pespin has uploaded this change for review. ( https://gerrit.osmocom.org/c/libosmo-sigtran/+/43421?usp=email )
Change subject: sua: sua_addr_parse_part(): Fix potential read buffer overflow
......................................................................
sua: sua_addr_parse_part(): Fix potential read buffer overflow
The sua_addr_parse_part() function lacked validating that the length
value in the TLV struct didn't go past the buffer, which could end up in
a read buffer overflow.
Related: OS#7079
Reported-By: Tristan Madani <tristan(a)talencesecurity.com>
Change-Id: I12fbdfc37bfbf6cf9ba18942eb0ec43c9d1349fe
---
M src/sua.c
1 file changed, 4 insertions(+), 1 deletion(-)
git pull ssh://gerrit.osmocom.org:29418/libosmo-sigtran refs/changes/21/43421/1
diff --git a/src/sua.c b/src/sua.c
index 3b217f4..0784b61 100644
--- a/src/sua.c
+++ b/src/sua.c
@@ -830,9 +830,12 @@
par_tag = ntohs(par->tag);
par_len = ntohs(par->len);
- /* sanity: check par->len received on the wire, make sure the subtraction does not wrap past zero. */
+ /* L value must account for at least TL (struct xua_parameter_hdr): */
if (par_len < sizeof(*par))
goto subpar_fail;
+ /* Avoid reading past buffer: */
+ if (pos + par_len > param->len)
+ goto subpar_fail;
par_datalen = par_len - sizeof(*par);
LOGP(DLSUA, LOGL_DEBUG, "SUA IEI 0x%04x pos %hu/%hu: subpart tag 0x%04x, len %hu\n",
--
To view, visit https://gerrit.osmocom.org/c/libosmo-sigtran/+/43421?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: newchange
Gerrit-Project: libosmo-sigtran
Gerrit-Branch: master
Gerrit-Change-Id: I12fbdfc37bfbf6cf9ba18942eb0ec43c9d1349fe
Gerrit-Change-Number: 43421
Gerrit-PatchSet: 1
Gerrit-Owner: pespin <pespin(a)sysmocom.de>
osmith has submitted this change. ( https://gerrit.osmocom.org/c/osmo-ttcn3-hacks/+/43420?usp=email )
Change subject: testenv/README: automatic backtraces for coredumps
......................................................................
testenv/README: automatic backtraces for coredumps
Add documentation for this feature.
Change-Id: I9b65bfb14853edb03ddb571867bb795bde9d495c
---
M _testenv/README.md
1 file changed, 13 insertions(+), 0 deletions(-)
Approvals:
pespin: Looks good to me, but someone else must approve
fixeria: Looks good to me, approved
Jenkins Builder: Verified
diff --git a/_testenv/README.md b/_testenv/README.md
index 710c021..047abc0 100644
--- a/_testenv/README.md
+++ b/_testenv/README.md
@@ -309,6 +309,19 @@
Switching between the versions is done either by setting a `titan_min` version
in `testsrcdir.cfg`, or by using `-T` / `--titan-version`.
+## Automatic backtraces for coredumps
+
+When your SUT crashes with a coredump, testenv automatically runs `gdb` to get
+a backtrace, displays it in the output and writes it next to other logs into a
+`.backtrace` file.
+
+For this to work, you either need to have `systemd-coredump` set up, or
+alternatively have a core pattern in `/proc/sys/kernel/core_pattern` starting
+with `core`.
+
+Executables that do not start with a relevant prefix (`osmo-` or `open5gs-`)
+get ignored, see `testenv.coredump.executable_is_relevant()`.
+
## Troubleshooting
### Timeout waiting for RESET-ACK after sending RESET
--
To view, visit https://gerrit.osmocom.org/c/osmo-ttcn3-hacks/+/43420?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: merged
Gerrit-Project: osmo-ttcn3-hacks
Gerrit-Branch: master
Gerrit-Change-Id: I9b65bfb14853edb03ddb571867bb795bde9d495c
Gerrit-Change-Number: 43420
Gerrit-PatchSet: 2
Gerrit-Owner: osmith <osmith(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Reviewer: osmith <osmith(a)sysmocom.de>
Gerrit-Reviewer: pespin <pespin(a)sysmocom.de>
Attention is currently required from: dexter.
Hello Jenkins Builder,
I'd like you to reexamine a change. Please visit
https://gerrit.osmocom.org/c/onomondo-eim/+/43402?usp=email
to look at the new patch set (#3).
The following approvals got outdated and were removed:
Verified-1 by Jenkins Builder
Change subject: rest_api_response_schema: re-structure REST API responses
......................................................................
rest_api_response_schema: re-structure REST API responses
The REST API responses are in parts inconsistent and the schema
file lacks proper spec references in the description fields. Also
in some places we mix proprietary error codes with return codes
from SGP.32, which may lead to unexpected effects in case the SGP.32
ASN.1 spec changes.
With this patch we clean up those remaining shortcomings, in
particular the following:
- Add a spec reference to each non-proprietary field
- No longer mix SGP.32 error codes with proprietary error codes
- Rename procedureError to eimProcedureError and make sure all
possible error codes appear in the JSON schema properly.
- Add dedicated error fields for each SGP.32 error code, so that
the REST API user gets more detailed information in the error case
- Restructure profileInstallationResult also return AID and
SimaResponse, also add an profileInstallationError field which
returns BppCommandId, ErrorReason and SimaResponse so that a REST
API user has a chance to debug profile installation issues.
- Orient the layout of result and error responses closer to the
SGP.32 ASN.1 specification.
- Do not specify the error codes in the JSON schema file to avoid
unexpected problems when SGP.32 adds new error code. A spec
reference in the field description should be sufficient.
Change-Id: I16cc063c185727e1b30f26d656bd15154504b087
Related: SYS#8100
---
M doc/build.md
M doc/database.md
M priv/rest_api_response_schema.json
M src/esipa_asn1_handler.erl
M src/esipa_asn1_handler_utils.erl
M src/esipa_asn1_http_handler.erl
M src/esipa_json_handler.erl
M src/esipa_json_http_handler.erl
M src/esipa_rest_utils.erl
M src/mnesia_db.erl
M src/mnesia_db_euicc.erl
M src/mnesia_db_rest.erl
M src/mnesia_db_work.erl
13 files changed, 388 insertions(+), 456 deletions(-)
git pull ssh://gerrit.osmocom.org:29418/onomondo-eim refs/changes/02/43402/3
--
To view, visit https://gerrit.osmocom.org/c/onomondo-eim/+/43402?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: newpatchset
Gerrit-Project: onomondo-eim
Gerrit-Branch: master
Gerrit-Change-Id: I16cc063c185727e1b30f26d656bd15154504b087
Gerrit-Change-Number: 43402
Gerrit-PatchSet: 3
Gerrit-Owner: dexter <pmaier(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Attention: dexter <pmaier(a)sysmocom.de>