Code quality: Address Copilot review comments
All accesses to g_drdynvcs[] in chansrv.c have been checked for unbounded access.
This commit is contained in:
+1
-1
@@ -439,7 +439,7 @@ dyn_dechunker_process_first_chunk(struct dyn_dechunker *self,
|
||||
}
|
||||
else if (frag_size == total_size)
|
||||
{
|
||||
// This chunk ccontains all the data
|
||||
// This chunk contains all the data
|
||||
status = E_DYN_INLINE_CHUNK;
|
||||
}
|
||||
else
|
||||
|
||||
+1
-1
@@ -50,7 +50,7 @@ enum vc_dechunker_status
|
||||
};
|
||||
|
||||
/**
|
||||
* Returned from dyn_dechunker_process_chunk() and
|
||||
* Returned from dyn_dechunker_process_data_chunk() and
|
||||
* Returned from dyn_dechunker_process_first_chunk()
|
||||
*/
|
||||
enum dyn_dechunker_status
|
||||
|
||||
@@ -83,7 +83,6 @@ tbus g_exec_mutex;
|
||||
tbus g_exec_sem;
|
||||
int g_exec_pid = 0;
|
||||
|
||||
#define ARRAYSIZE(x) (sizeof(x)/sizeof(*(x)))
|
||||
/* max total channel bytes size */
|
||||
#define MAX_CHANNEL_BYTES (1 * 1024 * 1024 * 1024) /* 1 GB */
|
||||
#define MAX_CHANNEL_FRAG_BYTES 1600
|
||||
@@ -724,7 +723,7 @@ static int
|
||||
process_message_drdynvc_data(struct stream *s)
|
||||
{
|
||||
struct chansrv_drdynvc *drdynvc;
|
||||
int chan_id;
|
||||
uint32_t chan_id;
|
||||
struct stream *ls = NULL; // Set if the application to be called
|
||||
int free_ls = 0; // Set if we need to clear ls when we're done
|
||||
int rv = 0;
|
||||
@@ -890,6 +889,10 @@ chansrv_drdynvc_close(int chan_id)
|
||||
struct stream *s;
|
||||
int error;
|
||||
|
||||
if (chan_id < 0 || chan_id >= DRDYNVC_CHANNEL_COUNT)
|
||||
{
|
||||
return 1;
|
||||
}
|
||||
s = trans_get_out_s(g_con_trans, 8192);
|
||||
if (s == NULL)
|
||||
{
|
||||
@@ -1179,9 +1182,10 @@ my_trans_data_in(struct trans *trans)
|
||||
|
||||
/*****************************************************************************/
|
||||
static struct trans *
|
||||
get_api_trans_from_chan_id(int chan_id)
|
||||
get_api_trans_from_chan_id(uint32_t chan_id)
|
||||
{
|
||||
return g_drdynvcs[chan_id].xrdp_api_trans;
|
||||
return (chan_id >= DRDYNVC_CHANNEL_COUNT)
|
||||
? NULL : g_drdynvcs[chan_id].xrdp_api_trans;
|
||||
}
|
||||
|
||||
/*****************************************************************************/
|
||||
@@ -1605,7 +1609,7 @@ api_con_trans_list_check_wait_objs(void)
|
||||
chansrv_drdynvc_close(ad->chan_id);
|
||||
}
|
||||
for (drdynvc_index = 0;
|
||||
drdynvc_index < (int) ARRAYSIZE(g_drdynvcs);
|
||||
drdynvc_index < DRDYNVC_CHANNEL_COUNT;
|
||||
drdynvc_index++)
|
||||
{
|
||||
if (g_drdynvcs[drdynvc_index].xrdp_api_trans == ltran)
|
||||
|
||||
@@ -152,7 +152,7 @@ static const char frankenstein[] =
|
||||
// The dynamic dechunker works on total data block sizes of 1600 bytes,
|
||||
// including the block header as well.
|
||||
// The FIRST block header is 6-12 bytes long, and the DATA block header
|
||||
// is 5-8 bytes long. For simplicity we're assume a header size of 8
|
||||
// is 5-8 bytes long. For simplicity we assume a header size of 8
|
||||
// bytes, and hence a data size of 1592 bytes.
|
||||
#define FRANKENSTEIN_DYN_CHUNK_SIZE 1592
|
||||
|
||||
@@ -202,10 +202,10 @@ START_TEST(test_vc_dechunker_bad_params)
|
||||
ck_assert_ptr_ne(dc, NULL);
|
||||
|
||||
// vc_dechunker_free
|
||||
vc_dechunker_free(NULL); // Musn't crash!
|
||||
vc_dechunker_free(NULL); // Must not crash!
|
||||
|
||||
// vc_dechunker_get_stream
|
||||
vc_dechunker_get_stream(NULL); // Musn't crash!
|
||||
vc_dechunker_get_stream(NULL); // Must not crash!
|
||||
|
||||
// vc_dechunker_process_chunk
|
||||
stat = vc_dechunker_process_chunk(NULL, s, 0, 1600); // No dechunker
|
||||
@@ -629,10 +629,10 @@ START_TEST(test_dyn_dechunker_bad_params)
|
||||
ck_assert_ptr_ne(dc, NULL);
|
||||
|
||||
// dyn_dechunker_free
|
||||
dyn_dechunker_free(NULL); // Musn't crash!
|
||||
dyn_dechunker_free(NULL); // Must not crash!
|
||||
|
||||
// dyn_dechunker_get_stream
|
||||
dyn_dechunker_get_stream(NULL); // Musn't crash!
|
||||
dyn_dechunker_get_stream(NULL); // Must not crash!
|
||||
|
||||
// dyn_dechunker_process_first_chunk
|
||||
stat = dyn_dechunker_process_first_chunk(NULL, s, 1600); // No dechunker
|
||||
|
||||
+1
-1
@@ -997,7 +997,7 @@ xrdp_egfx_create(struct xrdp_mm *mm, struct xrdp_egfx **egfx)
|
||||
}
|
||||
procs.open_response = xrdp_egfx_open_response;
|
||||
procs.close_response = xrdp_egfx_close_response;
|
||||
procs.data_first = NULL; // Defragging handled elsewere
|
||||
procs.data_first = NULL; // Defragging handled elsewhere
|
||||
procs.data = xrdp_egfx_data;
|
||||
process = mm->wm->pro_layer;
|
||||
error = libxrdp_drdynvc_open(process->session,
|
||||
|
||||
Reference in New Issue
Block a user