Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package libosmocore for openSUSE:Factory checked in at 2026-08-21 17:01:27 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/libosmocore (Old) and /work/SRC/openSUSE:Factory/.libosmocore.new.1258 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "libosmocore" Fri Aug 21 17:01:27 2026 rev:42 rq:1372814 version:1.14.2 Changes: -------- --- /work/SRC/openSUSE:Factory/libosmocore/libosmocore.changes 2026-07-23 23:34:59.404205584 +0200 +++ /work/SRC/openSUSE:Factory/.libosmocore.new.1258/libosmocore.changes 2026-08-21 17:02:50.689288740 +0200 @@ -1,0 +2,12 @@ +Fri Aug 21 09:34:27 UTC 2026 - Jan Engelhardt <[email protected]> + +- Update to release 1.14.2 + * Fix buffer overflows/overreads in `bssgp_rx_paging`, + `parse_process_uss_req`, `osmo_dec_gcr`, `osmo_pbit2ubit`, in + the CBSP WRITE-REPLACE decoder, and in TLV tag logging. + * iuup: Cure stack buffer-overflow rx IuUP with payload + larger than 1024 bytes. + * gsm: Reject BSSMAP Encryption Information IE with no selected + algo or key length != 8. + +------------------------------------------------------------------- Old: ---- libosmocore-1.14.1.tar.bz2 New: ---- libosmocore-1.14.2.tar.bz2 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ libosmocore.spec ++++++ --- /var/tmp/diff_new_pack.56NBT8/_old 2026-08-21 17:02:52.381348648 +0200 +++ /var/tmp/diff_new_pack.56NBT8/_new 2026-08-21 17:02:52.386348825 +0200 @@ -17,7 +17,7 @@ Name: libosmocore -Version: 1.14.1 +Version: 1.14.2 Release: 0 Summary: The Open Source Mobile Communications Core Library License: AGPL-3.0-or-later AND GPL-2.0-only AND GPL-2.0-or-later AND LGPL-2.1-or-later ++++++ _scmsync.obsinfo ++++++ --- /var/tmp/diff_new_pack.56NBT8/_old 2026-08-21 17:02:52.442350808 +0200 +++ /var/tmp/diff_new_pack.56NBT8/_new 2026-08-21 17:02:52.446350949 +0200 @@ -1,5 +1,5 @@ -mtime: 1784732036 -commit: 5f4f8cdd2199c1f7c8efd44e4574b21fbe235325a7e4bc37acc2868a728bdc05 +mtime: 1787305369 +commit: 28dc02f3dfadbe8c939a55c91daf2ef957b21769addad370fe4538c1becac3c3 url: https://src.opensuse.org/jengelh/libosmocore revision: master ++++++ build.specials.obscpio ++++++ ++++++ build.specials.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/.gitignore new/.gitignore --- old/.gitignore 1970-01-01 01:00:00.000000000 +0100 +++ new/.gitignore 2026-08-21 11:42:49.000000000 +0200 @@ -0,0 +1 @@ +.osc ++++++ libosmocore-1.14.1.tar.bz2 -> libosmocore-1.14.2.tar.bz2 ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/.tarball-version new/libosmocore-1.14.2/.tarball-version --- old/libosmocore-1.14.1/.tarball-version 2026-07-22 12:35:27.000000000 +0200 +++ new/libosmocore-1.14.2/.tarball-version 2026-08-21 07:21:04.000000000 +0200 @@ -1 +1 @@ -1.14.1 +1.14.2 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/.version new/libosmocore-1.14.2/.version --- old/libosmocore-1.14.1/.version 2026-07-22 12:35:23.000000000 +0200 +++ new/libosmocore-1.14.2/.version 2026-08-21 07:21:00.000000000 +0200 @@ -1 +1 @@ -1.14.1 +1.14.2 diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/configure new/libosmocore-1.14.2/configure --- old/libosmocore-1.14.1/configure 2026-07-22 12:35:12.000000000 +0200 +++ new/libosmocore-1.14.2/configure 2026-08-21 07:20:48.000000000 +0200 @@ -1,6 +1,6 @@ #! /bin/sh # Guess values for system-dependent variables and create Makefiles. -# Generated by GNU Autoconf 2.71 for libosmocore 1.14.1. +# Generated by GNU Autoconf 2.71 for libosmocore 1.14.2. # # Report bugs to <[email protected]>. # @@ -621,8 +621,8 @@ # Identity of this package. PACKAGE_NAME='libosmocore' PACKAGE_TARNAME='libosmocore' -PACKAGE_VERSION='1.14.1' -PACKAGE_STRING='libosmocore 1.14.1' +PACKAGE_VERSION='1.14.2' +PACKAGE_STRING='libosmocore 1.14.2' PACKAGE_BUGREPORT='[email protected]' PACKAGE_URL='' @@ -1548,7 +1548,7 @@ # Omit some internal or obsolete options to make the list less imposing. # This message is too long to be a string in the A/UX 3.1 sh. cat <<_ACEOF -\`configure' configures libosmocore 1.14.1 to adapt to many kinds of systems. +\`configure' configures libosmocore 1.14.2 to adapt to many kinds of systems. Usage: $0 [OPTION]... [VAR=VALUE]... @@ -1619,7 +1619,7 @@ if test -n "$ac_init_help"; then case $ac_init_help in - short | recursive ) echo "Configuration of libosmocore 1.14.1:";; + short | recursive ) echo "Configuration of libosmocore 1.14.2:";; esac cat <<\_ACEOF @@ -1819,7 +1819,7 @@ test -n "$ac_init_help" && exit $ac_status if $ac_init_version; then cat <<\_ACEOF -libosmocore configure 1.14.1 +libosmocore configure 1.14.2 generated by GNU Autoconf 2.71 Copyright (C) 2021 Free Software Foundation, Inc. @@ -2287,7 +2287,7 @@ This file contains any messages produced by compilers while running configure, to aid debugging if configure makes a mistake. -It was created by libosmocore $as_me 1.14.1, which was +It was created by libosmocore $as_me 1.14.2, which was generated by GNU Autoconf 2.71. Invocation command line was $ $0$ac_configure_args_raw @@ -3559,7 +3559,7 @@ # Define the identity of the package. PACKAGE='libosmocore' - VERSION='1.14.1' + VERSION='1.14.2' printf "%s\n" "#define PACKAGE \"$PACKAGE\"" >>confdefs.h @@ -19078,7 +19078,7 @@ # report actual input values of CONFIG_FILES etc. instead of their # values after options handling. ac_log=" -This file was extended by libosmocore $as_me 1.14.1, which was +This file was extended by libosmocore $as_me 1.14.2, which was generated by GNU Autoconf 2.71. Invocation command line was CONFIG_FILES = $CONFIG_FILES @@ -19146,7 +19146,7 @@ cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1 ac_cs_config='$ac_cs_config_escaped' ac_cs_version="\\ -libosmocore config.status 1.14.1 +libosmocore config.status 1.14.2 configured by $0, generated by GNU Autoconf 2.71, with options \\"\$ac_cs_config\\" diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/debian/changelog new/libosmocore-1.14.2/debian/changelog --- old/libosmocore-1.14.1/debian/changelog 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/debian/changelog 2026-08-21 07:20:41.000000000 +0200 @@ -1,3 +1,35 @@ +libosmocore (1.14.2) unstable; urgency=medium + + [ Pau Espin Pedrol ] + * tests/osmo_io: Remove unused variable + * iuup: Improve validation of header size + * iuup: Avoid stack buffer-overflow rx IuUP with payload >1024 bytes + * bits: Fix osmo_pbit2ubit() reading extra input byte on num_bits%8==0 + * iuup: Fix formatting of log line printing payload checksum error + * iuup: Validate msgb input length in rx Initialization path + * iuup: test receival of IuUP Data with way too big payload + * gsm: Reject BSSMAP Encryption Information IE with no selected algo + * gsm: Reject BSSMAP Encryption Information IE with key length != 8 + * gsm: Introduce gsm_septet_pack2() and deprecate gsm_septet_pack() + * tests/sms: Validate gsm_septet_pack2() succeeds + + [ Vadim Yanitskiy ] + * gb: fix buffer overflow in bssgp_rx_paging() + * gsm0480: fix out-of-bounds read in parse_process_uss_req() + * gsm29205: fix out-of-bounds read in osmo_dec_gcr() + * gsm/ipa: fix out-of-bounds read in TLV tag logging + * gsm/ipa: reject t_len == 0 in ID_GET/ID_RESP TLV parsers + * gsm/ipa: fix t_len truncation in ipa_ccm_id_resp_parse() + * gsm0480: fix out-of-bounds reads in parse_ss_{invoke,return_result}() + + [ Andreas Eversberg ] + * Add missing length check in gsm48_decode_callerid() + + [ Adam Bedard ] + * gsm/cbsp: stack OOB read in the CBSP WRITE-REPLACE decoder + + -- Pau Espin Pedrol <[email protected]> Thu, 20 Aug 2026 10:02:21 +0200 + libosmocore (1.14.1) unstable; urgency=medium [ Vadim Yanitskiy ] diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/include/osmocom/core/version.h new/libosmocore-1.14.2/include/osmocom/core/version.h --- old/libosmocore-1.14.1/include/osmocom/core/version.h 2026-07-22 12:35:23.000000000 +0200 +++ new/libosmocore-1.14.2/include/osmocom/core/version.h 2026-08-21 07:21:01.000000000 +0200 @@ -1,11 +1,11 @@ #pragma once -#define LIBOSMOCORE_VERSION 1.14.1 -#define LIBOSMOCORE_VERSION_STR "1.14.1" +#define LIBOSMOCORE_VERSION 1.14.2 +#define LIBOSMOCORE_VERSION_STR "1.14.2" #define LIBOSMOCORE_VERSION_MAJOR 1 #define LIBOSMOCORE_VERSION_MINOR 14 -#define LIBOSMOCORE_VERSION_PATCH 1 +#define LIBOSMOCORE_VERSION_PATCH 2 #define LIBOSMOCORE_VERSION_GREATER_EQUAL(major, minor, patch) \ (LIBOSMOCORE_VERSION_MAJOR > (major) || \ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/include/osmocom/gsm/gsm_utils.h new/libosmocore-1.14.2/include/osmocom/gsm/gsm_utils.h --- old/libosmocore-1.14.1/include/osmocom/gsm/gsm_utils.h 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/include/osmocom/gsm/gsm_utils.h 2026-08-21 07:20:41.000000000 +0200 @@ -109,8 +109,10 @@ /* the four functions below are helper functions and here for the unit test */ int gsm_septets2octets(uint8_t *result, const uint8_t *rdata, uint8_t septet_len, uint8_t padding) OSMO_DEPRECATED("This function is unable to handle more than 255 septets, " - "use gsm_septet_pack() instead."); -int gsm_septet_pack(uint8_t *result, const uint8_t *rdata, size_t septet_len, uint8_t padding); + "use gsm_septet_pack2() instead."); +int gsm_septet_pack(uint8_t *result, const uint8_t *rdata, size_t septet_len, uint8_t padding) + OSMO_DEPRECATED("This function is not write-safe, use gsm_septet_pack2() instead."); +int gsm_septet_pack2(uint8_t *result, size_t result_size, const uint8_t *rdata, size_t septet_len, uint8_t padding); int gsm_septet_encode(uint8_t *result, const char *data); uint8_t gsm_get_octet_len(const uint8_t sept_len); int gsm_7bit_decode_n_hdr(char *decoded, size_t n, const uint8_t *user_data, uint8_t length, uint8_t ud_hdr_ind); diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/include/osmocom/gsm/protocol/gsm_25_415.h new/libosmocore-1.14.2/include/osmocom/gsm/protocol/gsm_25_415.h --- old/libosmocore-1.14.1/include/osmocom/gsm/protocol/gsm_25_415.h 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/include/osmocom/gsm/protocol/gsm_25_415.h 2026-08-21 07:20:41.000000000 +0200 @@ -158,9 +158,9 @@ /* 3GPP TS 25.415 Section 6.6.2 + 6.6.3.1 */ enum iuup_pdu_type { - IUUP_PDU_T_DATA_CRC = 0, - IUUP_PDU_T_DATA_NOCRC = 1, - IUUP_PDU_T_CONTROL = 14, + IUUP_PDU_T_DATA_CRC = 0, /* PDU Type 0 */ + IUUP_PDU_T_DATA_NOCRC = 1, /* PDU Type 1 */ + IUUP_PDU_T_CONTROL = 14, /* PDU Type 14 */ }; /* 3GPP TS 25.415 Section 6.6.3.2 */ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/core/Makefile.am new/libosmocore-1.14.2/src/core/Makefile.am --- old/libosmocore-1.14.1/src/core/Makefile.am 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/src/core/Makefile.am 2026-08-21 07:20:41.000000000 +0200 @@ -1,7 +1,7 @@ # This is _NOT_ the library release version, it's an API version. # Please read chapter "Library interface versions" of the libtool documentation # before making any modifications: https://www.gnu.org/software/libtool/manual/html_node/Versioning.html -LIBVERSION=26:1:4 +LIBVERSION=26:2:4 AM_CPPFLAGS = -I$(top_srcdir)/include -I$(top_builddir)/include -I$(top_builddir) AM_CFLAGS = -Wall $(TALLOC_CFLAGS) $(PTHREAD_CFLAGS) $(LIBSCTP_CFLAGS) $(LIBMNL_CFLAGS) $(URING_CFLAGS) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/core/Makefile.in new/libosmocore-1.14.2/src/core/Makefile.in --- old/libosmocore-1.14.1/src/core/Makefile.in 2026-07-22 12:35:13.000000000 +0200 +++ new/libosmocore-1.14.2/src/core/Makefile.in 2026-08-21 07:20:49.000000000 +0200 @@ -513,7 +513,7 @@ # This is _NOT_ the library release version, it's an API version. # Please read chapter "Library interface versions" of the libtool documentation # before making any modifications: https://www.gnu.org/software/libtool/manual/html_node/Versioning.html -LIBVERSION = 26:1:4 +LIBVERSION = 26:2:4 AM_CPPFLAGS = -I$(top_srcdir)/include -I$(top_builddir)/include \ -I$(top_builddir) $(am__append_1) AM_CFLAGS = -Wall $(TALLOC_CFLAGS) $(PTHREAD_CFLAGS) $(LIBSCTP_CFLAGS) $(LIBMNL_CFLAGS) $(URING_CFLAGS) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/core/bits.c new/libosmocore-1.14.2/src/core/bits.c --- old/libosmocore-1.14.1/src/core/bits.c 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/src/core/bits.c 2026-08-21 07:20:41.000000000 +0200 @@ -139,6 +139,8 @@ * \param[in] in input buffer of packed bits * \param[in] num_bits number of bits * \return number of bytes used in \ref out + * + * Note: size of out array is expected to be ">= num_bits" bytes. */ int osmo_pbit2ubit(ubit_t *out, const pbit_t *in, unsigned int num_bits) { @@ -146,7 +148,7 @@ ubit_t *cur = out; ubit_t *limit = out + num_bits; - for (i = 0; i < (num_bits/8)+1; i++) { + for (i = 0; i < ((num_bits + 7) / 8); i++) { pbit_t byte = in[i]; *cur++ = (byte >> 7) & 1; if (cur >= limit) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/gb/Makefile.am new/libosmocore-1.14.2/src/gb/Makefile.am --- old/libosmocore-1.14.1/src/gb/Makefile.am 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/src/gb/Makefile.am 2026-08-21 07:20:41.000000000 +0200 @@ -1,7 +1,7 @@ # This is _NOT_ the library release version, it's an API version. # Please read chapter "Library interface versions" of the libtool documentation # before making any modifications: https://www.gnu.org/software/libtool/manual/html_node/Versioning.html -LIBVERSION=17:2:3 +LIBVERSION=17:3:3 AM_CPPFLAGS = -I$(top_srcdir)/include -I$(top_builddir)/include -I$(top_builddir) AM_CFLAGS = -Wall -fno-strict-aliasing \ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/gb/Makefile.in new/libosmocore-1.14.2/src/gb/Makefile.in --- old/libosmocore-1.14.1/src/gb/Makefile.in 2026-07-22 12:35:13.000000000 +0200 +++ new/libosmocore-1.14.2/src/gb/Makefile.in 2026-08-21 07:20:49.000000000 +0200 @@ -470,7 +470,7 @@ # This is _NOT_ the library release version, it's an API version. # Please read chapter "Library interface versions" of the libtool documentation # before making any modifications: https://www.gnu.org/software/libtool/manual/html_node/Versioning.html -LIBVERSION = 17:2:3 +LIBVERSION = 17:3:3 AM_CPPFLAGS = -I$(top_srcdir)/include -I$(top_builddir)/include -I$(top_builddir) AM_CFLAGS = -Wall -fno-strict-aliasing \ $(TALLOC_CFLAGS) \ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/gb/gprs_bssgp_bss.c new/libosmocore-1.14.2/src/gb/gprs_bssgp_bss.c --- old/libosmocore-1.14.1/src/gb/gprs_bssgp_bss.c 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/src/gb/gprs_bssgp_bss.c 2026-08-21 07:20:41.000000000 +0200 @@ -479,11 +479,8 @@ struct bssgp_normal_hdr *bgph = (struct bssgp_normal_hdr *) msgb_bssgph(msg); struct tlv_parsed tp; - uint8_t ra[6]; int rc, data_len; - memset(ra, 0, sizeof(ra)); - data_len = msgb_bssgp_len(msg) - sizeof(*bgph); rc = bssgp_tlv_parse(&tp, bgph->data, data_len); if (rc < 0) @@ -519,14 +516,10 @@ pinfo->scope = BSSGP_PAGING_BSS_AREA; } else if (TLVP_PRES_LEN(&tp, BSSGP_IE_LOCATION_AREA, 5)) { pinfo->scope = BSSGP_PAGING_LOCATION_AREA; - memcpy(ra, TLVP_VAL(&tp, BSSGP_IE_LOCATION_AREA), - TLVP_LEN(&tp, BSSGP_IE_LOCATION_AREA)); - gsm48_parse_ra(&pinfo->raid, ra); + gsm48_parse_ra(&pinfo->raid, TLVP_VAL(&tp, BSSGP_IE_LOCATION_AREA)); } else if (TLVP_PRES_LEN(&tp, BSSGP_IE_ROUTEING_AREA, 6)) { pinfo->scope = BSSGP_PAGING_ROUTEING_AREA; - memcpy(ra, TLVP_VAL(&tp, BSSGP_IE_ROUTEING_AREA), - TLVP_LEN(&tp, BSSGP_IE_ROUTEING_AREA)); - gsm48_parse_ra(&pinfo->raid, ra); + gsm48_parse_ra(&pinfo->raid, TLVP_VAL(&tp, BSSGP_IE_ROUTEING_AREA)); } else if (TLVP_PRES_LEN(&tp, BSSGP_IE_BVCI, 2)) { pinfo->scope = BSSGP_PAGING_BVCI; pinfo->bvci = tlvp_val16be(&tp, BSSGP_IE_BVCI); diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/Makefile.am new/libosmocore-1.14.2/src/gsm/Makefile.am --- old/libosmocore-1.14.1/src/gsm/Makefile.am 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/src/gsm/Makefile.am 2026-08-21 07:20:41.000000000 +0200 @@ -1,7 +1,7 @@ # This is _NOT_ the library release version, it's an API version. # Please read chapter "Library interface versions" of the libtool documentation # before making any modifications: https://www.gnu.org/software/libtool/manual/html_node/Versioning.html -LIBVERSION=24:1:4 +LIBVERSION=25:0:5 AM_CPPFLAGS = -I$(top_srcdir)/include -I$(top_builddir)/include AM_CFLAGS = -Wall $(TALLOC_CFLAGS) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/Makefile.in new/libosmocore-1.14.2/src/gsm/Makefile.in --- old/libosmocore-1.14.1/src/gsm/Makefile.in 2026-07-22 12:35:13.000000000 +0200 +++ new/libosmocore-1.14.2/src/gsm/Makefile.in 2026-08-21 07:20:49.000000000 +0200 @@ -511,7 +511,7 @@ # This is _NOT_ the library release version, it's an API version. # Please read chapter "Library interface versions" of the libtool documentation # before making any modifications: https://www.gnu.org/software/libtool/manual/html_node/Versioning.html -LIBVERSION = 24:1:4 +LIBVERSION = 25:0:5 AM_CPPFLAGS = -I$(top_srcdir)/include -I$(top_builddir)/include \ $(am__append_1) AM_CFLAGS = -Wall $(TALLOC_CFLAGS) $(am__append_3) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/cbsp.c new/libosmocore-1.14.2/src/gsm/cbsp.c --- old/libosmocore-1.14.1/src/gsm/cbsp.c 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/src/gsm/cbsp.c 2026-08-21 07:20:41.000000000 +0200 @@ -633,6 +633,7 @@ /*********************************************************************** * Message Decoding ***********************************************************************/ +#define MAX_NUM_CBS_PAGES 16 /* max. number of pages in a given CBS message */ /* 8.1.3.1 WRITE REPLACE */ static int cbsp_dec_write_repl(struct osmo_cbsp_write_replace *out, const struct tlv_parsed *tp, @@ -684,8 +685,10 @@ out->u.cbs.num_bcast_req = tlvp_val16be(tp, CBSP_IEI_NUM_BCAST_REQ); out->u.cbs.dcs = *TLVP_VAL(tp, CBSP_IEI_DCS); num_of_pages = *TLVP_VAL(tp, CBSP_IEI_NUM_OF_PAGES); - if (num_of_pages < 1) + if (num_of_pages < 1 || num_of_pages > MAX_NUM_CBS_PAGES) { + osmo_cbsp_errstr = "invalid number of pages"; return -EINVAL; + } /* parse pages */ for (i = 0; i < num_of_pages; i++) { const uint8_t *ie = TLVP_VAL(&tp[i], CBSP_IEI_MSG_CONTENT); @@ -1264,7 +1267,7 @@ OSMO_ASSERT(in->l1h != NULL && in->l2h != NULL); struct osmo_cbsp_decoded *out = talloc_zero(ctx, struct osmo_cbsp_decoded); const struct cbsp_header *h = msgb_l1(in); - struct tlv_parsed tp[16]; /* max. number of pages in a given CBS message */ + struct tlv_parsed tp[MAX_NUM_CBS_PAGES]; unsigned int len; int rc; diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/gsm0480.c new/libosmocore-1.14.2/src/gsm/gsm0480.c --- old/libosmocore-1.14.1/src/gsm/gsm0480.c 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/src/gsm/gsm0480.c 2026-08-21 07:20:41.000000000 +0200 @@ -548,17 +548,24 @@ offset = invoke_data[1] + 2; req->invoke_id = invoke_data[2]; - /* look ahead once */ - if (offset + 1 > length) + /* look ahead once: need invoke_data[offset] and, if it turns out to be + * the optional Linked ID tag, invoke_data[offset+1] as well */ + if (offset + 2 > length) return 0; /* optional part */ - if (invoke_data[offset] == GSM0480_COMPIDTAG_LINKED_ID) + if (invoke_data[offset] == GSM0480_COMPIDTAG_LINKED_ID) { offset += invoke_data[offset+1] + 2; /* skip over it */ + /* offset moved by an attacker-controlled amount: re-validate */ + if (offset >= length) + return 0; + } + /* mandatory part */ if (invoke_data[offset] == GSM0480_OPERATION_CODE) { - if (offset + 2 > length) + /* need invoke_data[offset+2] below, and length - offset - 3 must not underflow */ + if (offset + 3 > length) return 0; uint8_t operation_code = invoke_data[offset+2]; req->opcode = operation_code; @@ -624,10 +631,12 @@ if (rr_data[offset] != GSM_0480_SEQUENCE_TAG) return 0; - if (offset + 2 > length) + offset += 2; + + /* need rr_data[offset+2] below, and length - offset - 3 must not underflow */ + if (offset + 3 > length) return 0; - offset += 2; operation_code = rr_data[offset + 2]; req->opcode = operation_code; @@ -704,6 +713,8 @@ dcs = uss_req_data[4]; /* Get the amount of bytes */ num_chars = uss_req_data[6]; + if (num_chars > length - 7) + return 0; /* Drop messages with incorrect length */ if (num_chars > GSM0480_USSD_OCTET_STRING_LEN) { diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/gsm0808_utils.c new/libosmocore-1.14.2/src/gsm/gsm0808_utils.c --- old/libosmocore-1.14.1/src/gsm/gsm0808_utils.c 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/src/gsm/gsm0808_utils.c 2026-08-21 07:20:41.000000000 +0200 @@ -820,7 +820,7 @@ return *tlv_len + 2; } -/*! Decode TS 08.08 Encryption Information IE +/*! Decode 3GPP TS 48.008 3.2.2.10 Encryption Information IE * \param[out] ei Caller-provided memory to store encryption information * \param[in] elem IE value to be decoded * \param[in] len Length of \a elem in bytes @@ -831,7 +831,6 @@ uint8_t perm_algo; unsigned int i; unsigned int perm_algo_len = 0; - const uint8_t *old_elem = elem; if (!elem) return -EINVAL; @@ -843,6 +842,10 @@ perm_algo = *elem; elem++; + /* "A permitted algorithms octet containing all bits encoded as 0 shall not be used." */ + if (perm_algo == 0x00) + return -EINVAL; + for (i = 0; i < ENCRY_INFO_PERM_ALGO_MAXLEN; i++) { if (perm_algo & (1 << i)) { ei->perm_algo[perm_algo_len] = i + 1; @@ -850,14 +853,18 @@ } } ei->perm_algo_len = perm_algo_len; - - /* FIXME: 48.008 3.2.2.10 Encryption Information says: - * "When present, the key shall be 8 octets long." */ ei->key_len = len - 1; - memcpy(ei->key, elem, ei->key_len); - elem+=ei->key_len; - return (int)(elem - old_elem); + /* No key present, done */ + if (ei->key_len == 0) + return len; + + /* "When present, the key shall be 8 octets long." */ + if (ei->key_len != 8) + return -EINVAL; + OSMO_ASSERT(sizeof(ei->key) >= ei->key_len); + memcpy(ei->key, elem, ei->key_len); + return len; } /*! Encode TS 48.008 Kc128 IE. diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/gsm29205.c new/libosmocore-1.14.2/src/gsm/gsm29205.c --- old/libosmocore-1.14.1/src/gsm/gsm29205.c 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/src/gsm/gsm29205.c 2026-08-21 07:20:41.000000000 +0200 @@ -73,6 +73,8 @@ gcr->net_len = elem[0]; if (gcr->net_len < 3 || gcr->net_len > 5) return -EINVAL; + if (len < 10 + gcr->net_len) + return -EBADMSG; memcpy(gcr->net, elem + parsed, gcr->net_len); /* +1 for ignored Node ID length field */ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/gsm48_ie.c new/libosmocore-1.14.2/src/gsm/gsm48_ie.c --- old/libosmocore-1.14.1/src/gsm/gsm48_ie.c 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/src/gsm/gsm48_ie.c 2026-08-21 07:20:41.000000000 +0200 @@ -491,6 +491,8 @@ /* octet 3a */ if (!(lv[1] & 0x80)) { + if (in_len < 2) + return -EINVAL; callerid->screen = lv[2] & 0x03; callerid->present = (lv[2] & 0x60) >> 5; i = 2; diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/gsm_utils.c new/libosmocore-1.14.2/src/gsm/gsm_utils.c --- old/libosmocore-1.14.1/src/gsm/gsm_utils.c 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/src/gsm/gsm_utils.c 2026-08-21 07:20:41.000000000 +0200 @@ -90,6 +90,7 @@ #include <errno.h> #include <ctype.h> #include <inttypes.h> +#include <limits.h> #include <time.h> #include <unistd.h> @@ -317,11 +318,12 @@ /*! GSM Default Alphabet 7bit to octet packing * \param[out] result Caller-provided output buffer + * \param[in] result_size Caller-provided output buffer size * \param[in] rdata Input data septets * \param[in] septet_len Length of \a rdata * \param[in] padding padding bits at start - * \returns number of bytes used in \a result */ -int gsm_septet_pack(uint8_t *result, const uint8_t *rdata, size_t septet_len, uint8_t padding) + * \returns number of bytes used in \a result, negative on error */ +int gsm_septet_pack2(uint8_t *result, size_t result_size, const uint8_t *rdata, size_t septet_len, uint8_t padding) { int i = 0, z = 0; uint8_t cb, nb; @@ -358,6 +360,10 @@ cb = cb | nb; } + if (z == result_size) { + free(data); + return -ENOBUFS; + } result[z++] = cb; shift++; } @@ -367,10 +373,21 @@ return z; } +/*! GSM Default Alphabet 7bit to octet packing + * \param[out] result Caller-provided output buffer + * \param[in] rdata Input data septets + * \param[in] septet_len Length of \a rdata + * \param[in] padding padding bits at start + * \returns number of bytes used in \a result, negative on error */ +int gsm_septet_pack(uint8_t *result, const uint8_t *rdata, size_t septet_len, uint8_t padding) +{ + return gsm_septet_pack2(result, INT_MAX, rdata, septet_len, padding); +} + /*! Backwards compatibility wrapper for gsm_septets_pack(), deprecated. */ int gsm_septets2octets(uint8_t *result, const uint8_t *rdata, uint8_t septet_len, uint8_t padding) { - return gsm_septet_pack(result, rdata, septet_len, padding); + return gsm_septet_pack2(result, INT_MAX, rdata, septet_len, padding); } /*! GSM 7-bit alphabet TS 03.38 6.2.1 Character packing @@ -397,7 +414,7 @@ y = max_septets; } - o = gsm_septet_pack(result, rdata, y, 0); + o = gsm_septet_pack2(result, n, rdata, y, 0); if (octets) *octets = o; diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/ipa.c new/libosmocore-1.14.2/src/gsm/ipa.c --- old/libosmocore-1.14.1/src/gsm/ipa.c 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/src/gsm/ipa.c 2026-08-21 07:20:41.000000000 +0200 @@ -139,7 +139,7 @@ return -EINVAL; } - LOGPC(DLMI, LOGL_DEBUG, "%s='%s' ", ipa_ccm_idtag_name(t_tag), cur); + LOGPC(DLMI, LOGL_DEBUG, "%s='%.*s' ", ipa_ccm_idtag_name(t_tag), t_len - len_offset, cur); dec->lv[t_tag].len = t_len - len_offset; dec->lv[t_tag].val = cur; @@ -174,13 +174,19 @@ t_len = *cur++; t_tag = *cur++; + if (t_len < 1) { + LOGPC(DLMI, LOGL_DEBUG, "\n"); + LOGP(DLMI, LOGL_ERROR, "The tag length is too short: %d < 1\n", t_len); + return -EINVAL; + } + if (t_len > len + 1) { LOGPC(DLMI, LOGL_DEBUG, "\n"); LOGP(DLMI, LOGL_ERROR, "The tag does not fit: %d > %d\n", t_len, len + 1); return -EINVAL; } - LOGPC(DLMI, LOGL_DEBUG, "%s='%s' ", ipa_ccm_idtag_name(t_tag), cur); + LOGPC(DLMI, LOGL_DEBUG, "%s='%.*s' ", ipa_ccm_idtag_name(t_tag), t_len - 1, cur); dec->lv[t_tag].len = t_len-1; dec->lv[t_tag].val = cur; @@ -203,7 +209,7 @@ * \returns 0 on success; negative on error */ int ipa_ccm_id_resp_parse(struct tlv_parsed *dec, const uint8_t *buf, unsigned int len) { - uint8_t t_len; + uint16_t t_len; uint8_t t_tag; const uint8_t *cur = buf; @@ -216,13 +222,19 @@ cur += 2; t_tag = *cur++; + if (t_len < 1) { + LOGPC(DLMI, LOGL_DEBUG, "\n"); + LOGP(DLMI, LOGL_ERROR, "The tag length is too short: %d < 1\n", t_len); + return -EINVAL; + } + if (t_len > len + 1) { LOGPC(DLMI, LOGL_DEBUG, "\n"); LOGP(DLMI, LOGL_ERROR, "The tag does not fit: %d > %d\n", t_len, len + 1); return -EINVAL; } - DEBUGPC(DLMI, "%s='%s' ", ipa_ccm_idtag_name(t_tag), cur); + DEBUGPC(DLMI, "%s='%.*s' ", ipa_ccm_idtag_name(t_tag), t_len - 1, cur); dec->lv[t_tag].len = t_len-1; dec->lv[t_tag].val = cur; diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/iuup.c new/libosmocore-1.14.2/src/gsm/iuup.c --- old/libosmocore-1.14.1/src/gsm/iuup.c 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/src/gsm/iuup.c 2026-08-21 07:20:41.000000000 +0200 @@ -70,9 +70,12 @@ int osmo_iuup_compute_payload_crc(const uint8_t *iuup_pdu, unsigned int pdu_len) { - ubit_t buf[1024*8]; + /* Assume no IuUP payloads bigger than a regular ethernet frame: */ + const unsigned int max_supported_iuup_payload_len_bytes = 1500; + ubit_t buf[max_supported_iuup_payload_len_bytes * 8]; uint8_t pdu_type; - int offset, payload_len_bytes; + int offset; + unsigned int payload_len_bytes; if (pdu_len < 1) return -1; @@ -91,6 +94,11 @@ return -1; payload_len_bytes = pdu_len - offset; + + /* Guard against osmo_pbit2ubit writing past buf: */ + if (payload_len_bytes > max_supported_iuup_payload_len_bytes) + return -1; + osmo_pbit2ubit(buf, iuup_pdu+offset, payload_len_bytes*8); return osmo_crc16gen_compute_bits(&iuup_data_crc_code, buf, payload_len_bytes*8); } @@ -531,7 +539,8 @@ /* return: whether the last Init was Acked correctly and hence can transition to next state */ static bool iuup_rx_initialization(struct osmo_iuup_instance *iui, struct osmo_iuup_tnl_prim *itp) { - struct iuup_pdutype14_hdr *hdr; + struct msgb *msg = itp->oph.msg; + struct iuup_pdutype14_hdr *hdr = (struct iuup_pdutype14_hdr *)msgb_l2(msg); struct iuup_ctrl_init_hdr *ihdr; struct iuup_ctrl_init_rfci_hdr *ihdr_rfci; struct iuup_ctrl_init_tail *itail; @@ -543,9 +552,16 @@ struct osmo_iuup_rnl_prim *irp; struct osmo_iuup_tnl_prim *resp; - /* TODO: whenever we check message boundaries, length, etc. and we fail, send NACK */ + /* We expect at least the INIT header with at least 1 RFCI header: */ + if (msgb_l2len(msg) < sizeof(struct iuup_pdutype14_hdr) + + sizeof(struct iuup_ctrl_init_hdr) + + sizeof(struct iuup_ctrl_init_rfci_hdr)) { + LOGPFSML(iui->fi, LOGL_NOTICE, + "Initialization: Malformed packet, length %u too short\n", msgb_l2len(msg)); + err_cause = IUUP_ERR_CAUSE_FRAME_TOO_SHORT; + goto send_nack; + } - hdr = (struct iuup_pdutype14_hdr *)msgb_l2(itp->oph.msg); ihdr = (struct iuup_ctrl_init_hdr *)hdr->payload; if (ihdr->num_subflows_per_rfci == 0) { LOGPFSML(iui->fi, LOGL_NOTICE, "Initialization: Unexpected num_subflows=0 received\n"); @@ -554,16 +570,33 @@ } ihdr_rfci = (struct iuup_ctrl_init_rfci_hdr *)ihdr->rfci_data; + /* Iterate over RFCIs and parse and store its subflow lengths: */ do { struct osmo_iuup_rfci *rfci = &iui->config.rfci[num_rfci]; uint8_t l_size_bytes = ihdr_rfci->li + 1; + struct iuup_ctrl_init_rfci_hdr *next_ihdr_rfci = + (struct iuup_ctrl_init_rfci_hdr *)(&ihdr_rfci->subflow_length[0] + + (ihdr->num_subflows_per_rfci * l_size_bytes)); is_last = ihdr_rfci->lri; + if (num_rfci >= IUUP_MAX_RFCIS) { LOGPFSML(iui->fi, LOGL_NOTICE, "Initialization: Too many RFCIs received (%u)\n", - num_rfci); + num_rfci); err_cause = IUUP_ERR_CAUSE_UNEXPECTED_RFCI; goto send_nack; } + + /* Check contents of current RFCI are available in msgb, and if not last RFCI, + * also check for availability of next ihdr_rfci, all in one go: */ + if ((((uint8_t *)next_ihdr_rfci) + (is_last ? 0 : sizeof(struct iuup_ctrl_init_rfci_hdr))) > + msg->tail) { + LOGPFSML(iui->fi, LOGL_NOTICE, + "Initialization: Malformed packet, length %u too short\n", + msgb_l2len(msg)); + err_cause = IUUP_ERR_CAUSE_FRAME_TOO_SHORT; + goto send_nack; + } + rfci->used = 1; rfci->id = ihdr_rfci->rfci; if (l_size_bytes == 2) { @@ -580,13 +613,21 @@ } } num_rfci++; - ihdr_rfci++; - ihdr_rfci = (struct iuup_ctrl_init_rfci_hdr *)(((uint8_t *)ihdr_rfci) + ihdr->num_subflows_per_rfci * l_size_bytes); + ihdr_rfci = next_ihdr_rfci; } while (!is_last); if (ihdr->ti) { /* Timing information present */ uint8_t *buf = (uint8_t *)ihdr_rfci; uint8_t num_bytes = (num_rfci + 1) / 2; + + if (buf + num_bytes > msg->tail) { + LOGPFSML(iui->fi, LOGL_NOTICE, + "Initialization: Malformed packet, length %u too short\n", + msgb_l2len(msg)); + err_cause = IUUP_ERR_CAUSE_FRAME_TOO_SHORT; + goto send_nack; + } + iui->config.IPTIs_present = true; for (i = 0; i < num_bytes - 1; i++) { iui->config.rfci[i*2].IPTI = *buf >> 4; @@ -602,6 +643,15 @@ iui->config.IPTIs_present = false; itail = (struct iuup_ctrl_init_tail *)ihdr_rfci; } + + if (((uint8_t *)itail) + sizeof(*itail) > msg->tail) { + LOGPFSML(iui->fi, LOGL_NOTICE, + "Initialization: Malformed packet, length %u too short\n", + msgb_l2len(msg)); + err_cause = IUUP_ERR_CAUSE_FRAME_TOO_SHORT; + goto send_nack; + } + if (itail->data_pdu_type > 1) { LOGPFSML(iui->fi, LOGL_NOTICE, "Initialization: Unexpected Data PDU Type %u received\n", itail->data_pdu_type); err_cause = IUUP_ERR_CAUSE_UNEXPECTED_VALUE; @@ -635,9 +685,10 @@ resp = itp_ctrl_ack_alloc(iui, IUUP_PROC_INIT, hdr->frame_nr); iui->transport_prim_cb(&resp->oph, iui->transport_prim_priv); return ihdr->chain_ind == 0; + send_nack: LOGPFSML(iui->fi, LOGL_NOTICE, "Tx Initialization NACK cause=%u orig_message=%s\n", - err_cause, osmo_hexdump((const unsigned char *) msgb_l2(itp->oph.msg), msgb_l2len(itp->oph.msg))); + err_cause, osmo_hexdump((const unsigned char *) msgb_l2(msg), msgb_l2len(msg))); resp = tnp_ctrl_nack_alloc(iui, IUUP_PROC_INIT, err_cause, hdr->frame_nr); iui->transport_prim_cb(&resp->oph, iui->transport_prim_priv); return false; @@ -871,7 +922,7 @@ struct iuup_pdutype0_hdr *t0h; struct iuup_pdutype14_hdr *t14h; - if (len < 3) + if (len < 3) /* common minimum length for all IuUP packet types */ return -EINVAL; header_crc_computed = osmo_iuup_compute_header_crc(data, len); @@ -881,22 +932,30 @@ return -EIO; } switch (pdu_type) { - case IUUP_PDU_T_DATA_NOCRC: - if (len < 4) + case IUUP_PDU_T_DATA_CRC: /* PDU Type 0 */ + if (len < sizeof(struct iuup_pdutype0_hdr)) return -EINVAL; - break; - case IUUP_PDU_T_DATA_CRC: t0h = (struct iuup_pdutype0_hdr *) data; payload_crc = ((uint16_t)t0h->payload_crc_hi << 8) | t0h->payload_crc_lo; payload_crc_computed = osmo_iuup_compute_payload_crc(data, len); + if (payload_crc_computed < 0) + goto payload_crc_err; if (payload_crc != payload_crc_computed) goto payload_crc_err; break; - case IUUP_PDU_T_CONTROL: + case IUUP_PDU_T_DATA_NOCRC: /* PDU Type 1 */ + if (len < sizeof(struct iuup_pdutype1_hdr)) + return -EINVAL; + break; + case IUUP_PDU_T_CONTROL: /* PDU Type 14 */ + if (len < sizeof(struct iuup_pdutype14_hdr)) + return -EINVAL; t14h = (struct iuup_pdutype14_hdr *) data; if (t14h->ack_nack == IUUP_AN_PROCEDURE) { payload_crc = ((uint16_t)t14h->payload_crc_hi << 8) | t14h->payload_crc_lo; payload_crc_computed = osmo_iuup_compute_payload_crc(data, len); + if (payload_crc_computed < 0) + goto payload_crc_err; if (payload_crc != payload_crc_computed) goto payload_crc_err; } @@ -907,8 +966,13 @@ return 0; payload_crc_err: - LOGP(DLIUUP, LOGL_NOTICE, "Payload Checksum error (pdu type %u): rx 0x%02x vs exp 0x%02x\n", - pdu_type, payload_crc, payload_crc_computed); + if (payload_crc_computed < 0) { + LOGP(DLIUUP, LOGL_NOTICE, "Payload Checksum failed (pdu type %u): Packet too big? length %u\n", + pdu_type, len); + } else { + LOGP(DLIUUP, LOGL_NOTICE, "Payload Checksum error (pdu type %u): rx 0x%04x vs exp 0x%04x\n", + pdu_type, payload_crc, payload_crc_computed); + } return -EIO; } diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/src/gsm/libosmogsm.map new/libosmocore-1.14.2/src/gsm/libosmogsm.map --- old/libosmocore-1.14.1/src/gsm/libosmogsm.map 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/src/gsm/libosmogsm.map 2026-08-21 07:20:41.000000000 +0200 @@ -566,6 +566,7 @@ gsm_milenage; gsm_septet_encode; gsm_septet_pack; +gsm_septet_pack2; gsm_septets2octets; lapd_dl_exit; diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/tests/gsm0808/gsm0808_test.c new/libosmocore-1.14.2/tests/gsm0808/gsm0808_test.c --- old/libosmocore-1.14.1/tests/gsm0808/gsm0808_test.c 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/tests/gsm0808/gsm0808_test.c 2026-08-21 07:20:41.000000000 +0200 @@ -1281,10 +1281,42 @@ rc_dec = gsm0808_dec_encrypt_info(&dec_ei, msg->data + 2, msg->len - 2); OSMO_ASSERT(rc_dec == 9); - OSMO_ASSERT(memcmp(&enc_ei, &dec_ei, sizeof(enc_ei)) == 0); + + /* Test decoding IE with No Encryption and hence with no Key */ + struct gsm0808_encrypt_info enc_ei_no_encryption = { + .perm_algo = { GSM0808_ALG_ID_A5_0 }, + .perm_algo_len = 1, + .key = { 0 }, + .key_len = 0, + }; + uint8_t ei_enc_no_encryption_expected[] = { GSM0808_IE_ENCRYPTION_INFORMATION, 0x01, 0x01 }; + + msg = msgb_alloc(1024, "output buffer"); + rc_enc = gsm0808_enc_encrypt_info(msg, &enc_ei_no_encryption); + OSMO_ASSERT(rc_enc == 3); + OSMO_ASSERT(memcmp(ei_enc_no_encryption_expected, msg->data, msg->len) == 0); + + rc_dec = gsm0808_dec_encrypt_info(&dec_ei, msg->data + 2, msg->len - 2); + OSMO_ASSERT(rc_dec == 1); + OSMO_ASSERT(memcmp(&enc_ei_no_encryption, &dec_ei, sizeof(enc_ei_no_encryption)) == 0); msgb_free(msg); + + /* Test decoding of malformed IE with no algo selected: */ + uint8_t ei_enc_no_algo[] = { GSM0808_IE_ENCRYPTION_INFORMATION, 0x01, 0x00 }; + rc_dec = gsm0808_dec_encrypt_info(&dec_ei, &ei_enc_no_algo[2], sizeof(ei_enc_no_algo) - 2); + OSMO_ASSERT(rc_dec == -EINVAL); + + /* Test decoding of malformed IE with wrong key length: */ + uint8_t ei_enc_wrong_key_len[256] = { GSM0808_IE_ENCRYPTION_INFORMATION, 0xfd, 0x03 }; + rc_dec = gsm0808_dec_encrypt_info(&dec_ei, &ei_enc_wrong_key_len[2], 0xfd); + OSMO_ASSERT(rc_dec == -EINVAL); + /* test with another invalid key length: */ + ei_enc_wrong_key_len[1] = 0x03; + rc_dec = gsm0808_dec_encrypt_info(&dec_ei, &ei_enc_wrong_key_len[2], 0x03); + OSMO_ASSERT(rc_dec == -EINVAL); + } static void test_gsm0808_dec_cell_id_list_srvcc(void) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/tests/gsm29205/gsm29205_test.c new/libosmocore-1.14.2/tests/gsm29205/gsm29205_test.c --- old/libosmocore-1.14.1/tests/gsm29205/gsm29205_test.c 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/tests/gsm29205/gsm29205_test.c 2026-08-21 07:20:41.000000000 +0200 @@ -95,6 +95,34 @@ msgb_free(msg); } +/* osmo_dec_gcr() must reject buffers that are too short for the announced + * .net_len (3..5), not just shorter than the 13-byte minimum for + * .net_len == 3. Otherwise it reads past the end of 'elem'. */ +static void test_gcr_dec_short_buf(void) +{ + static const uint8_t res[] = { + 0x05, /* .net_len */ + 0x51, 0x52, 0x53, 0x54, 0x55, /* .net */ + 0x02, /* .node length */ + 0xde, 0xad, /* .node */ + 0x05, /* length of Call. Ref. */ + 0x41, 0x42, 0x43, 0x44, 0x45 /* .cr - Call. Ref. */ + }; + struct osmo_gcr_parsed p; + uint8_t len; + int rc; + + printf("Testing Global Call Reference decoder against short buffers...\n"); + + /* net_len == 5 requires 15 bytes, feed it 13 and 14 + * the full buffer must still decode successfully */ + for (len = 13; len <= ARRAY_SIZE(res); len++) { + rc = osmo_dec_gcr(&p, res, len); + printf("\tosmo_dec_gcr(len=%u) -> %s\n", + len, rc == len ? "OK" : "FAIL"); + } +} + int main(int argc, char **argv) { osmo_init_logging2(talloc_named_const(NULL, 0, "gsm29205 test"), NULL); @@ -102,6 +130,7 @@ printf("Testing 3GPP TS 29.205 routines...\n"); test_gcr(); + test_gcr_dec_short_buf(); printf("Done.\n"); diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/tests/gsm29205/gsm29205_test.ok new/libosmocore-1.14.2/tests/gsm29205/gsm29205_test.ok --- old/libosmocore-1.14.1/tests/gsm29205/gsm29205_test.ok 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/tests/gsm29205/gsm29205_test.ok 2026-08-21 07:20:41.000000000 +0200 @@ -2,4 +2,8 @@ Testing Global Call Reference encoder... 13 bytes added: OK decoded 13 bytes: OK +Testing Global Call Reference decoder against short buffers... + osmo_dec_gcr(len=13) -> FAIL + osmo_dec_gcr(len=14) -> FAIL + osmo_dec_gcr(len=15) -> OK Done. diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/tests/iuup/iuup_test.c new/libosmocore-1.14.2/tests/iuup/iuup_test.c --- old/libosmocore-1.14.1/tests/iuup/iuup_test.c 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/tests/iuup/iuup_test.c 2026-08-21 07:20:41.000000000 +0200 @@ -31,6 +31,56 @@ .t_rc = { .t_ms = IUUP_TIMER_RC_T_DEFAULT, .n_max = IUUP_TIMER_RC_N_DEFAULT }, }; +/* Frame 46, "Initialization", SYS#5969 call4_Iu_Iuh.pcap + 1110 .... = PDU Type: Control Procedure (14) + .... 00.. = Ack/Nack: Procedure (0) + .... ..00 = Frame Number: 0 + 0000 .... = Mode Version: 0x0 + .... 0000 = Procedure: Initialization (0) + 1101 11.. = Header CRC: 0x37 [correct] + .... ..01 1011 0100 = Payload CRC: 0x1b4 + 000. .... = Spare: 0x0 + ...0 .... = TI: IPTIs not present (0) + .... 011. = Subflows: 3 + .... ...0 = Chain Indicator: this frame is the last frame for the procedure (0) + RFCI 1 Initialization + 0... .... = RFCI 0 LRI: Not last RFCI (0x0) + .0.. .... = RFCI 0 LI: one octet used (0x0) + ..00 0001 = RFCI 0: 1 + RFCI 0 Flow 0 Len: 81 + RFCI 0 Flow 1 Len: 103 + RFCI 0 Flow 2 Len: 60 + RFCI 6 Initialization + 1... .... = RFCI 1 LRI: Last RFCI in current frame (0x1) + .0.. .... = RFCI 1 LI: one octet used (0x0) + ..00 0110 = RFCI 1: 6 + RFCI 1 Flow 0 Len: 39 + RFCI 1 Flow 1 Len: 0 + RFCI 1 Flow 2 Len: 0 + Iu UP Mode Versions Supported: 0x0001 + 0... .... .... .... = Version 16: not supported (0x0) + .0.. .... .... .... = Version 15: not supported (0x0) + ..0. .... .... .... = Version 14: not supported (0x0) + ...0 .... .... .... = Version 13: not supported (0x0) + .... 0... .... .... = Version 12: not supported (0x0) + .... .0.. .... .... = Version 11: not supported (0x0) + .... ..0. .... .... = Version 10: not supported (0x0) + .... ...0 .... .... = Version 9: not supported (0x0) + .... .... 0... .... = Version 8: not supported (0x0) + .... .... .0.. .... = Version 7: not supported (0x0) + .... .... ..0. .... = Version 6: not supported (0x0) + .... .... ...0 .... = Version 5: not supported (0x0) + .... .... .... 0... = Version 4: not supported (0x0) + .... .... .... .0.. = Version 3: not supported (0x0) + .... .... .... ..0. = Version 2: not supported (0x0) + .... .... .... ...1 = Version 1: supported (0x1) + 0000 .... = RFCI Data Pdu Type: PDU type 0 (0x0) +*/ +const uint8_t iuup_initialization_no_iptis[] = { + 0xe0, 0x00, 0xdd, 0xb4, 0x06, 0x01, 0x51, 0x67, 0x3c, 0x86, 0x27, + 0x00, 0x00, 0x00, 0x01, 0x00 +}; + /* Frame 33, "Initialization", OS#4744 3g_call_23112021.pcapng IuUP 1110 .... = PDU Type: Control Procedure (14) @@ -665,56 +715,6 @@ struct iuup_pdutype14_hdr *hdr14; int rc; - /* Frame 46, "Initialization", SYS#5969 call4_Iu_Iuh.pcap - 1110 .... = PDU Type: Control Procedure (14) - .... 00.. = Ack/Nack: Procedure (0) - .... ..00 = Frame Number: 0 - 0000 .... = Mode Version: 0x0 - .... 0000 = Procedure: Initialization (0) - 1101 11.. = Header CRC: 0x37 [correct] - .... ..01 1011 0100 = Payload CRC: 0x1b4 - 000. .... = Spare: 0x0 - ...0 .... = TI: IPTIs not present (0) - .... 011. = Subflows: 3 - .... ...0 = Chain Indicator: this frame is the last frame for the procedure (0) - RFCI 1 Initialization - 0... .... = RFCI 0 LRI: Not last RFCI (0x0) - .0.. .... = RFCI 0 LI: one octet used (0x0) - ..00 0001 = RFCI 0: 1 - RFCI 0 Flow 0 Len: 81 - RFCI 0 Flow 1 Len: 103 - RFCI 0 Flow 2 Len: 60 - RFCI 6 Initialization - 1... .... = RFCI 1 LRI: Last RFCI in current frame (0x1) - .0.. .... = RFCI 1 LI: one octet used (0x0) - ..00 0110 = RFCI 1: 6 - RFCI 1 Flow 0 Len: 39 - RFCI 1 Flow 1 Len: 0 - RFCI 1 Flow 2 Len: 0 - Iu UP Mode Versions Supported: 0x0001 - 0... .... .... .... = Version 16: not supported (0x0) - .0.. .... .... .... = Version 15: not supported (0x0) - ..0. .... .... .... = Version 14: not supported (0x0) - ...0 .... .... .... = Version 13: not supported (0x0) - .... 0... .... .... = Version 12: not supported (0x0) - .... .0.. .... .... = Version 11: not supported (0x0) - .... ..0. .... .... = Version 10: not supported (0x0) - .... ...0 .... .... = Version 9: not supported (0x0) - .... .... 0... .... = Version 8: not supported (0x0) - .... .... .0.. .... = Version 7: not supported (0x0) - .... .... ..0. .... = Version 6: not supported (0x0) - .... .... ...0 .... = Version 5: not supported (0x0) - .... .... .... 0... = Version 4: not supported (0x0) - .... .... .... .0.. = Version 3: not supported (0x0) - .... .... .... ..0. = Version 2: not supported (0x0) - .... .... .... ...1 = Version 1: supported (0x1) - 0000 .... = RFCI Data Pdu Type: PDU type 0 (0x0) - */ - const uint8_t iuup_init[] = { - 0xe0, 0x00, 0xdd, 0xb4, 0x06, 0x01, 0x51, 0x67, 0x3c, 0x86, 0x27, - 0x00, 0x00, 0x00, 0x01, 0x00 - }; - iui = osmo_iuup_instance_alloc(iuup_test_ctx, __func__); OSMO_ASSERT(iui); osmo_iuup_instance_set_user_prim_cb(iui, _decode_passive_init_2_rfci_no_iptis_user_prim_cb, NULL); @@ -732,15 +732,226 @@ /* Send Init: */ tnp = osmo_iuup_tnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_TNL_UNITDATA, PRIM_OP_INDICATION, IUUP_MSGB_SIZE); - tnp->oph.msg->l2h = msgb_put(tnp->oph.msg, sizeof(iuup_init)); + tnp->oph.msg->l2h = msgb_put(tnp->oph.msg, sizeof(iuup_initialization_no_iptis)); + hdr14 = (struct iuup_pdutype14_hdr *)msgb_l2(tnp->oph.msg); + memcpy(hdr14, iuup_initialization_no_iptis, sizeof(iuup_initialization_no_iptis)); + + rc = osmo_iuup_tnl_prim_up(iui, tnp); + OSMO_ASSERT(rc == 0); + + osmo_iuup_instance_free(iui); +} + +static int _decode_passive_init_exp_nack_transport_prim_cb(struct osmo_prim_hdr *oph, void *ctx) +{ + struct osmo_iuup_tnl_prim *itp = (struct osmo_iuup_tnl_prim *)oph; + struct msgb *msg; + struct iuup_pdutype14_hdr *hdr; + + printf("%s()\n", __func__); + msg = oph->msg; + OSMO_ASSERT(OSMO_PRIM_HDR(&itp->oph) == OSMO_PRIM(OSMO_IUUP_TNL_UNITDATA, PRIM_OP_REQUEST)); + printf("Transport: DL len=%u: %s\n", msgb_l2len(msg), + osmo_hexdump((const unsigned char *) msgb_l2(msg), msgb_l2len(msg))); + hdr = msgb_l2(msg); + OSMO_ASSERT(hdr->pdu_type == IUUP_PDU_T_CONTROL); + OSMO_ASSERT(hdr->ack_nack == IUUP_AN_NACK); + msgb_free(msg); + return 0; +} +/* Send a malformed Initialization to UIT containing num_subflows_per_rfci = 0. + * It shall be rejected since num_subflows_per_rfci should be at least one accoridng to 3GPP TS 25.415 Figure 24 */ +void test_decode_passive_init_malformed_0subflows(void) +{ + /* Here we check the passive INIT code path, aka receiving INIT and returning INIT_ACK/NACK */ + struct osmo_iuup_instance *iui; + struct osmo_iuup_rnl_prim *rnp; + struct osmo_iuup_tnl_prim *tnp; + struct iuup_pdutype14_hdr *hdr14; + struct iuup_ctrl_init_hdr *ihdr; + uint16_t payload_crc; + int rc; + + iui = osmo_iuup_instance_alloc(iuup_test_ctx, __func__); + OSMO_ASSERT(iui); + osmo_iuup_instance_set_transport_prim_cb(iui, _decode_passive_init_exp_nack_transport_prim_cb, NULL); + + clock_override_set(0, 0); + + /* Tx CONFIG.req */ + rnp = osmo_iuup_rnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_RNL_CONFIG, PRIM_OP_REQUEST, IUUP_MSGB_SIZE); + rnp->u.config = def_configure_req; + rnp->u.config.active = false; + + rc = osmo_iuup_rnl_prim_down(iui, rnp); + OSMO_ASSERT(rc == 0); + + /* Prepare and send Init: copy iuup_initialization_no_iptis, modify setting TI=1 (becoming malformed) and dispatch it. */ + tnp = osmo_iuup_tnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_TNL_UNITDATA, PRIM_OP_INDICATION, IUUP_MSGB_SIZE); + tnp->oph.msg->l2h = msgb_put(tnp->oph.msg, sizeof(iuup_initialization_no_iptis)); + hdr14 = (struct iuup_pdutype14_hdr *)msgb_l2(tnp->oph.msg); + memcpy(hdr14, iuup_initialization_no_iptis, sizeof(iuup_initialization_no_iptis)); + + ihdr = (struct iuup_ctrl_init_hdr *)hdr14->payload; + ihdr->num_subflows_per_rfci = 0; + payload_crc = osmo_iuup_compute_payload_crc(msgb_l2(tnp->oph.msg), msgb_l2len(tnp->oph.msg)); + hdr14->payload_crc_hi = (payload_crc >> 8) & 0x03; + hdr14->payload_crc_lo = payload_crc & 0xff; + + rc = osmo_iuup_tnl_prim_up(iui, tnp); + OSMO_ASSERT(rc == 0); + + osmo_iuup_instance_free(iui); +} + +/* Send a malformed Initialization to UIT containing TI=1 and no IPTIs encoded. + * As a result, the msgb content is too short and should be rejected. */ +void test_decode_passive_init_malformed_ti1_no_iptis(void) +{ + /* Here we check the passive INIT code path, aka receiving INIT and returning INIT_ACK/NACK */ + struct osmo_iuup_instance *iui; + struct osmo_iuup_rnl_prim *rnp; + struct osmo_iuup_tnl_prim *tnp; + struct iuup_pdutype14_hdr *hdr14; + struct iuup_ctrl_init_hdr *ihdr; + uint16_t payload_crc; + int rc; + + iui = osmo_iuup_instance_alloc(iuup_test_ctx, __func__); + OSMO_ASSERT(iui); + osmo_iuup_instance_set_transport_prim_cb(iui, _decode_passive_init_exp_nack_transport_prim_cb, NULL); + + clock_override_set(0, 0); + + /* Tx CONFIG.req */ + rnp = osmo_iuup_rnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_RNL_CONFIG, PRIM_OP_REQUEST, IUUP_MSGB_SIZE); + rnp->u.config = def_configure_req; + rnp->u.config.active = false; + + rc = osmo_iuup_rnl_prim_down(iui, rnp); + OSMO_ASSERT(rc == 0); + + /* Prepare and send Init: copy iuup_initialization_no_iptis, modify setting TI=1 (becoming malformed) and dispatch it. */ + tnp = osmo_iuup_tnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_TNL_UNITDATA, PRIM_OP_INDICATION, IUUP_MSGB_SIZE); + tnp->oph.msg->l2h = msgb_put(tnp->oph.msg, sizeof(iuup_initialization_no_iptis)); + hdr14 = (struct iuup_pdutype14_hdr *)msgb_l2(tnp->oph.msg); + memcpy(hdr14, iuup_initialization_no_iptis, sizeof(iuup_initialization_no_iptis)); + + ihdr = (struct iuup_ctrl_init_hdr *)hdr14->payload; + ihdr->ti = 1; + payload_crc = osmo_iuup_compute_payload_crc(msgb_l2(tnp->oph.msg), msgb_l2len(tnp->oph.msg)); + hdr14->payload_crc_hi = (payload_crc >> 8) & 0x03; + hdr14->payload_crc_lo = payload_crc & 0xff; + + rc = osmo_iuup_tnl_prim_up(iui, tnp); + OSMO_ASSERT(rc == 0); + + osmo_iuup_instance_free(iui); +} + +/* Send a malformed Initialization to UIT containing no RFCIs. + * As a result, the msgb content is too short and should be rejected. */ +void _test_submit_iuup_initialization_trimmed(unsigned int pkt_len, const char *test_name) +{ + /* Here we check the passive INIT code path, aka receiving INIT and returning INIT_ACK/NACK */ + struct osmo_iuup_instance *iui; + struct osmo_iuup_rnl_prim *rnp; + struct osmo_iuup_tnl_prim *tnp; + struct iuup_pdutype14_hdr *hdr14; + uint16_t payload_crc; + int rc; + + OSMO_ASSERT(pkt_len <= sizeof(iuup_initialization_no_iptis)); + + iui = osmo_iuup_instance_alloc(iuup_test_ctx, test_name); + OSMO_ASSERT(iui); + osmo_iuup_instance_set_transport_prim_cb(iui, _decode_passive_init_exp_nack_transport_prim_cb, NULL); + + /* Tx CONFIG.req */ + rnp = osmo_iuup_rnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_RNL_CONFIG, PRIM_OP_REQUEST, IUUP_MSGB_SIZE); + rnp->u.config = def_configure_req; + rnp->u.config.active = false; + + rc = osmo_iuup_rnl_prim_down(iui, rnp); + OSMO_ASSERT(rc == 0); + + /* Prepare and send Init: copy iuup_initialization_no_iptis, modify setting TI=1 (becoming malformed) and dispatch it. */ + tnp = osmo_iuup_tnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_TNL_UNITDATA, PRIM_OP_INDICATION, IUUP_MSGB_SIZE); + tnp->oph.msg->l2h = msgb_put(tnp->oph.msg, pkt_len); hdr14 = (struct iuup_pdutype14_hdr *)msgb_l2(tnp->oph.msg); - memcpy(hdr14, iuup_init, sizeof(iuup_init)); + memcpy(hdr14, iuup_initialization_no_iptis, pkt_len); + + payload_crc = osmo_iuup_compute_payload_crc(msgb_l2(tnp->oph.msg), msgb_l2len(tnp->oph.msg)); + hdr14->payload_crc_hi = (payload_crc >> 8) & 0x03; + hdr14->payload_crc_lo = payload_crc & 0xff; rc = osmo_iuup_tnl_prim_up(iui, tnp); OSMO_ASSERT(rc == 0); osmo_iuup_instance_free(iui); } +void test_decode_passive_init_malformed_no_rfci(void) +{ + unsigned int pkt_len = sizeof(struct iuup_pdutype14_hdr) + sizeof(struct iuup_ctrl_init_hdr); + clock_override_set(0, 0); + _test_submit_iuup_initialization_trimmed(pkt_len, __func__); +} + +/* Send a malformed Initialization to UIT containing malformed RFCIs. + * As a result, the msgb content is too short and should be rejected. */ +void test_decode_passive_init_malformed_rfci_too_short(void) +{ + unsigned int pkt_len = sizeof(struct iuup_pdutype14_hdr) + sizeof(struct iuup_ctrl_init_hdr) + 2; + clock_override_set(0, 0); + _test_submit_iuup_initialization_trimmed(pkt_len, __func__); +} + +void test_decode_passive_init_malformed_missing_last_byte(void) +{ + clock_override_set(0, 0); + _test_submit_iuup_initialization_trimmed(sizeof(iuup_initialization_no_iptis) - 1, __func__); +} + +/* Test IUT when a way too big IuUP data packet is received. It should be dropped. */ +void test_data_too_big(void) +{ + /* Here we check the passive INIT code path, aka receiving INIT and returning INIT_ACK/NACK */ + struct osmo_iuup_instance *iui; + struct osmo_iuup_rnl_prim *rnp; + struct osmo_iuup_tnl_prim *tnp; + struct iuup_pdutype0_hdr *hdr0; + uint16_t payload_crc; + int rc; + unsigned int pkt_len = sizeof(struct iuup_pdutype0_hdr) + 1600; + OSMO_ASSERT(pkt_len <= IUUP_MSGB_SIZE); + + iui = osmo_iuup_instance_alloc(iuup_test_ctx, __func__); + OSMO_ASSERT(iui); + + clock_override_set(0, 0); + + /* Tx CONFIG.req */ + rnp = osmo_iuup_rnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_RNL_CONFIG, PRIM_OP_REQUEST, IUUP_MSGB_SIZE); + rnp->u.config = def_configure_req; + rnp->u.config.active = false; + + rc = osmo_iuup_rnl_prim_down(iui, rnp); + OSMO_ASSERT(rc == 0); + + /* Send IuUP incoming data to the implementation: */ + tnp = osmo_iuup_tnl_prim_alloc(iuup_test_ctx, OSMO_IUUP_TNL_UNITDATA, PRIM_OP_INDICATION, IUUP_MSGB_SIZE); + tnp->oph.msg->l2h = msgb_put(tnp->oph.msg, pkt_len); + hdr0 = (struct iuup_pdutype0_hdr *)msgb_l2(tnp->oph.msg); + memcpy(hdr0, iuup_data, sizeof(iuup_data)); + + payload_crc = osmo_iuup_compute_payload_crc(msgb_l2(tnp->oph.msg), msgb_l2len(tnp->oph.msg)); + hdr0->payload_crc_hi = (payload_crc >> 8) & 0x03; + hdr0->payload_crc_lo = payload_crc & 0xff; + + OSMO_ASSERT((rc = osmo_iuup_tnl_prim_up(iui, tnp)) == 0); + + osmo_iuup_instance_free(iui); +} int main(int argc, char **argv) { @@ -762,6 +973,12 @@ test_passive_init(); test_passive_init_retrans(); test_decode_passive_init_2_rfci_no_iptis(); + test_decode_passive_init_malformed_0subflows(); + test_decode_passive_init_malformed_ti1_no_iptis(); + test_decode_passive_init_malformed_no_rfci(); + test_decode_passive_init_malformed_rfci_too_short(); + test_decode_passive_init_malformed_missing_last_byte(); + test_data_too_big(); printf("OK.\n"); } diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/tests/iuup/iuup_test.err new/libosmocore-1.14.2/tests/iuup/iuup_test.err --- old/libosmocore-1.14.1/tests/iuup/iuup_test.err 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/tests/iuup/iuup_test.err 2026-08-21 07:20:41.000000000 +0200 @@ -53,3 +53,43 @@ DLIUUP IuUP(test_decode_passive_init_2_rfci_no_iptis){Initialisation}: Tx Initialization ACK DLIUUP IuUP(test_decode_passive_init_2_rfci_no_iptis){Initialisation}: state_chg to SMpSDU_Data_Transfer_Ready DLIUUP IuUP(test_decode_passive_init_2_rfci_no_iptis){SMpSDU_Data_Transfer_Ready}: Deallocated +DLIUUP IuUP(test_decode_passive_init_malformed_0subflows){NULL}: Allocated +DLIUUP IuUP(test_decode_passive_init_malformed_0subflows){NULL}: Received Event IuUP-CONFIG-req +DLIUUP IuUP(test_decode_passive_init_malformed_0subflows){NULL}: state_chg to Initialisation +DLIUUP IuUP(test_decode_passive_init_malformed_0subflows){Initialisation}: Received Event INIT +DLIUUP IuUP(test_decode_passive_init_malformed_0subflows){Initialisation}: Initialization: Unexpected num_subflows=0 received +DLIUUP IuUP(test_decode_passive_init_malformed_0subflows){Initialisation}: Tx Initialization NACK cause=20 orig_message=e0 00 dc 62 00 01 51 67 3c 86 27 00 00 00 01 00 +DLIUUP IuUP(test_decode_passive_init_malformed_0subflows){Initialisation}: Deallocated +DLIUUP IuUP(test_decode_passive_init_malformed_ti1_no_iptis){NULL}: Allocated +DLIUUP IuUP(test_decode_passive_init_malformed_ti1_no_iptis){NULL}: Received Event IuUP-CONFIG-req +DLIUUP IuUP(test_decode_passive_init_malformed_ti1_no_iptis){NULL}: state_chg to Initialisation +DLIUUP IuUP(test_decode_passive_init_malformed_ti1_no_iptis){Initialisation}: Received Event INIT +DLIUUP IuUP(test_decode_passive_init_malformed_ti1_no_iptis){Initialisation}: Initialization: Malformed packet, length 16 too short +DLIUUP IuUP(test_decode_passive_init_malformed_ti1_no_iptis){Initialisation}: Tx Initialization NACK cause=8 orig_message=e0 00 dc 06 16 01 51 67 3c 86 27 00 00 00 01 00 +DLIUUP IuUP(test_decode_passive_init_malformed_ti1_no_iptis){Initialisation}: Deallocated +DLIUUP IuUP(test_decode_passive_init_malformed_no_rfci){NULL}: Allocated +DLIUUP IuUP(test_decode_passive_init_malformed_no_rfci){NULL}: Received Event IuUP-CONFIG-req +DLIUUP IuUP(test_decode_passive_init_malformed_no_rfci){NULL}: state_chg to Initialisation +DLIUUP IuUP(test_decode_passive_init_malformed_no_rfci){Initialisation}: Received Event INIT +DLIUUP IuUP(test_decode_passive_init_malformed_no_rfci){Initialisation}: Initialization: Malformed packet, length 5 too short +DLIUUP IuUP(test_decode_passive_init_malformed_no_rfci){Initialisation}: Tx Initialization NACK cause=8 orig_message=e0 00 dc cc 06 +DLIUUP IuUP(test_decode_passive_init_malformed_no_rfci){Initialisation}: Deallocated +DLIUUP IuUP(test_decode_passive_init_malformed_rfci_too_short){NULL}: Allocated +DLIUUP IuUP(test_decode_passive_init_malformed_rfci_too_short){NULL}: Received Event IuUP-CONFIG-req +DLIUUP IuUP(test_decode_passive_init_malformed_rfci_too_short){NULL}: state_chg to Initialisation +DLIUUP IuUP(test_decode_passive_init_malformed_rfci_too_short){Initialisation}: Received Event INIT +DLIUUP IuUP(test_decode_passive_init_malformed_rfci_too_short){Initialisation}: Initialization: Malformed packet, length 7 too short +DLIUUP IuUP(test_decode_passive_init_malformed_rfci_too_short){Initialisation}: Tx Initialization NACK cause=8 orig_message=e0 00 df 7d 06 01 51 +DLIUUP IuUP(test_decode_passive_init_malformed_rfci_too_short){Initialisation}: Deallocated +DLIUUP IuUP(test_decode_passive_init_malformed_missing_last_byte){NULL}: Allocated +DLIUUP IuUP(test_decode_passive_init_malformed_missing_last_byte){NULL}: Received Event IuUP-CONFIG-req +DLIUUP IuUP(test_decode_passive_init_malformed_missing_last_byte){NULL}: state_chg to Initialisation +DLIUUP IuUP(test_decode_passive_init_malformed_missing_last_byte){Initialisation}: Received Event INIT +DLIUUP IuUP(test_decode_passive_init_malformed_missing_last_byte){Initialisation}: Initialization: Malformed packet, length 15 too short +DLIUUP IuUP(test_decode_passive_init_malformed_missing_last_byte){Initialisation}: Tx Initialization NACK cause=8 orig_message=e0 00 df f7 06 01 51 67 3c 86 27 00 00 00 01 +DLIUUP IuUP(test_decode_passive_init_malformed_missing_last_byte){Initialisation}: Deallocated +DLIUUP IuUP(test_data_too_big){NULL}: Allocated +DLIUUP IuUP(test_data_too_big){NULL}: Received Event IuUP-CONFIG-req +DLIUUP IuUP(test_data_too_big){NULL}: state_chg to Initialisation +DLIUUP Payload Checksum failed (pdu type 0): Packet too big? length 1604 +DLIUUP IuUP(test_data_too_big){Initialisation}: Discarding invalid IuUP PDU: 01 00 e3 ff 08 55 6d 94 4c 71 a1 a0 81 e7 ea d2 04 24 44 80 00 0e cd 82 b8 11 18 00 00 97 c4 79 4e 77 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0 0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0DLIUUP IuUP(test_data_too_big){Initialisation}: Deallocated diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/tests/iuup/iuup_test.ok new/libosmocore-1.14.2/tests/iuup/iuup_test.ok --- old/libosmocore-1.14.1/tests/iuup/iuup_test.ok 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/tests/iuup/iuup_test.ok 2026-08-21 07:20:41.000000000 +0200 @@ -58,4 +58,20 @@ _decode_passive_init_2_rfci_no_iptis_user_prim_cb(): Initialization decoded fine! _decode_passive_init_2_rfci_no_iptis_transport_prim_cb() Transport: DL len=4: e4 00 24 00 +sys={0.000000}, clock_override_set +_decode_passive_init_exp_nack_transport_prim_cb() +Transport: DL len=5: e8 00 90 00 50 +sys={0.000000}, clock_override_set +_decode_passive_init_exp_nack_transport_prim_cb() +Transport: DL len=5: e8 00 90 00 20 +sys={0.000000}, clock_override_set +_decode_passive_init_exp_nack_transport_prim_cb() +Transport: DL len=5: e8 00 90 00 20 +sys={0.000000}, clock_override_set +_decode_passive_init_exp_nack_transport_prim_cb() +Transport: DL len=5: e8 00 90 00 20 +sys={0.000000}, clock_override_set +_decode_passive_init_exp_nack_transport_prim_cb() +Transport: DL len=5: e8 00 90 00 20 +sys={0.000000}, clock_override_set OK. diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/tests/osmo-config-merge/package.m4 new/libosmocore-1.14.2/tests/osmo-config-merge/package.m4 --- old/libosmocore-1.14.1/tests/osmo-config-merge/package.m4 2026-07-22 12:35:26.000000000 +0200 +++ new/libosmocore-1.14.2/tests/osmo-config-merge/package.m4 2026-08-21 07:21:04.000000000 +0200 @@ -4,9 +4,9 @@ m4_define([AT_PACKAGE_TARNAME], [libosmocore]) m4_define([AT_PACKAGE_VERSION], - [1.14.1]) + [1.14.2]) m4_define([AT_PACKAGE_STRING], - [libosmocore 1.14.1]) + [libosmocore 1.14.2]) m4_define([AT_PACKAGE_BUGREPORT], [[email protected]]) m4_define([AT_PACKAGE_URL], diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/tests/osmo-config-merge/testsuite new/libosmocore-1.14.2/tests/osmo-config-merge/testsuite --- old/libosmocore-1.14.1/tests/osmo-config-merge/testsuite 2026-07-22 12:35:27.000000000 +0200 +++ new/libosmocore-1.14.2/tests/osmo-config-merge/testsuite 2026-08-21 07:21:04.000000000 +0200 @@ -923,7 +923,7 @@ # List of tests. if $at_list_p; then cat <<_ATEOF || at_write_fail=1 -libosmocore 1.14.1 test suite test groups: +libosmocore 1.14.2 test suite test groups: NUM: FILE-NAME:LINE TEST-GROUP-NAME KEYWORDS @@ -964,7 +964,7 @@ exit $at_write_fail fi if $at_version_p; then - printf "%s\n" "$as_me (libosmocore 1.14.1)" && + printf "%s\n" "$as_me (libosmocore 1.14.2)" && cat <<\_ATEOF || at_write_fail=1 Copyright (C) 2021 Free Software Foundation, Inc. @@ -1152,11 +1152,11 @@ # Banners and logs. printf "%s\n" "## ------------------------------ ## -## libosmocore 1.14.1 test suite. ## +## libosmocore 1.14.2 test suite. ## ## ------------------------------ ##" { printf "%s\n" "## ------------------------------ ## -## libosmocore 1.14.1 test suite. ## +## libosmocore 1.14.2 test suite. ## ## ------------------------------ ##" echo @@ -1973,7 +1973,7 @@ printf "%s\n" "Please send $at_msg and all information you think might help: To: <[email protected]> - Subject: [libosmocore 1.14.1] $as_me: $at_msg1$at_msg2 + Subject: [libosmocore 1.14.2] $as_me: $at_msg1$at_msg2 You may investigate any problem if you feel able to do so, in which case the test suite provides a good starting point. Its output may diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/tests/osmo_io/osmo_io_backpressure_test.c new/libosmocore-1.14.2/tests/osmo_io/osmo_io_backpressure_test.c --- old/libosmocore-1.14.1/tests/osmo_io/osmo_io_backpressure_test.c 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/tests/osmo_io/osmo_io_backpressure_test.c 2026-08-21 07:20:41.000000000 +0200 @@ -106,7 +106,6 @@ file_bytes_write_compl = 0; char drain_buffer[512]; - int messages_queued = 0; for (int i = 0; i < 10; i++) { /* Add a message */ @@ -114,9 +113,7 @@ memset(msgb_put(msg, 1024), 0xAA + (i % 16), 1024); rc = osmo_iofd_write_msgb(iofd, msg); - if (rc == 0) - messages_queued++; - else + if (rc != 0) msgb_free(msg); /* Process events with explicit timeout */ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/tests/package.m4 new/libosmocore-1.14.2/tests/package.m4 --- old/libosmocore-1.14.1/tests/package.m4 2026-07-22 12:35:26.000000000 +0200 +++ new/libosmocore-1.14.2/tests/package.m4 2026-08-21 07:21:04.000000000 +0200 @@ -4,9 +4,9 @@ m4_define([AT_PACKAGE_TARNAME], [libosmocore]) m4_define([AT_PACKAGE_VERSION], - [1.14.1]) + [1.14.2]) m4_define([AT_PACKAGE_STRING], - [libosmocore 1.14.1]) + [libosmocore 1.14.2]) m4_define([AT_PACKAGE_BUGREPORT], [[email protected]]) m4_define([AT_PACKAGE_URL], diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/tests/sms/sms_test.c new/libosmocore-1.14.2/tests/sms/sms_test.c --- old/libosmocore-1.14.1/tests/sms/sms_test.c 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/tests/sms/sms_test.c 2026-08-21 07:20:41.000000000 +0200 @@ -380,7 +380,8 @@ memcpy(tmp, septet_data, concatenated_part1_septet_length); /* In our case: test_multiple_decode[0].ud_hdr_ind equals number of padding bits*/ - octet_length = gsm_septet_pack(coded, tmp, concatenated_part1_septet_length, test_multiple_encode[0].ud_hdr_ind); + octet_length = gsm_septet_pack2(coded, sizeof(coded), tmp, concatenated_part1_septet_length, test_multiple_encode[0].ud_hdr_ind); + OSMO_ASSERT(octet_length == 134); /* copy header */ memset(tmp, 0x42, sizeof(tmp)); @@ -398,7 +399,8 @@ memcpy(tmp, septet_data + concatenated_part1_septet_length, concatenated_part2_septet_length); /* In our case: test_multiple_decode[1].ud_hdr_ind equals number of padding bits*/ - octet_length = gsm_septet_pack(coded, tmp, concatenated_part2_septet_length, test_multiple_encode[1].ud_hdr_ind); + octet_length = gsm_septet_pack2(coded, sizeof(coded), tmp, concatenated_part2_septet_length, test_multiple_encode[1].ud_hdr_ind); + OSMO_ASSERT(octet_length == 36); /* copy header */ memset(tmp, 0x42, sizeof(tmp)); diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/tests/testsuite new/libosmocore-1.14.2/tests/testsuite --- old/libosmocore-1.14.1/tests/testsuite 2026-07-22 12:35:26.000000000 +0200 +++ new/libosmocore-1.14.2/tests/testsuite 2026-08-21 07:21:04.000000000 +0200 @@ -1012,7 +1012,7 @@ # List of tests. if $at_list_p; then cat <<_ATEOF || at_write_fail=1 -libosmocore 1.14.1 test suite test groups: +libosmocore 1.14.2 test suite test groups: NUM: FILE-NAME:LINE TEST-GROUP-NAME KEYWORDS @@ -1053,7 +1053,7 @@ exit $at_write_fail fi if $at_version_p; then - printf "%s\n" "$as_me (libosmocore 1.14.1)" && + printf "%s\n" "$as_me (libosmocore 1.14.2)" && cat <<\_ATEOF || at_write_fail=1 Copyright (C) 2021 Free Software Foundation, Inc. @@ -1241,11 +1241,11 @@ # Banners and logs. printf "%s\n" "## ------------------------------ ## -## libosmocore 1.14.1 test suite. ## +## libosmocore 1.14.2 test suite. ## ## ------------------------------ ##" { printf "%s\n" "## ------------------------------ ## -## libosmocore 1.14.1 test suite. ## +## libosmocore 1.14.2 test suite. ## ## ------------------------------ ##" echo @@ -2062,7 +2062,7 @@ printf "%s\n" "Please send $at_msg and all information you think might help: To: <[email protected]> - Subject: [libosmocore 1.14.1] $as_me: $at_msg1$at_msg2 + Subject: [libosmocore 1.14.2] $as_me: $at_msg1$at_msg2 You may investigate any problem if you feel able to do so, in which case the test suite provides a good starting point. Its output may diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/tests/ussd/ussd_test.c new/libosmocore-1.14.2/tests/ussd/ussd_test.c --- old/libosmocore-1.14.1/tests/ussd/ussd_test.c 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/tests/ussd/ussd_test.c 2026-08-21 07:20:41.000000000 +0200 @@ -41,6 +41,16 @@ 0x05, 0x02, 0x01, 0x24 }; +/* Same REGISTER/ProcessUssReq message as ussd_request[], except the + * USSD-String octet count (index 18) claims 100 bytes while the message + * only ever carries 6. Must be rejected, not read past the buffer end. */ +static const uint8_t ussd_process_uss_req_overflow[] = { + 0x0b, 0x7b, 0x1c, 0x15, 0xa1, 0x13, 0x02, 0x01, + 0x03, 0x02, 0x01, 0x3b, 0x30, 0x0b, 0x04, 0x01, + 0x0f, 0x04, 0x64, 0x2a, 0xd5, 0x4c, 0x16, 0x1b, + 0x01, 0x7f, 0x01, 0x00 +}; + static const uint8_t interrogate_ss[] = { 0x0b, 0x7b, 0x1c, 0x0d, 0xa1, 0x0b, 0x02, 0x01, 0x03, 0x02, 0x01, 0x0e, 0x30, 0x03, 0x04, 0x01, @@ -221,6 +231,23 @@ printf("\n"); } +/* parse_process_uss_req() must reject a USSD-String octet count that + * exceeds the bytes actually remaining in the message, rather than only + * capping it against GSM0480_USSD_OCTET_STRING_LEN and reading past the + * end of the buffer. */ +static void test_process_uss_req_overflow(void) +{ + int rc; + + printf("[i] Testing parse_process_uss_req() against an oversized " + "USSD-String length\n"); + + rc = parse_ussd(ussd_process_uss_req_overflow, sizeof(ussd_process_uss_req_overflow)); + OSMO_ASSERT(rc == 0); + + printf("\n"); +} + int main(int argc, char **argv) { struct ss_request req; @@ -237,6 +264,9 @@ /* Test gsm0480_parse_facility_ie() */ test_parse_facility_ie(); + /* Test parse_process_uss_req() against an oversized length byte */ + test_process_uss_req_overflow(); + memset(&req, 0, sizeof(req)); gsm0480_decode_ss_request((struct gsm48_hdr *) ussd_request, sizeof(ussd_request), &req); diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/libosmocore-1.14.1/tests/ussd/ussd_test.ok new/libosmocore-1.14.2/tests/ussd/ussd_test.ok --- old/libosmocore-1.14.1/tests/ussd/ussd_test.ok 2026-07-22 12:35:06.000000000 +0200 +++ new/libosmocore-1.14.2/tests/ussd/ussd_test.ok 2026-08-21 07:20:41.000000000 +0200 @@ -12,6 +12,8 @@ [?] Data length: expected 0x01, decoded 0x01 [?] Data: expected 32, decoded 32 +[i] Testing parse_process_uss_req() against an oversized USSD-String length + Tested if it still works. Text was: **321# interrogateSS CFU text..'' code 33 Testing parsing a USSD request and truncated versions
