5 Commits
Author SHA1 Message Date
Oliver Hartkopp cbbad5eede lib: parse_canframe: guard delimiter reads with length checks
As Alex J pointed out in comment
https://github.com/linux-can/can-utils/issues/632#issuecomment-5746692502
the delimiters to detect CAN CC/FD/XL frames were read from the input
data without checking the length of that input data. This could lead
to an out-of-bounds read and to unintended detection of incorrect content.

Add a length check before reading those delimiters and also add/change
some comments to clarify the reasons for some assignments.

Reported-by: Alex J <jipaionut@gmail.com>
Signed-off-by: Oliver Hartkopp <socketcan@hartkopp.net>
2026-09-20 21:44:32 +02:00
Oleksij RempelandGitHub 95aae6bf83 Merge pull request #626 from SamantazFox/patch-1
J1939: VP1/VP2 PG fixes
2026-05-12 15:48:35 +02:00
Oleksij RempelandOliver Hartkopp bf5fe736c3 canlogserver: fix infinite loops during signal handling
Fix infinite loops that prevent graceful termination when the server
receives SIGINT or SIGTERM signals. Without this fix, Ctrl-C and kill
commands are ignored, making it impossible to stop the server cleanly.

Two scenarios cause the infinite loops:

1) The bind() retry loop: When the port is busy, the loop retries
   indefinitely without checking the running flag set by the signal
   handler.

2) The accept() loop: The loop is unconditional, so when accept() is
   interrupted by a signal and returns EINTR, the loop immediately
   restarts, ignoring the shutdown request.

Signed-off-by: Oleksij Rempel <linux@rempel-privat.de>
2026-05-12 10:22:48 +02:00
Marc Kleine-BuddeandGitHub 14245b7c79 Merge pull request #627 from SamantazFox/patch-2
J1939: Handle localtime_r() failure in TD PG
2026-05-11 10:16:48 +02:00
Samantaz Fox d5cb91c8ea Handle localtime_r() failure in j1939 timedate
When the call to localtime_r() fails (by returning NULL, as per the POSIX specification), make sure to fill the hour/minute offsets with the fallback values as specified in the J1939DA supporting information.
2026-05-08 17:00:31 +02:00
3 changed files with 57 additions and 23 deletions
+25 -3
View File
@@ -177,7 +177,8 @@ int main(int argc, char **argv)
sigset_t sigset; sigset_t sigset;
fd_set rdfs; fd_set rdfs;
int s[MAXDEV]; int s[MAXDEV];
int socki, accsocket; int socki;
int accsocket = -1;
canid_t mask[MAXDEV] = {0}; canid_t mask[MAXDEV] = {0};
canid_t value[MAXDEV] = {0}; canid_t value[MAXDEV] = {0};
int inv_filter[MAXDEV] = {0}; int inv_filter[MAXDEV] = {0};
@@ -286,7 +287,7 @@ int main(int argc, char **argv)
inaddr.sin_addr.s_addr = htonl(INADDR_ANY); inaddr.sin_addr.s_addr = htonl(INADDR_ANY);
inaddr.sin_port = htons(port); inaddr.sin_port = htons(port);
while(bind(socki, (struct sockaddr*)&inaddr, sizeof(inaddr)) < 0) { while(running && bind(socki, (struct sockaddr*)&inaddr, sizeof(inaddr)) < 0) {
struct timespec f = { struct timespec f = {
.tv_nsec = 100 * 1000 * 1000, .tv_nsec = 100 * 1000 * 1000,
}; };
@@ -295,18 +296,28 @@ int main(int argc, char **argv)
nanosleep(&f, NULL); nanosleep(&f, NULL);
} }
/*
* Check if loop exited due to signal (during nanosleep) rather than
* successful bind.
*/
if (!running) {
close(socki);
return 128 + signal_num;
}
if (listen(socki, 3) != 0) { if (listen(socki, 3) != 0) {
perror("listen"); perror("listen");
exit(1); exit(1);
} }
while(1) { while(running) {
accsocket = accept(socki, (struct sockaddr*)&clientaddr, &sin_size); accsocket = accept(socki, (struct sockaddr*)&clientaddr, &sin_size);
if (accsocket > 0) { if (accsocket > 0) {
//printf("accepted\n"); //printf("accepted\n");
if (!fork()) if (!fork())
break; break;
close(accsocket); close(accsocket);
accsocket = -1;
} }
else if (errno != EINTR) { else if (errno != EINTR) {
perror("accept"); perror("accept");
@@ -314,6 +325,17 @@ int main(int argc, char **argv)
} }
} }
/*
* Check if loop exited due to signal (accept returned EINTR) rather
* than successful fork
*/
if (!running) {
if (accsocket > 0)
close(accsocket);
close(socki);
return 128 + signal_num;
}
for (i=0; i<currmax; i++) { for (i=0; i<currmax; i++) {
pr_debug("open %d '%s' m%08X v%08X i%d e%d.\n", pr_debug("open %d '%s' m%08X v%08X i%d e%d.\n",
+15 -9
View File
@@ -41,16 +41,22 @@ static void gmtime_to_j1939_pgn_65254_td(struct j1939_time_date_packet *tdp)
utc_tm = gmtime_r(&now, &utc_tm_buf); utc_tm = gmtime_r(&now, &utc_tm_buf);
local_tm = localtime_r(&now, &local_tm_buf); local_tm = localtime_r(&now, &local_tm_buf);
/* Calculate the offsets */ if (local_tm) {
hour_offset = local_tm->tm_hour - utc_tm->tm_hour; /* Calculate the offsets */
minute_offset = local_tm->tm_min - utc_tm->tm_min; hour_offset = local_tm->tm_hour - utc_tm->tm_hour;
minute_offset = local_tm->tm_min - utc_tm->tm_min;
/* Handle date rollover */ /* Handle date rollover */
if (local_tm->tm_mday != utc_tm->tm_mday) { if (local_tm->tm_mday != utc_tm->tm_mday) {
if (local_tm->tm_hour < 12) if (local_tm->tm_hour < 12)
hour_offset += 24; /* past midnight */ hour_offset += 24; /* past midnight */
else else
hour_offset -= 24; /* before midnight */ hour_offset -= 24; /* before midnight */
}
} else {
/* The local time offsets cannot be determined at the moment */
hour_offset = 0xF9;
minute_offset = 0xFF;
} }
/* /*
+16 -10
View File
@@ -170,21 +170,23 @@ int parse_canframe(char *cs, union cfu *cu)
memset(cu, 0, sizeof(*cu)); /* init CAN CC/FD/XL frame, e.g. LEN = 0 */ memset(cu, 0, sizeof(*cu)); /* init CAN CC/FD/XL frame, e.g. LEN = 0 */
if (len < 4) if (len >= 4 && cs[3] == CANID_DELIM) { /* 3 digits SFF CAN ID */
return 0;
if (cs[3] == CANID_DELIM) { /* 3 digits SFF */ idx = 4; /* start of frame data */
idx = 4; /* get 3 digits SFF CAN ID value */
for (i = 0; i < 3; i++) { for (i = 0; i < 3; i++) {
if ((tmp = asc2nibble(cs[i])) > 0x0F) if ((tmp = asc2nibble(cs[i])) > 0x0F)
return 0; return 0;
cu->cc.can_id |= tmp << (2 - i) * 4; cu->cc.can_id |= tmp << (2 - i) * 4;
} }
} else if (cs[5] == CANID_DELIM) { /* 5 digits CAN XL VCID/PRIO*/ } else if (len >= 21 && cs[5] == CANID_DELIM && cs[20] == CANID_DELIM) {
/* 5 digits CAN XL VCID/PRIO - but also check for 2nd '#' here */
idx = 6; idx = 6; /* start of CAN XL frame extra content (AF, SDT, etc) */
/* get 5 digits CAN XL VCID/PRIO */
for (i = 0; i < 5; i++) { for (i = 0; i < 5; i++) {
if ((tmp = asc2nibble(cs[i])) > 0x0F) if ((tmp = asc2nibble(cs[i])) > 0x0F)
return 0; return 0;
@@ -196,9 +198,11 @@ int parse_canframe(char *cs, union cfu *cu)
cu->xl.prio &= CANXL_PRIO_MASK; cu->xl.prio &= CANXL_PRIO_MASK;
cu->xl.prio |= tmp; cu->xl.prio |= tmp;
} else if (cs[8] == CANID_DELIM) { /* 8 digits EFF */ } else if (len >= 9 && cs[8] == CANID_DELIM) { /* 8 digits EFF CAN ID */
idx = 9; idx = 9; /* start of frame data */
/* get 8 digits EFF CAN ID value */
for (i = 0; i < 8; i++) { for (i = 0; i < 8; i++) {
if ((tmp = asc2nibble(cs[i])) > 0x0F) if ((tmp = asc2nibble(cs[i])) > 0x0F)
return 0; return 0;
@@ -239,11 +243,12 @@ int parse_canframe(char *cs, union cfu *cu)
cu->fd.flags |= CANFD_FDF; /* dual-use */ cu->fd.flags |= CANFD_FDF; /* dual-use */
idx += 2; idx += 2;
} else if (cs[idx + 14] == CANID_DELIM) { /* CAN XL frame '#80:00:11223344#' */ } else if (idx == 6) { /* CAN XL frame extra content '#80:00:11223344#' */
maxdlen = CANXL_MAX_DLEN; maxdlen = CANXL_MAX_DLEN;
mtu = CANXL_MTU; mtu = CANXL_MTU;
data = cu->xl.data; /* fill CAN XL data */ data = cu->xl.data; /* overwrite pointer to CAN XL data */
/* get CAN XL frame extra content */
if ((cs[idx + 2] != XL_HDR_DELIM) || (cs[idx + 5] != XL_HDR_DELIM)) if ((cs[idx + 2] != XL_HDR_DELIM) || (cs[idx + 5] != XL_HDR_DELIM))
return 0; return 0;
@@ -277,6 +282,7 @@ int parse_canframe(char *cs, union cfu *cu)
idx++; /* skip CANID_DELIM */ idx++; /* skip CANID_DELIM */
} }
/* copy CAN frame data content */
for (i = 0, dlen = 0; i < maxdlen; i++) { for (i = 0, dlen = 0; i < maxdlen; i++) {
if (cs[idx] == DATA_SEPERATOR) /* skip (optional) separator */ if (cs[idx] == DATA_SEPERATOR) /* skip (optional) separator */
idx++; idx++;