9 Commits
Author SHA1 Message Date
Oliver Hartkopp cbbad5eede lib: parse_canframe: guard delimiter reads with length checks
As Alex J pointed out in comment
https://github.com/linux-can/can-utils/issues/632#issuecomment-5746692502
the delimiters to detect CAN CC/FD/XL frames were read from the input
data without checking the length of that input data. This could lead
to an out-of-bounds read and to unintended detection of incorrect content.

Add a length check before reading those delimiters and also add/change
some comments to clarify the reasons for some assignments.

Reported-by: Alex J <jipaionut@gmail.com>
Signed-off-by: Oliver Hartkopp <socketcan@hartkopp.net>
2026-09-20 21:44:32 +02:00
Oleksij RempelandGitHub 95aae6bf83 Merge pull request #626 from SamantazFox/patch-1
J1939: VP1/VP2 PG fixes
2026-05-12 15:48:35 +02:00
Oleksij RempelandOliver Hartkopp bf5fe736c3 canlogserver: fix infinite loops during signal handling
Fix infinite loops that prevent graceful termination when the server
receives SIGINT or SIGTERM signals. Without this fix, Ctrl-C and kill
commands are ignored, making it impossible to stop the server cleanly.

Two scenarios cause the infinite loops:

1) The bind() retry loop: When the port is busy, the loop retries
   indefinitely without checking the running flag set by the signal
   handler.

2) The accept() loop: The loop is unconditional, so when accept() is
   interrupted by a signal and returns EINTR, the loop immediately
   restarts, ignoring the shutdown request.

Signed-off-by: Oleksij Rempel <linux@rempel-privat.de>
2026-05-12 10:22:48 +02:00
Marc Kleine-BuddeandGitHub 14245b7c79 Merge pull request #627 from SamantazFox/patch-2
J1939: Handle localtime_r() failure in TD PG
2026-05-11 10:16:48 +02:00
Samantaz Fox 90383a0cca Fill unassigned bytes with 0xFF in J1939 VP2 2026-05-08 17:18:03 +02:00
Samantaz Fox d5cb91c8ea Handle localtime_r() failure in j1939 timedate
When the call to localtime_r() fails (by returning NULL, as per the POSIX specification), make sure to fill the hour/minute offsets with the fallback values as specified in the J1939DA supporting information.
2026-05-08 17:00:31 +02:00
Samantaz FoxandGitHub 9743a2ffcf Add j1939 VP2 details
Add 3 missing unused bytes (for a message len of 8) to the j1939 VP2 struct, as well as range information for the existing parameters.
2026-05-05 20:56:39 +00:00
Samantaz FoxandGitHub d5ed23583c Update j1939 VP1 parameters ranges
Lat/longitude parameters have a range of -210 to +211.1081215
2026-05-05 20:48:33 +00:00
Samantaz FoxandGitHub 60301896d1 Update j1939 VP1 repetition rate
Since J1939DA:SEP2015, the repetition rate of VP1 has been changed to 1s.
2026-05-05 20:44:47 +00:00
5 changed files with 80 additions and 34 deletions
+25 -3
View File
@@ -177,7 +177,8 @@ int main(int argc, char **argv)
sigset_t sigset; sigset_t sigset;
fd_set rdfs; fd_set rdfs;
int s[MAXDEV]; int s[MAXDEV];
int socki, accsocket; int socki;
int accsocket = -1;
canid_t mask[MAXDEV] = {0}; canid_t mask[MAXDEV] = {0};
canid_t value[MAXDEV] = {0}; canid_t value[MAXDEV] = {0};
int inv_filter[MAXDEV] = {0}; int inv_filter[MAXDEV] = {0};
@@ -286,7 +287,7 @@ int main(int argc, char **argv)
inaddr.sin_addr.s_addr = htonl(INADDR_ANY); inaddr.sin_addr.s_addr = htonl(INADDR_ANY);
inaddr.sin_port = htons(port); inaddr.sin_port = htons(port);
while(bind(socki, (struct sockaddr*)&inaddr, sizeof(inaddr)) < 0) { while(running && bind(socki, (struct sockaddr*)&inaddr, sizeof(inaddr)) < 0) {
struct timespec f = { struct timespec f = {
.tv_nsec = 100 * 1000 * 1000, .tv_nsec = 100 * 1000 * 1000,
}; };
@@ -295,18 +296,28 @@ int main(int argc, char **argv)
nanosleep(&f, NULL); nanosleep(&f, NULL);
} }
/*
* Check if loop exited due to signal (during nanosleep) rather than
* successful bind.
*/
if (!running) {
close(socki);
return 128 + signal_num;
}
if (listen(socki, 3) != 0) { if (listen(socki, 3) != 0) {
perror("listen"); perror("listen");
exit(1); exit(1);
} }
while(1) { while(running) {
accsocket = accept(socki, (struct sockaddr*)&clientaddr, &sin_size); accsocket = accept(socki, (struct sockaddr*)&clientaddr, &sin_size);
if (accsocket > 0) { if (accsocket > 0) {
//printf("accepted\n"); //printf("accepted\n");
if (!fork()) if (!fork())
break; break;
close(accsocket); close(accsocket);
accsocket = -1;
} }
else if (errno != EINTR) { else if (errno != EINTR) {
perror("accept"); perror("accept");
@@ -314,6 +325,17 @@ int main(int argc, char **argv)
} }
} }
/*
* Check if loop exited due to signal (accept returned EINTR) rather
* than successful fork
*/
if (!running) {
if (accsocket > 0)
close(accsocket);
close(socki);
return 128 + signal_num;
}
for (i=0; i<currmax; i++) { for (i=0; i<currmax; i++) {
pr_debug("open %d '%s' m%08X v%08X i%d e%d.\n", pr_debug("open %d '%s' m%08X v%08X i%d e%d.\n",
+6
View File
@@ -41,6 +41,7 @@ static void gmtime_to_j1939_pgn_65254_td(struct j1939_time_date_packet *tdp)
utc_tm = gmtime_r(&now, &utc_tm_buf); utc_tm = gmtime_r(&now, &utc_tm_buf);
local_tm = localtime_r(&now, &local_tm_buf); local_tm = localtime_r(&now, &local_tm_buf);
if (local_tm) {
/* Calculate the offsets */ /* Calculate the offsets */
hour_offset = local_tm->tm_hour - utc_tm->tm_hour; hour_offset = local_tm->tm_hour - utc_tm->tm_hour;
minute_offset = local_tm->tm_min - utc_tm->tm_min; minute_offset = local_tm->tm_min - utc_tm->tm_min;
@@ -52,6 +53,11 @@ static void gmtime_to_j1939_pgn_65254_td(struct j1939_time_date_packet *tdp)
else else
hour_offset -= 24; /* before midnight */ hour_offset -= 24; /* before midnight */
} }
} else {
/* The local time offsets cannot be determined at the moment */
hour_offset = 0xF9;
minute_offset = 0xFF;
}
/* /*
* Seconds (spn959): * Seconds (spn959):
@@ -51,7 +51,7 @@ struct j1939_vp_err_msg {
#define J1939_VP1_PRIO_DEFAULT 6 #define J1939_VP1_PRIO_DEFAULT 6
#define J1939_VP1_MAX_TRANSFER_LENGH \ #define J1939_VP1_MAX_TRANSFER_LENGH \
sizeof(struct j1939_vp1_packet) sizeof(struct j1939_vp1_packet)
#define J1939_VP1_REPETITION_RATE_MS 5000 #define J1939_VP1_REPETITION_RATE_MS 1000
#define J1939_VP1_JITTER_MS 500 #define J1939_VP1_JITTER_MS 500
/** /**
@@ -63,8 +63,8 @@ struct j1939_vp_err_msg {
* - Data Length: 4 bytes * - Data Length: 4 bytes
* - Resolution: 10^-7 deg/bit * - Resolution: 10^-7 deg/bit
* - Offset: -210 degrees * - Offset: -210 degrees
* - Range: -210 to +211.1008122 degrees * - Range: -210 to +211.10081215 degrees
* - Operating Range: -210 degrees (SOUTH) to +211.108122 degrees * - Operating Range: -210 degrees (SOUTH) to +211.1081215 degrees
* (NORTH) * (NORTH)
* *
* @longitude: Raw longitude position of the vehicle * @longitude: Raw longitude position of the vehicle
@@ -72,8 +72,8 @@ struct j1939_vp_err_msg {
* - Data Length: 4 bytes * - Data Length: 4 bytes
* - Resolution: 10^-7 deg/bit * - Resolution: 10^-7 deg/bit
* - Offset: -210 degrees * - Offset: -210 degrees
* - Range: -210 to +211.1008122 degrees * - Range: -210 to +211.10081215 degrees
* - Operating Range: -210 degrees (WEST) to +211.108122 degrees * - Operating Range: -210 degrees (WEST) to +211.1081215 degrees
* (EAST) * (EAST)
* *
* This structure defines each component of the Vehicle Position as described in * This structure defines each component of the Vehicle Position as described in
@@ -142,32 +142,35 @@ j1939_vp1_set_longitude(struct j1939_vp1_packet *packet, int32_t longitude)
/** /**
* struct j1939_vp2_packet - Represents the PGN 64502 Vehicle * struct j1939_vp2_packet - Represents the PGN 64502 Vehicle
* Position 2 packet * Position 2 packet
* FIXME: current packet layout is guessed based on limited information:
* https://www.isobus.net/isobus/pGNAndSPN/10801?type=PGN
* *
* @total_satellites: Total number of satellites in view * @total_satellites: Total number of satellites in view
* - SPN: 8128 * - SPN: 8128
* - Data Length: 1 byte * - Data Length: 1 byte
* - Range: 0 to 250
* *
* @hdop: Horizontal dilution of precision * @hdop: Horizontal dilution of precision
* - SPN: 8129 * - SPN: 8129
* - Data Length: 1 byte * - Data Length: 1 byte
* - Resolution: 0.1 * - Resolution: 0.1
* - Range: 0.0 to 25.0
* *
* @vdop: Vertical dilution of precision * @vdop: Vertical dilution of precision
* - SPN: 8130 * - SPN: 8130
* - Data Length: 1 byte * - Data Length: 1 byte
* - Resolution: 0.1 * - Resolution: 0.1
* - Range: 0.0 to 25.0
* *
* @pdop: Position dilution of precision * @pdop: Position dilution of precision
* - SPN: 8131 * - SPN: 8131
* - Data Length: 1 byte * - Data Length: 1 byte
* - Resolution: 0.1 * - Resolution: 0.1
* - Range: 0.0 to 25.0
* *
* @tdop: Time dilution of precision * @tdop: Time dilution of precision
* - SPN: 8132 * - SPN: 8132
* - Data Length: 1 byte * - Data Length: 1 byte
* - Resolution: 0.1 * - Resolution: 0.1
* - Range: 0.0 to 25.0
* *
* This structure defines each component of the Vehicle Position 2 as described * This structure defines each component of the Vehicle Position 2 as described
* in PGN 64502. * in PGN 64502.
@@ -178,6 +181,9 @@ struct j1939_vp2_packet {
uint8_t vdop; /* SPN 8130 */ uint8_t vdop; /* SPN 8130 */
uint8_t pdop; /* SPN 8131 */ uint8_t pdop; /* SPN 8131 */
uint8_t tdop; /* SPN 8132 */ uint8_t tdop; /* SPN 8132 */
uint8_t unused5; /* Always 0xFF */
uint8_t unused6; /* Always 0xFF */
uint8_t unused7; /* Always 0xFF */
} __attribute__((__packed__)); } __attribute__((__packed__));
/** /**
@@ -270,6 +270,12 @@ static int j1939_vp2_get_data(struct j1939_vp_srv_priv *priv,
j1939_vp2_set_pdop(vp2p, pdop); j1939_vp2_set_pdop(vp2p, pdop);
j1939_vp2_set_tdop(vp2p, tdop); j1939_vp2_set_tdop(vp2p, tdop);
/* This PG's last 3 bytes are not assigned and hence must be set
* to 0xFF as per J1939-71, section 5.2 */
vp2p->unused5 = 0xFF;
vp2p->unused6 = 0xFF;
vp2p->unused7 = 0xFF;
return 0; return 0;
} }
+16 -10
View File
@@ -170,21 +170,23 @@ int parse_canframe(char *cs, union cfu *cu)
memset(cu, 0, sizeof(*cu)); /* init CAN CC/FD/XL frame, e.g. LEN = 0 */ memset(cu, 0, sizeof(*cu)); /* init CAN CC/FD/XL frame, e.g. LEN = 0 */
if (len < 4) if (len >= 4 && cs[3] == CANID_DELIM) { /* 3 digits SFF CAN ID */
return 0;
if (cs[3] == CANID_DELIM) { /* 3 digits SFF */ idx = 4; /* start of frame data */
idx = 4; /* get 3 digits SFF CAN ID value */
for (i = 0; i < 3; i++) { for (i = 0; i < 3; i++) {
if ((tmp = asc2nibble(cs[i])) > 0x0F) if ((tmp = asc2nibble(cs[i])) > 0x0F)
return 0; return 0;
cu->cc.can_id |= tmp << (2 - i) * 4; cu->cc.can_id |= tmp << (2 - i) * 4;
} }
} else if (cs[5] == CANID_DELIM) { /* 5 digits CAN XL VCID/PRIO*/ } else if (len >= 21 && cs[5] == CANID_DELIM && cs[20] == CANID_DELIM) {
/* 5 digits CAN XL VCID/PRIO - but also check for 2nd '#' here */
idx = 6; idx = 6; /* start of CAN XL frame extra content (AF, SDT, etc) */
/* get 5 digits CAN XL VCID/PRIO */
for (i = 0; i < 5; i++) { for (i = 0; i < 5; i++) {
if ((tmp = asc2nibble(cs[i])) > 0x0F) if ((tmp = asc2nibble(cs[i])) > 0x0F)
return 0; return 0;
@@ -196,9 +198,11 @@ int parse_canframe(char *cs, union cfu *cu)
cu->xl.prio &= CANXL_PRIO_MASK; cu->xl.prio &= CANXL_PRIO_MASK;
cu->xl.prio |= tmp; cu->xl.prio |= tmp;
} else if (cs[8] == CANID_DELIM) { /* 8 digits EFF */ } else if (len >= 9 && cs[8] == CANID_DELIM) { /* 8 digits EFF CAN ID */
idx = 9; idx = 9; /* start of frame data */
/* get 8 digits EFF CAN ID value */
for (i = 0; i < 8; i++) { for (i = 0; i < 8; i++) {
if ((tmp = asc2nibble(cs[i])) > 0x0F) if ((tmp = asc2nibble(cs[i])) > 0x0F)
return 0; return 0;
@@ -239,11 +243,12 @@ int parse_canframe(char *cs, union cfu *cu)
cu->fd.flags |= CANFD_FDF; /* dual-use */ cu->fd.flags |= CANFD_FDF; /* dual-use */
idx += 2; idx += 2;
} else if (cs[idx + 14] == CANID_DELIM) { /* CAN XL frame '#80:00:11223344#' */ } else if (idx == 6) { /* CAN XL frame extra content '#80:00:11223344#' */
maxdlen = CANXL_MAX_DLEN; maxdlen = CANXL_MAX_DLEN;
mtu = CANXL_MTU; mtu = CANXL_MTU;
data = cu->xl.data; /* fill CAN XL data */ data = cu->xl.data; /* overwrite pointer to CAN XL data */
/* get CAN XL frame extra content */
if ((cs[idx + 2] != XL_HDR_DELIM) || (cs[idx + 5] != XL_HDR_DELIM)) if ((cs[idx + 2] != XL_HDR_DELIM) || (cs[idx + 5] != XL_HDR_DELIM))
return 0; return 0;
@@ -277,6 +282,7 @@ int parse_canframe(char *cs, union cfu *cu)
idx++; /* skip CANID_DELIM */ idx++; /* skip CANID_DELIM */
} }
/* copy CAN frame data content */
for (i = 0, dlen = 0; i < maxdlen; i++) { for (i = 0, dlen = 0; i < maxdlen; i++) {
if (cs[idx] == DATA_SEPERATOR) /* skip (optional) separator */ if (cs[idx] == DATA_SEPERATOR) /* skip (optional) separator */
idx++; idx++;