk(NULL, s, 0, 1600); // No dechunker
@@ -629,10 +629,10 @@ START_TEST(test_dyn_dechunker_bad_params)
ck_assert_ptr_ne(dc, NULL);
// dyn_dechunker_free
dyn_dechunker_free(NULL); // Musn't crash!
dyn_dechunker_free(NULL); // Must not crash!
// dyn_dechunker_get_stream
dyn_dechunker_get_stream(NULL); // Musn't crash!
dyn_dechunker_get_stream(NULL); // Must not crash!
// dyn_dechunker_process_first_chunk
stat = dyn_dechunker_process_first_chunk(NULL, s, 1600); // No dechunker
+1 -1
View File
@@ -997,7 +997,7 @@ xrdp_egfx_create(struct xrdp_mm *mm, struct xrdp_egfx **egfx)
}
procs.open_response = xrdp_egfx_open_response;
procs.close_response = xrdp_egfx_close_response;
procs.data_first = NULL; // Defragging handled elsewere
procs.data_first = NULL; // Defragging handled elsewhere
procs.data = xrdp_egfx_data;
process = mm->wm->pro_layer;
error = libxrdp_drdynvc_open(process->session,