mirror of
https://github.com/meshtastic/firmware.git
synced 2026-10-08 22:29:03 -04:00
c0d5ebffb249718153a50f7a7b7806e36fe2aaf3
escapedNotificationBody() returned its input unescaped if g_markup_escape_text() gave back NULL, which would hand libnotify the exact attacker-controlled string the function exists to neutralize. The branch is unreachable for the input we pass - already sanitized to valid UTF-8, and GLib documents no NULL return for it - but an error path whose fallback is the unsafe action is the wrong shape for a helper on this boundary. Drop the body instead. Also note in the doc comment why running this on the caller's thread does not weaken the rule that the worker owns every libnotify call: it is a pure GLib string function that touches no libnotify or DBus state. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013EZstXBJtzRyBmUD1h2FLs
Overview
This repository contains the official device firmware for Meshtastic, an open-source LoRa mesh networking project designed for long-range, low-power communication without relying on internet or cellular infrastructure. The firmware supports various hardware platforms, including ESP32, nRF52, RP2040/RP2350, and Linux-based devices.
Meshtastic enables text messaging, location sharing, and telemetry over a decentralized mesh network, making it ideal for outdoor adventures, emergency preparedness, and remote operations.
Get Started
- 🔧 Building Instructions - Learn how to compile the firmware from source.
- ⚡ Flashing Instructions - Install or update the firmware on your device.
Join our community and help improve Meshtastic! 🚀
Stats
Languages
C++
72.9%
C
22.2%
Python
2.7%
Shell
1.6%
Batchfile
0.2%
Other
0.2%
