Sane sanitization
This commit is contained in:
@@ -1,6 +1,7 @@
|
||||
#include "TypeConversions.h"
|
||||
#include "mesh/generated/meshtastic/deviceonly.pb.h"
|
||||
#include "mesh/generated/meshtastic/mesh.pb.h"
|
||||
#include "meshUtils.h"
|
||||
|
||||
meshtastic_NodeInfo TypeConversions::ConvertToNodeInfo(const meshtastic_NodeInfoLite *lite)
|
||||
{
|
||||
@@ -82,8 +83,10 @@ meshtastic_UserLite TypeConversions::ConvertToUserLite(meshtastic_User user)
|
||||
|
||||
strncpy(lite.long_name, user.long_name, sizeof(lite.long_name));
|
||||
lite.long_name[sizeof(lite.long_name) - 1] = '\0';
|
||||
sanitizeUtf8(lite.long_name, sizeof(lite.long_name));
|
||||
strncpy(lite.short_name, user.short_name, sizeof(lite.short_name));
|
||||
lite.short_name[sizeof(lite.short_name) - 1] = '\0';
|
||||
sanitizeUtf8(lite.short_name, sizeof(lite.short_name));
|
||||
lite.hw_model = user.hw_model;
|
||||
lite.role = user.role;
|
||||
lite.is_licensed = user.is_licensed;
|
||||
@@ -102,8 +105,10 @@ meshtastic_User TypeConversions::ConvertToUser(uint32_t nodeNum, meshtastic_User
|
||||
snprintf(user.id, sizeof(user.id), "!%08x", nodeNum);
|
||||
strncpy(user.long_name, lite.long_name, sizeof(user.long_name));
|
||||
user.long_name[sizeof(user.long_name) - 1] = '\0';
|
||||
sanitizeUtf8(user.long_name, sizeof(user.long_name));
|
||||
strncpy(user.short_name, lite.short_name, sizeof(user.short_name));
|
||||
user.short_name[sizeof(user.short_name) - 1] = '\0';
|
||||
sanitizeUtf8(user.short_name, sizeof(user.short_name));
|
||||
user.hw_model = lite.hw_model;
|
||||
user.role = lite.role;
|
||||
user.is_licensed = lite.is_licensed;
|
||||
|
||||
@@ -117,4 +117,93 @@ size_t pb_string_length(const char *str, size_t max_len)
|
||||
}
|
||||
}
|
||||
return len;
|
||||
}
|
||||
|
||||
bool sanitizeUtf8(char *buf, size_t bufSize)
|
||||
{
|
||||
if (!buf || bufSize == 0)
|
||||
return false;
|
||||
|
||||
// Ensure null-terminated within buffer
|
||||
buf[bufSize - 1] = '\0';
|
||||
|
||||
bool replaced = false;
|
||||
size_t i = 0;
|
||||
size_t len = strlen(buf);
|
||||
|
||||
while (i < len) {
|
||||
uint8_t b = (uint8_t)buf[i];
|
||||
|
||||
// Determine expected sequence length from lead byte
|
||||
size_t seqLen;
|
||||
uint32_t minCodepoint;
|
||||
if (b <= 0x7F) {
|
||||
// ASCII — valid single byte
|
||||
i++;
|
||||
continue;
|
||||
} else if ((b & 0xE0) == 0xC0) {
|
||||
seqLen = 2;
|
||||
minCodepoint = 0x80; // Reject overlong
|
||||
} else if ((b & 0xF0) == 0xE0) {
|
||||
seqLen = 3;
|
||||
minCodepoint = 0x800;
|
||||
} else if ((b & 0xF8) == 0xF0) {
|
||||
seqLen = 4;
|
||||
minCodepoint = 0x10000;
|
||||
} else {
|
||||
// Invalid lead byte (0x80-0xBF or 0xF8+)
|
||||
buf[i] = '?';
|
||||
replaced = true;
|
||||
i++;
|
||||
continue;
|
||||
}
|
||||
|
||||
// Check that we have enough bytes remaining
|
||||
if (i + seqLen > len) {
|
||||
// Truncated sequence at end of string — replace remaining bytes
|
||||
for (size_t j = i; j < len; j++) {
|
||||
buf[j] = '?';
|
||||
}
|
||||
replaced = true;
|
||||
break;
|
||||
}
|
||||
|
||||
// Validate continuation bytes (must be 10xxxxxx)
|
||||
bool valid = true;
|
||||
for (size_t j = 1; j < seqLen; j++) {
|
||||
if (((uint8_t)buf[i + j] & 0xC0) != 0x80) {
|
||||
valid = false;
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
if (valid) {
|
||||
// Decode codepoint to check for overlong encodings and surrogates
|
||||
uint32_t cp = 0;
|
||||
if (seqLen == 2)
|
||||
cp = b & 0x1F;
|
||||
else if (seqLen == 3)
|
||||
cp = b & 0x0F;
|
||||
else
|
||||
cp = b & 0x07;
|
||||
for (size_t j = 1; j < seqLen; j++)
|
||||
cp = (cp << 6) | ((uint8_t)buf[i + j] & 0x3F);
|
||||
|
||||
if (cp < minCodepoint || cp > 0x10FFFF || (cp >= 0xD800 && cp <= 0xDFFF)) {
|
||||
// Overlong encoding, out of Unicode range, or surrogate half
|
||||
valid = false;
|
||||
}
|
||||
}
|
||||
|
||||
if (valid) {
|
||||
i += seqLen;
|
||||
} else {
|
||||
// Replace only the lead byte; continuation bytes will be caught on next iteration
|
||||
buf[i] = '?';
|
||||
replaced = true;
|
||||
i++;
|
||||
}
|
||||
}
|
||||
|
||||
return replaced;
|
||||
}
|
||||
@@ -38,6 +38,10 @@ const std::string vformat(const char *const zcFormat, ...);
|
||||
// Get actual string length for nanopb char array fields.
|
||||
size_t pb_string_length(const char *str, size_t max_len);
|
||||
|
||||
// Sanitize a fixed-size char buffer in-place by replacing invalid UTF-8 sequences with '?'.
|
||||
// Ensures the result is null-terminated within bufSize. Returns true if any bytes were replaced.
|
||||
bool sanitizeUtf8(char *buf, size_t bufSize);
|
||||
|
||||
/// Calculate 2^n without calling pow() - used for spreading factor and other calculations
|
||||
inline uint32_t pow_of_2(uint32_t n)
|
||||
{
|
||||
|
||||
@@ -599,10 +599,14 @@ void AdminModule::handleSetOwner(const meshtastic_User &o)
|
||||
if (*o.long_name) {
|
||||
changed |= strcmp(owner.long_name, o.long_name);
|
||||
strncpy(owner.long_name, o.long_name, sizeof(owner.long_name));
|
||||
owner.long_name[sizeof(owner.long_name) - 1] = '\0';
|
||||
sanitizeUtf8(owner.long_name, sizeof(owner.long_name));
|
||||
}
|
||||
if (*o.short_name) {
|
||||
changed |= strcmp(owner.short_name, o.short_name);
|
||||
strncpy(owner.short_name, o.short_name, sizeof(owner.short_name));
|
||||
owner.short_name[sizeof(owner.short_name) - 1] = '\0';
|
||||
sanitizeUtf8(owner.short_name, sizeof(owner.short_name));
|
||||
}
|
||||
snprintf(owner.id, sizeof(owner.id), "!%08x", nodeDB->getNodeNum());
|
||||
|
||||
@@ -1400,7 +1404,11 @@ void AdminModule::handleSetHamMode(const meshtastic_HamParameters &p)
|
||||
|
||||
// Set call sign and override lora limitations for licensed use
|
||||
strncpy(owner.long_name, p.call_sign, sizeof(owner.long_name));
|
||||
owner.long_name[sizeof(owner.long_name) - 1] = '\0';
|
||||
sanitizeUtf8(owner.long_name, sizeof(owner.long_name));
|
||||
strncpy(owner.short_name, p.short_name, sizeof(owner.short_name));
|
||||
owner.short_name[sizeof(owner.short_name) - 1] = '\0';
|
||||
sanitizeUtf8(owner.short_name, sizeof(owner.short_name));
|
||||
owner.is_licensed = true;
|
||||
config.lora.override_duty_cycle = true;
|
||||
config.lora.tx_power = p.tx_power;
|
||||
|
||||
Reference in New Issue
Block a user