Code quality: Address Copilot review comments

All accesses to g_drdynvcs[] in chansrv.c have been checked for
unbounded access.
This commit is contained in:
matt335672
2026-08-13 11:37:11 +01:00
parent f4249b3ca6
commit a6d80e17ab
5 changed files with 17 additions and 13 deletions
+1 -1
View File
@@ -439,7 +439,7 @@ dyn_dechunker_process_first_chunk(struct dyn_dechunker *self,
} }
else if (frag_size == total_size) else if (frag_size == total_size)
{ {
// This chunk ccontains all the data // This chunk contains all the data
status = E_DYN_INLINE_CHUNK; status = E_DYN_INLINE_CHUNK;
} }
else else
+1 -1
View File
@@ -50,7 +50,7 @@ enum vc_dechunker_status
}; };
/** /**
* Returned from dyn_dechunker_process_chunk() and * Returned from dyn_dechunker_process_data_chunk() and
* Returned from dyn_dechunker_process_first_chunk() * Returned from dyn_dechunker_process_first_chunk()
*/ */
enum dyn_dechunker_status enum dyn_dechunker_status
+9 -5
View File
@@ -83,7 +83,6 @@ tbus g_exec_mutex;
tbus g_exec_sem; tbus g_exec_sem;
int g_exec_pid = 0; int g_exec_pid = 0;
#define ARRAYSIZE(x) (sizeof(x)/sizeof(*(x)))
/* max total channel bytes size */ /* max total channel bytes size */
#define MAX_CHANNEL_BYTES (1 * 1024 * 1024 * 1024) /* 1 GB */ #define MAX_CHANNEL_BYTES (1 * 1024 * 1024 * 1024) /* 1 GB */
#define MAX_CHANNEL_FRAG_BYTES 1600 #define MAX_CHANNEL_FRAG_BYTES 1600
@@ -724,7 +723,7 @@ static int
process_message_drdynvc_data(struct stream *s) process_message_drdynvc_data(struct stream *s)
{ {
struct chansrv_drdynvc *drdynvc; struct chansrv_drdynvc *drdynvc;
int chan_id; uint32_t chan_id;
struct stream *ls = NULL; // Set if the application to be called struct stream *ls = NULL; // Set if the application to be called
int free_ls = 0; // Set if we need to clear ls when we're done int free_ls = 0; // Set if we need to clear ls when we're done
int rv = 0; int rv = 0;
@@ -890,6 +889,10 @@ chansrv_drdynvc_close(int chan_id)
struct stream *s; struct stream *s;
int error; int error;
if (chan_id < 0 || chan_id >= DRDYNVC_CHANNEL_COUNT)
{
return 1;
}
s = trans_get_out_s(g_con_trans, 8192); s = trans_get_out_s(g_con_trans, 8192);
if (s == NULL) if (s == NULL)
{ {
@@ -1179,9 +1182,10 @@ my_trans_data_in(struct trans *trans)
/*****************************************************************************/ /*****************************************************************************/
static struct trans * static struct trans *
get_api_trans_from_chan_id(int chan_id) get_api_trans_from_chan_id(uint32_t chan_id)
{ {
return g_drdynvcs[chan_id].xrdp_api_trans; return (chan_id >= DRDYNVC_CHANNEL_COUNT)
? NULL : g_drdynvcs[chan_id].xrdp_api_trans;
} }
/*****************************************************************************/ /*****************************************************************************/
@@ -1605,7 +1609,7 @@ api_con_trans_list_check_wait_objs(void)
chansrv_drdynvc_close(ad->chan_id); chansrv_drdynvc_close(ad->chan_id);
} }
for (drdynvc_index = 0; for (drdynvc_index = 0;
drdynvc_index < (int) ARRAYSIZE(g_drdynvcs); drdynvc_index < DRDYNVC_CHANNEL_COUNT;
drdynvc_index++) drdynvc_index++)
{ {
if (g_drdynvcs[drdynvc_index].xrdp_api_trans == ltran) if (g_drdynvcs[drdynvc_index].xrdp_api_trans == ltran)
+5 -5
View File
@@ -152,7 +152,7 @@ static const char frankenstein[] =
// The dynamic dechunker works on total data block sizes of 1600 bytes, // The dynamic dechunker works on total data block sizes of 1600 bytes,
// including the block header as well. // including the block header as well.
// The FIRST block header is 6-12 bytes long, and the DATA block header // The FIRST block header is 6-12 bytes long, and the DATA block header
// is 5-8 bytes long. For simplicity we're assume a header size of 8 // is 5-8 bytes long. For simplicity we assume a header size of 8
// bytes, and hence a data size of 1592 bytes. // bytes, and hence a data size of 1592 bytes.
#define FRANKENSTEIN_DYN_CHUNK_SIZE 1592 #define FRANKENSTEIN_DYN_CHUNK_SIZE 1592
@@ -202,10 +202,10 @@ START_TEST(test_vc_dechunker_bad_params)
ck_assert_ptr_ne(dc, NULL); ck_assert_ptr_ne(dc, NULL);
// vc_dechunker_free // vc_dechunker_free
vc_dechunker_free(NULL); // Musn't crash! vc_dechunker_free(NULL); // Must not crash!
// vc_dechunker_get_stream // vc_dechunker_get_stream
vc_dechunker_get_stream(NULL); // Musn't crash! vc_dechunker_get_stream(NULL); // Must not crash!
// vc_dechunker_process_chunk // vc_dechunker_process_chunk
stat = vc_dechunker_process_chunk(NULL, s, 0, 1600); // No dechunker stat = vc_dechunker_process_chunk(NULL, s, 0, 1600); // No dechunker
@@ -629,10 +629,10 @@ START_TEST(test_dyn_dechunker_bad_params)
ck_assert_ptr_ne(dc, NULL); ck_assert_ptr_ne(dc, NULL);
// dyn_dechunker_free // dyn_dechunker_free
dyn_dechunker_free(NULL); // Musn't crash! dyn_dechunker_free(NULL); // Must not crash!
// dyn_dechunker_get_stream // dyn_dechunker_get_stream
dyn_dechunker_get_stream(NULL); // Musn't crash! dyn_dechunker_get_stream(NULL); // Must not crash!
// dyn_dechunker_process_first_chunk // dyn_dechunker_process_first_chunk
stat = dyn_dechunker_process_first_chunk(NULL, s, 1600); // No dechunker stat = dyn_dechunker_process_first_chunk(NULL, s, 1600); // No dechunker
+1 -1
View File
@@ -997,7 +997,7 @@ xrdp_egfx_create(struct xrdp_mm *mm, struct xrdp_egfx **egfx)
} }
procs.open_response = xrdp_egfx_open_response; procs.open_response = xrdp_egfx_open_response;
procs.close_response = xrdp_egfx_close_response; procs.close_response = xrdp_egfx_close_response;
procs.data_first = NULL; // Defragging handled elsewere procs.data_first = NULL; // Defragging handled elsewhere
procs.data = xrdp_egfx_data; procs.data = xrdp_egfx_data;
process = mm->wm->pro_layer; process = mm->wm->pro_layer;
error = libxrdp_drdynvc_open(process->session, error = libxrdp_drdynvc_open(process->session,