From c5d3321a4129771ec6062f62e7f302e55cc9aeff Mon Sep 17 00:00:00 2001 From: hackengineer Date: Thu, 13 Aug 2026 11:11:11 +0000 Subject: [PATCH] Fix unterminated MyNodeInfo.pio_env when APP_ENV is 40+ chars (#11468) strncpy does not null-terminate when the source fills the destination. A PlatformIO environment name of 40 or more characters leaves pio_env unterminated, nanopb aborts the whole MyInfo encode with 'unterminated string', getFromRadio() returns 0 bytes forever, and the client app never receives any config after want_config_id. Clients that receive a redacted MyInfo (pio_env cleared before encode) are unaffected, which makes the failure look client-specific when it is not. Co-authored-by: Claude Fable 5 --- src/mesh/PhoneAPI.cpp | 3 +++ 1 file changed, 3 insertions(+) diff --git a/src/mesh/PhoneAPI.cpp b/src/mesh/PhoneAPI.cpp index 45f9b2477e..813d413dea 100644 --- a/src/mesh/PhoneAPI.cpp +++ b/src/mesh/PhoneAPI.cpp @@ -579,6 +579,9 @@ size_t PhoneAPI::getFromRadio(uint8_t *buf) // app not to send locations on our behalf. fromRadioScratch.which_payload_variant = meshtastic_FromRadio_my_info_tag; strncpy(myNodeInfo.pio_env, optstr(APP_ENV), sizeof(myNodeInfo.pio_env)); + // strncpy does not terminate when the source fills the buffer; a 40+ char + // APP_ENV would make nanopb reject the MyInfo encode ("unterminated string"). + myNodeInfo.pio_env[sizeof(myNodeInfo.pio_env) - 1] = '\0'; myNodeInfo.nodedb_count = static_cast(nodeDB->getNumMeshNodes()); fromRadioScratch.my_info = myNodeInfo; #ifdef MESHTASTIC_PHONEAPI_ACCESS_CONTROL