Attention is currently required from: fixeria, laforge, osmith.
Hello Jenkins Builder, fixeria, laforge, osmith,
I'd like you to reexamine a change. Please visit
https://gerrit.osmocom.org/c/libosmo-sigtran/+/43386?usp=email
to look at the new patch set (#5).
The following approvals got outdated and were removed:
Verified+1 by Jenkins Builder
Change subject: xua: Validate IE lengths of incoming messages
......................................................................
xua: Validate IE lengths of incoming messages
Improve the data structures defining M3UA/SUA messages to also include
expected min/max lengths of each IE in a given message.
This way we already cover in one place validation of fixed length IEs.
Related: OS#7074
Reported-By: Tristan Madani <tristan(a)talencesecurity.com>
Change-Id: I9b1ae0dbc324123790942c9e6068f6822e3bb957
---
M src/m3ua.c
M src/sua.c
M src/xua_msg.c
M src/xua_msg.h
4 files changed, 399 insertions(+), 112 deletions(-)
git pull ssh://gerrit.osmocom.org:29418/libosmo-sigtran refs/changes/86/43386/5
--
To view, visit https://gerrit.osmocom.org/c/libosmo-sigtran/+/43386?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: newpatchset
Gerrit-Project: libosmo-sigtran
Gerrit-Branch: master
Gerrit-Change-Id: I9b1ae0dbc324123790942c9e6068f6822e3bb957
Gerrit-Change-Number: 43386
Gerrit-PatchSet: 5
Gerrit-Owner: pespin <pespin(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Reviewer: laforge <laforge(a)osmocom.org>
Gerrit-Reviewer: osmith <osmith(a)sysmocom.de>
Gerrit-Attention: osmith <osmith(a)sysmocom.de>
Gerrit-Attention: laforge <laforge(a)osmocom.org>
Gerrit-Attention: fixeria <vyanitskiy(a)sysmocom.de>
Hello Jenkins Builder,
I'd like you to reexamine a change. Please visit
https://gerrit.osmocom.org/c/libosmo-sigtran/+/43396?usp=email
to look at the new patch set (#2).
Change subject: xua_rkm: rx REG REQ: clean up Routing Context IE checks
......................................................................
xua_rkm: rx REG REQ: clean up Routing Context IE checks
RFC4666 3.6.1 clearly marks the IE as optional. Our exisitng logic also
expected that the routing key may not be there.
Validate existence of the IE and explicitly set local variable to 0
instead of relying on xua_msg_get_u32() returning 0 on failure.
Change-Id: I0dd6b2892f9ffa72880f98d03e13f0b354c47c61
---
M src/xua_rkm.c
1 file changed, 4 insertions(+), 2 deletions(-)
git pull ssh://gerrit.osmocom.org:29418/libosmo-sigtran refs/changes/96/43396/2
--
To view, visit https://gerrit.osmocom.org/c/libosmo-sigtran/+/43396?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: newpatchset
Gerrit-Project: libosmo-sigtran
Gerrit-Branch: master
Gerrit-Change-Id: I0dd6b2892f9ffa72880f98d03e13f0b354c47c61
Gerrit-Change-Number: 43396
Gerrit-PatchSet: 2
Gerrit-Owner: pespin <pespin(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Hello Jenkins Builder,
I'd like you to reexamine a change. Please visit
https://gerrit.osmocom.org/c/libosmo-sigtran/+/43395?usp=email
to look at the new patch set (#2).
Change subject: xua_rkm: rx DEREG REQ: Fix potential read buffer overflow
......................................................................
xua_rkm: rx DEREG REQ: Fix potential read buffer overflow
The loop in the function was not taking into account cases like data
being non-multiple of 4.
Related: OS#7074
Reported-By: Tristan Madani <tristan(a)talencesecurity.com>
Change-Id: I861259b2bb57ce80167a8f2d1c1770b56dc09718
---
M src/xua_rkm.c
1 file changed, 21 insertions(+), 7 deletions(-)
git pull ssh://gerrit.osmocom.org:29418/libosmo-sigtran refs/changes/95/43395/2
--
To view, visit https://gerrit.osmocom.org/c/libosmo-sigtran/+/43395?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: newpatchset
Gerrit-Project: libosmo-sigtran
Gerrit-Branch: master
Gerrit-Change-Id: I861259b2bb57ce80167a8f2d1c1770b56dc09718
Gerrit-Change-Number: 43395
Gerrit-PatchSet: 2
Gerrit-Owner: pespin <pespin(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
pespin has uploaded this change for review. ( https://gerrit.osmocom.org/c/libosmo-sigtran/+/43396?usp=email )
Change subject: xua_rkm: rx REG REQ: Fix potential assert reading optional rctx IE
......................................................................
xua_rkm: rx REG REQ: Fix potential assert reading optional rctx IE
RFC4666 3.6.1 clearly marks the IE as optional. Our exisitng logic also
expected that the routing key may not be there.
Related: OS#7074
Reported-By: Tristan Madani <tristan(a)talencesecurity.com>
Change-Id: I0dd6b2892f9ffa72880f98d03e13f0b354c47c61
---
M src/xua_rkm.c
1 file changed, 4 insertions(+), 2 deletions(-)
git pull ssh://gerrit.osmocom.org:29418/libosmo-sigtran refs/changes/96/43396/1
diff --git a/src/xua_rkm.c b/src/xua_rkm.c
index 61730db..ec898d2 100644
--- a/src/xua_rkm.c
+++ b/src/xua_rkm.c
@@ -175,6 +175,7 @@
struct msgb *resp, struct osmo_ss7_as **newly_assigned_as,
unsigned int max_nas_idx, unsigned int *nas_idx)
{
+ struct xua_msg_part *rctx_ie;
uint32_t rk_id, rctx, _tmode, dpc;
enum osmo_ss7_as_traffic_mode tmode;
struct osmo_ss7_as *as = NULL;
@@ -186,7 +187,7 @@
/* mandatory local routing key ID */
rk_id = xua_msg_get_u32(inner, M3UA_IEI_LOC_RKEY_ID);
/* ASP may already include a routing context value here */
- rctx = xua_msg_get_u32(inner, M3UA_IEI_ROUTE_CTX);
+ rctx_ie = xua_msg_find_tag(inner, M3UA_IEI_ROUTE_CTX);
/* traffic mode type (0 = undefined) */
_tmode = xua_msg_get_u32(inner, M3UA_IEI_TRAF_MODE_TYP);
@@ -229,8 +230,9 @@
* all AS/RK in situations where the peers are trusted.
*/
- if (rctx) {
+ if (rctx_ie) {
/* check if there is already an AS for this routing key */
+ rctx = xua_msg_part_get_u32(rctx_ie);
as = osmo_ss7_as_find_by_rctx(asp->inst, rctx);
} else {
/* if the ASP did not include a routing context number, allocate
--
To view, visit https://gerrit.osmocom.org/c/libosmo-sigtran/+/43396?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: newchange
Gerrit-Project: libosmo-sigtran
Gerrit-Branch: master
Gerrit-Change-Id: I0dd6b2892f9ffa72880f98d03e13f0b354c47c61
Gerrit-Change-Number: 43396
Gerrit-PatchSet: 1
Gerrit-Owner: pespin <pespin(a)sysmocom.de>
Hello Jenkins Builder,
I'd like you to reexamine a change. Please visit
https://gerrit.osmocom.org/c/libosmo-sigtran/+/43394?usp=email
to look at the new patch set (#2).
Change subject: xua_rkm: Validate IE lengths of RKM inner messages
......................................................................
xua_rkm: Validate IE lengths of RKM inner messages
Related: OS#7074
Reported-By: Tristan Madani <tristan(a)talencesecurity.com>
Change-Id: Ibe7e446b1a537c0c09f8049add3460e37cdd58e8
---
M src/m3ua.c
M src/xua_internal.h
M src/xua_msg.c
M src/xua_msg.h
M src/xua_rkm.c
5 files changed, 140 insertions(+), 39 deletions(-)
git pull ssh://gerrit.osmocom.org:29418/libosmo-sigtran refs/changes/94/43394/2
--
To view, visit https://gerrit.osmocom.org/c/libosmo-sigtran/+/43394?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: newpatchset
Gerrit-Project: libosmo-sigtran
Gerrit-Branch: master
Gerrit-Change-Id: Ibe7e446b1a537c0c09f8049add3460e37cdd58e8
Gerrit-Change-Number: 43394
Gerrit-PatchSet: 2
Gerrit-Owner: pespin <pespin(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Attention is currently required from: laforge, pespin.
fixeria has posted comments on this change by fixeria. ( https://gerrit.osmocom.org/c/libosmocore/+/43150?usp=email )
Change subject: linuxlist: fix false-positive UBSan misaligned-access reports
......................................................................
Patch Set 2:
(1 comment)
Patchset:
PS2:
Related:
https://stackoverflow.com/questions/64859526/does-linux-kernel-list-impleme…https://www.kernel.org/doc/html/v7.2/dev-tools/ubsan.html
Quote from the 2nd link:
> Detection of unaligned accesses controlled through the separate option -CONFIG_UBSAN_ALIGNMENT. It’s off by default on architectures that support unaligned accesses (CONFIG_HAVE_EFFICIENT_UNALIGNED_ACCESS=y). One could still enable it in config, just note that it will produce a lot of UBSAN reports.
We need to decide how much do we care about this, especially given that this is a false positive.
--
To view, visit https://gerrit.osmocom.org/c/libosmocore/+/43150?usp=email
To unsubscribe, or for help writing mail filters, visit https://gerrit.osmocom.org/settings?usp=email
Gerrit-MessageType: comment
Gerrit-Project: libosmocore
Gerrit-Branch: master
Gerrit-Change-Id: I0424e76e76d8aa9402bd1a5aefe789de16e72fae
Gerrit-Change-Number: 43150
Gerrit-PatchSet: 2
Gerrit-Owner: fixeria <vyanitskiy(a)sysmocom.de>
Gerrit-Reviewer: Jenkins Builder
Gerrit-Reviewer: laforge <laforge(a)osmocom.org>
Gerrit-CC: pespin <pespin(a)sysmocom.de>
Gerrit-Attention: laforge <laforge(a)osmocom.org>
Gerrit-Attention: pespin <pespin(a)sysmocom.de>
Gerrit-Comment-Date: Tue, 25 Aug 2026 16:10:24 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
Comment-In-Reply-To: laforge <laforge(a)osmocom.org>
Comment-In-Reply-To: fixeria <vyanitskiy(a)sysmocom.de>