Skip to content

fix: address out-of-bounds read in lighting_command_decode and add bounds checking tests - #1412

Merged
skarg merged 4 commits into
masterfrom
bugfix/lighting-command-decoder-out-of-bounds-read
Jun 28, 2026
Merged

fix: address out-of-bounds read in lighting_command_decode and add bounds checking tests#1412
skarg merged 4 commits into
masterfrom
bugfix/lighting-command-decoder-out-of-bounds-read

Conversation

@skarg

@skarg skarg commented Jun 28, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR hardens BACnet Lighting Command APDU decoding by fixing a bounds/remaining-length bug in lighting_command_decode() and adds a Zephyr ztest regression test intended to exercise truncation scenarios.

Changes:

  • Update nested decode calls in lighting_command_decode() to pass the remaining buffer length (apdu_size - apdu_len) to prevent out-of-bounds reads.
  • Add a new ztest that iteratively truncates encoded lighting commands and decodes them to validate bounds behavior.
  • Register the new test in the existing lighting ztest suite (legacy API path).

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 4 comments.

File Description
src/bacnet/lighting.c Fix remaining-length propagation in lighting_command_decode() for operation-dependent nested decodes.
test/bacnet/lighting/src/main.c Add truncation/bounds-checking test coverage for lighting_command_decode() and wire it into the suite.

Comment thread test/bacnet/lighting/src/main.c Outdated
Comment thread test/bacnet/lighting/src/main.c
Comment thread src/bacnet/lighting.c
Comment thread src/bacnet/lighting.c
skarg and others added 3 commits June 28, 2026 11:02
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@skarg
skarg merged commit 5afc5c9 into master Jun 28, 2026
36 checks passed
@skarg
skarg deleted the bugfix/lighting-command-decoder-out-of-bounds-read branch June 28, 2026 16:27
skarg added a commit that referenced this pull request Jul 2, 2026
…unds checking tests (#1412)

* fix: address out-of-bounds read in lighting_command_decode and add bounds checking tests

* fix: FADE_TO and RAMP_TO required levels in lighting_command_decode
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants