Code quality: Address Copilot review comments
All accesses to g_drdynvcs[] in chansrv.c have been checked for unbounded access.
This commit is contained in:
+1
-1
@@ -439,7 +439,7 @@ dyn_dechunker_process_first_chunk(struct dyn_dechunker *self,
|
|||||||
}
|
}
|
||||||
else if (frag_size == total_size)
|
else if (frag_size == total_size)
|
||||||
{
|
{
|
||||||
// This chunk ccontains all the data
|
// This chunk contains all the data
|
||||||
status = E_DYN_INLINE_CHUNK;
|
status = E_DYN_INLINE_CHUNK;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
|
|||||||
+1
-1
@@ -50,7 +50,7 @@ enum vc_dechunker_status
|
|||||||
};
|
};
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Returned from dyn_dechunker_process_chunk() and
|
* Returned from dyn_dechunker_process_data_chunk() and
|
||||||
* Returned from dyn_dechunker_process_first_chunk()
|
* Returned from dyn_dechunker_process_first_chunk()
|
||||||
*/
|
*/
|
||||||
enum dyn_dechunker_status
|
enum dyn_dechunker_status
|
||||||
|
|||||||
@@ -83,7 +83,6 @@ tbus g_exec_mutex;
|
|||||||
tbus g_exec_sem;
|
tbus g_exec_sem;
|
||||||
int g_exec_pid = 0;
|
int g_exec_pid = 0;
|
||||||
|
|
||||||
#define ARRAYSIZE(x) (sizeof(x)/sizeof(*(x)))
|
|
||||||
/* max total channel bytes size */
|
/* max total channel bytes size */
|
||||||
#define MAX_CHANNEL_BYTES (1 * 1024 * 1024 * 1024) /* 1 GB */
|
#define MAX_CHANNEL_BYTES (1 * 1024 * 1024 * 1024) /* 1 GB */
|
||||||
#define MAX_CHANNEL_FRAG_BYTES 1600
|
#define MAX_CHANNEL_FRAG_BYTES 1600
|
||||||
@@ -724,7 +723,7 @@ static int
|
|||||||
process_message_drdynvc_data(struct stream *s)
|
process_message_drdynvc_data(struct stream *s)
|
||||||
{
|
{
|
||||||
struct chansrv_drdynvc *drdynvc;
|
struct chansrv_drdynvc *drdynvc;
|
||||||
int chan_id;
|
uint32_t chan_id;
|
||||||
struct stream *ls = NULL; // Set if the application to be called
|
struct stream *ls = NULL; // Set if the application to be called
|
||||||
int free_ls = 0; // Set if we need to clear ls when we're done
|
int free_ls = 0; // Set if we need to clear ls when we're done
|
||||||
int rv = 0;
|
int rv = 0;
|
||||||
@@ -890,6 +889,10 @@ chansrv_drdynvc_close(int chan_id)
|
|||||||
struct stream *s;
|
struct stream *s;
|
||||||
int error;
|
int error;
|
||||||
|
|
||||||
|
if (chan_id < 0 || chan_id >= DRDYNVC_CHANNEL_COUNT)
|
||||||
|
{
|
||||||
|
return 1;
|
||||||
|
}
|
||||||
s = trans_get_out_s(g_con_trans, 8192);
|
s = trans_get_out_s(g_con_trans, 8192);
|
||||||
if (s == NULL)
|
if (s == NULL)
|
||||||
{
|
{
|
||||||
@@ -1179,9 +1182,10 @@ my_trans_data_in(struct trans *trans)
|
|||||||
|
|
||||||
/*****************************************************************************/
|
/*****************************************************************************/
|
||||||
static struct trans *
|
static struct trans *
|
||||||
get_api_trans_from_chan_id(int chan_id)
|
get_api_trans_from_chan_id(uint32_t chan_id)
|
||||||
{
|
{
|
||||||
return g_drdynvcs[chan_id].xrdp_api_trans;
|
return (chan_id >= DRDYNVC_CHANNEL_COUNT)
|
||||||
|
? NULL : g_drdynvcs[chan_id].xrdp_api_trans;
|
||||||
}
|
}
|
||||||
|
|
||||||
/*****************************************************************************/
|
/*****************************************************************************/
|
||||||
@@ -1605,7 +1609,7 @@ api_con_trans_list_check_wait_objs(void)
|
|||||||
chansrv_drdynvc_close(ad->chan_id);
|
chansrv_drdynvc_close(ad->chan_id);
|
||||||
}
|
}
|
||||||
for (drdynvc_index = 0;
|
for (drdynvc_index = 0;
|
||||||
drdynvc_index < (int) ARRAYSIZE(g_drdynvcs);
|
drdynvc_index < DRDYNVC_CHANNEL_COUNT;
|
||||||
drdynvc_index++)
|
drdynvc_index++)
|
||||||
{
|
{
|
||||||
if (g_drdynvcs[drdynvc_index].xrdp_api_trans == ltran)
|
if (g_drdynvcs[drdynvc_index].xrdp_api_trans == ltran)
|
||||||
|
|||||||
@@ -152,7 +152,7 @@ static const char frankenstein[] =
|
|||||||
// The dynamic dechunker works on total data block sizes of 1600 bytes,
|
// The dynamic dechunker works on total data block sizes of 1600 bytes,
|
||||||
// including the block header as well.
|
// including the block header as well.
|
||||||
// The FIRST block header is 6-12 bytes long, and the DATA block header
|
// The FIRST block header is 6-12 bytes long, and the DATA block header
|
||||||
// is 5-8 bytes long. For simplicity we're assume a header size of 8
|
// is 5-8 bytes long. For simplicity we assume a header size of 8
|
||||||
// bytes, and hence a data size of 1592 bytes.
|
// bytes, and hence a data size of 1592 bytes.
|
||||||
#define FRANKENSTEIN_DYN_CHUNK_SIZE 1592
|
#define FRANKENSTEIN_DYN_CHUNK_SIZE 1592
|
||||||
|
|
||||||
@@ -202,10 +202,10 @@ START_TEST(test_vc_dechunker_bad_params)
|
|||||||
ck_assert_ptr_ne(dc, NULL);
|
ck_assert_ptr_ne(dc, NULL);
|
||||||
|
|
||||||
// vc_dechunker_free
|
// vc_dechunker_free
|
||||||
vc_dechunker_free(NULL); // Musn't crash!
|
vc_dechunker_free(NULL); // Must not crash!
|
||||||
|
|
||||||
// vc_dechunker_get_stream
|
// vc_dechunker_get_stream
|
||||||
vc_dechunker_get_stream(NULL); // Musn't crash!
|
vc_dechunker_get_stream(NULL); // Must not crash!
|
||||||
|
|
||||||
// vc_dechunker_process_chunk
|
// vc_dechunker_process_chunk
|
||||||
stat = vc_dechunker_process_chunk(NULL, s, 0, 1600); // No dechunker
|
stat = vc_dechunker_process_chunk(NULL, s, 0, 1600); // No dechunker
|
||||||
@@ -629,10 +629,10 @@ START_TEST(test_dyn_dechunker_bad_params)
|
|||||||
ck_assert_ptr_ne(dc, NULL);
|
ck_assert_ptr_ne(dc, NULL);
|
||||||
|
|
||||||
// dyn_dechunker_free
|
// dyn_dechunker_free
|
||||||
dyn_dechunker_free(NULL); // Musn't crash!
|
dyn_dechunker_free(NULL); // Must not crash!
|
||||||
|
|
||||||
// dyn_dechunker_get_stream
|
// dyn_dechunker_get_stream
|
||||||
dyn_dechunker_get_stream(NULL); // Musn't crash!
|
dyn_dechunker_get_stream(NULL); // Must not crash!
|
||||||
|
|
||||||
// dyn_dechunker_process_first_chunk
|
// dyn_dechunker_process_first_chunk
|
||||||
stat = dyn_dechunker_process_first_chunk(NULL, s, 1600); // No dechunker
|
stat = dyn_dechunker_process_first_chunk(NULL, s, 1600); // No dechunker
|
||||||
|
|||||||
+1
-1
@@ -997,7 +997,7 @@ xrdp_egfx_create(struct xrdp_mm *mm, struct xrdp_egfx **egfx)
|
|||||||
}
|
}
|
||||||
procs.open_response = xrdp_egfx_open_response;
|
procs.open_response = xrdp_egfx_open_response;
|
||||||
procs.close_response = xrdp_egfx_close_response;
|
procs.close_response = xrdp_egfx_close_response;
|
||||||
procs.data_first = NULL; // Defragging handled elsewere
|
procs.data_first = NULL; // Defragging handled elsewhere
|
||||||
procs.data = xrdp_egfx_data;
|
procs.data = xrdp_egfx_data;
|
||||||
process = mm->wm->pro_layer;
|
process = mm->wm->pro_layer;
|
||||||
error = libxrdp_drdynvc_open(process->session,
|
error = libxrdp_drdynvc_open(process->session,
|
||||||
|
|||||||
Reference in New Issue
Block a user