Licensed channel defaults, phone map growth, and payload read bounds (#11286)

* Strip the default PSK when licensed defaults are installed

* Only record rate-limited portnums from the phone

* Bound payload reads by the received size
This commit is contained in:
Thomas Göttgens authored and GitHub committed 2026-07-29 22:29:12 +00:00
1 parent df6e67f70b
commit daf1213580
4 files changed
+23 -6

No files matched your search

+7 -4
View File
@@ -32,14 +32,17 @@ ProcessMessage DropzoneModule::handleReceived(const meshtastic_MeshPacket &mp)
auto &p = mp.decoded;
char matchCompare[54];
auto incomingMessage = reinterpret_cast<const char *>(p.payload.bytes);
sprintf(matchCompare, "%s conditions", owner.short_name);
if (strncasecmp(incomingMessage, matchCompare, strlen(matchCompare)) == 0) {
// payload.bytes is not NUL-terminated, so a comparison longer than the received size would read
// whatever the previous occupant of the packet left behind.
const size_t received = p.payload.size;
snprintf(matchCompare, sizeof(matchCompare), "%s conditions", owner.short_name);
if (received >= strlen(matchCompare) && strncasecmp(incomingMessage, matchCompare, strlen(matchCompare)) == 0) {
LOG_DEBUG("Received dropzone conditions request");
startSendConditions = millis();
}
sprintf(matchCompare, "%s conditions", owner.long_name);
if (strncasecmp(incomingMessage, matchCompare, strlen(matchCompare)) == 0) {
snprintf(matchCompare, sizeof(matchCompare), "%s conditions", owner.long_name);
if (received >= strlen(matchCompare) && strncasecmp(incomingMessage, matchCompare, strlen(matchCompare)) == 0) {
LOG_DEBUG("Received dropzone conditions request");
startSendConditions = millis();
}