21 Commits
Author SHA1 Message Date
Oliver Hartkopp cbbad5eede lib: parse_canframe: guard delimiter reads with length checks
As Alex J pointed out in comment
https://github.com/linux-can/can-utils/issues/632#issuecomment-5746692502
the delimiters to detect CAN CC/FD/XL frames were read from the input
data without checking the length of that input data. This could lead
to an out-of-bounds read and to unintended detection of incorrect content.

Add a length check before reading those delimiters and also add/change
some comments to clarify the reasons for some assignments.

Reported-by: Alex J <jipaionut@gmail.com>
Signed-off-by: Oliver Hartkopp <socketcan@hartkopp.net>
2026-09-20 21:44:32 +02:00
Oleksij RempelandGitHub 95aae6bf83 Merge pull request #626 from SamantazFox/patch-1
J1939: VP1/VP2 PG fixes
2026-05-12 15:48:35 +02:00
Oleksij RempelandOliver Hartkopp bf5fe736c3 canlogserver: fix infinite loops during signal handling
Fix infinite loops that prevent graceful termination when the server
receives SIGINT or SIGTERM signals. Without this fix, Ctrl-C and kill
commands are ignored, making it impossible to stop the server cleanly.

Two scenarios cause the infinite loops:

1) The bind() retry loop: When the port is busy, the loop retries
   indefinitely without checking the running flag set by the signal
   handler.

2) The accept() loop: The loop is unconditional, so when accept() is
   interrupted by a signal and returns EINTR, the loop immediately
   restarts, ignoring the shutdown request.

Signed-off-by: Oleksij Rempel <linux@rempel-privat.de>
2026-05-12 10:22:48 +02:00
Marc Kleine-BuddeandGitHub 14245b7c79 Merge pull request #627 from SamantazFox/patch-2
J1939: Handle localtime_r() failure in TD PG
2026-05-11 10:16:48 +02:00
Samantaz Fox 90383a0cca Fill unassigned bytes with 0xFF in J1939 VP2 2026-05-08 17:18:03 +02:00
Samantaz Fox d5cb91c8ea Handle localtime_r() failure in j1939 timedate
When the call to localtime_r() fails (by returning NULL, as per the POSIX specification), make sure to fill the hour/minute offsets with the fallback values as specified in the J1939DA supporting information.
2026-05-08 17:00:31 +02:00
Samantaz FoxandGitHub 9743a2ffcf Add j1939 VP2 details
Add 3 missing unused bytes (for a message len of 8) to the j1939 VP2 struct, as well as range information for the existing parameters.
2026-05-05 20:56:39 +00:00
Samantaz FoxandGitHub d5ed23583c Update j1939 VP1 parameters ranges
Lat/longitude parameters have a range of -210 to +211.1081215
2026-05-05 20:48:33 +00:00
Samantaz FoxandGitHub 60301896d1 Update j1939 VP1 repetition rate
Since J1939DA:SEP2015, the repetition rate of VP1 has been changed to 1s.
2026-05-05 20:44:47 +00:00
Marc Kleine-BuddeandGitHub 99ab67143a Merge pull request #625 from marckleinebudde/bcmserver-fix-buffer-overflow
bcmserver: fix buffer overflow
2026-03-10 10:58:56 +01:00
Marc Kleine-Budde a0aeaed234 bcmserver: main(): rxmsg: increase buffer size to hold long network interface names
Message-ID: <DM6PR17MB28748DA25E52E1BD3EC593E6937AA@DM6PR17MB2874.namprd17.prod.outlook.com>
2026-03-10 10:46:12 +01:00
Marc Kleine-Budde 3cae8a449b bcmserver: main(): convert from sprintf() to snprintf() to avoid buffer overflow
Message-ID: <DM6PR17MB28748DA25E52E1BD3EC593E6937AA@DM6PR17MB2874.namprd17.prod.outlook.com>
2026-03-10 10:46:11 +01:00
Marc Kleine-BuddeandGitHub 44e6eb45e3 Merge pull request #624 from marckleinebudde/canerrsim-fix-buffer-overflow
canerrsim: main(): avoid buffer overflow: check length of interface name
2026-03-09 12:27:28 +01:00
Marc Kleine-Budde 9e444073b1 canerrsim: main(): avoid buffer overflow: check length of interface name
Closes: https://github.com/linux-can/can-utils/issues/623
2026-03-09 12:23:29 +01:00
Marc Kleine-Budde 9d4f3c82a2 canerrsim: add missing \n at end of error messages 2026-03-09 12:21:33 +01:00
Marc Kleine-Budde 7e8e247b2f canerrsim: convert from show_custom_format_and_exit() to err_exit() 2026-03-09 12:20:50 +01:00
Marc Kleine-Budde 3fe1c42bbf canerrsim: err_exit(): add support for printf style formats 2026-03-09 12:18:10 +01:00
Marc Kleine-BuddeandGitHub 1520ab5b98 Merge pull request #620 from marckleinebudde/mcp251xfd-fix-strchr
mcp251xfd: mcp251xfd_regmap_read(): don't assign return value of `strchr()` to `char *`
2026-03-04 11:38:43 +01:00
Marc Kleine-Budde aa902ae2af mcp251xfd: mcp251xfd_regmap_read(): don't assign return value of strchr() to char *
The `file_path` of `strchr(file_path, '/')` is a `const char *`. In this
case the `strchr()` in debian experimental returns a `const char *`,
leading to this error message:

```
mcp251xfd/mcp251xfd-regmap.c:75:13: error: assignment discards 'const' qualifier from pointer target type [-Werror=discarded-qualifiers]
   75 |         tmp = strchr(file_path, '/');
      |             ^
```

Fix the error by using the return value from `strchr()` directly in the
`if()`.

Link: https://github.com/linux-can/can-utils/actions/runs/22649777324/job/65679726209?pr=619
2026-03-04 11:35:38 +01:00
Marc Kleine-BuddeandGitHub a0b592178e Merge pull request #621 from marckleinebudde/remove-mips
github-actions: remove mips for now

Closes: https://github.com/linux-can/can-utils/issues/611
2026-03-04 11:34:12 +01:00
Marc Kleine-Budde 4f2fdecfba github-actions: remove mips for now
It's being phased out on Ubuntu rolling release.
2026-03-04 11:30:14 +01:00
9 changed files with 128 additions and 72 deletions
-8
View File
@@ -75,7 +75,6 @@ jobs:
gcc \
gcc-aarch64-linux-gnu \
gcc-arm-linux-gnueabihf \
gcc-mips-linux-gnu \
libgps-dev \
make
@@ -139,13 +138,6 @@ jobs:
podman exec -i stable cmake -DCMAKE_BUILD_TYPE=Debug -DCMAKE_TOOLCHAIN_FILE=cmake/${toolchain}.cmake -DENABLE_WERROR=ON -DENABLE_GPS=${gps} -B build-${toolchain}
podman exec -i stable cmake --build build-${toolchain}
- name: Configure & Build with mips-linux-gnu-gcc
env:
toolchain: mips-linux-gnu-gcc
run: |
podman exec -i stable cmake -DCMAKE_BUILD_TYPE=Debug -DCMAKE_TOOLCHAIN_FILE=cmake/${toolchain}.cmake -DENABLE_WERROR=ON -B build-${toolchain}
podman exec -i stable cmake --build build-${toolchain}
- name: Configure & Build with gcc (Makefile)
env:
cc: gcc
+28 -8
View File
@@ -153,7 +153,7 @@ int main(void)
char buf[MAXLEN];
char format[FORMATSZ];
char rxmsg[50];
char rxmsg[64];
#pragma GCC diagnostic push
#pragma GCC diagnostic ignored "-Wpragmas"
@@ -234,7 +234,7 @@ int main(void)
}
while (1) {
again:
FD_ZERO(&readfds);
FD_SET(sc, &readfds);
FD_SET(sa, &readfds);
@@ -242,6 +242,8 @@ int main(void)
select((sc > sa)?sc+1:sa+1, &readfds, NULL, NULL, NULL);
if (FD_ISSET(sc, &readfds)) {
size_t size = sizeof(rxmsg);
int len = 0, res;
recvfrom(sc, &msg, sizeof(msg), 0,
(struct sockaddr*)&caddr, &caddrlen);
@@ -249,17 +251,35 @@ int main(void)
ifr.ifr_ifindex = caddr.can_ifindex;
ioctl(sc, SIOCGIFNAME, &ifr);
sprintf(rxmsg, "< %s %03X %d ", ifr.ifr_name,
res = snprintf(rxmsg, size, "< %s %03X %d ", ifr.ifr_name,
msg.msg_head.can_id, msg.frame.can_dlc);
if (res < 0 || (size_t)res >= size) {
printf("Error: rxmsg buffer (size %zu) too small for data.\n", size);
continue;
}
for ( i = 0; i < msg.frame.can_dlc; i++)
sprintf(rxmsg + strlen(rxmsg), "%02X ",
msg.frame.data[i]);
len += res;
for (i = 0; i < msg.frame.can_dlc; i++) {
res = snprintf(rxmsg + len, size - len, "%02X ", msg.frame.data[i]);
if (res < 0 || (size_t)res >= (size - len)) {
printf("Error: rxmsg buffer (size %zu) too small for data.\n", size);
goto again;
}
len += res;
}
/* delimiter '\0' for Adobe(TM) Flash(TM) XML sockets */
strcat(rxmsg, ">\0");
res = snprintf(rxmsg + len, size - len, ">");
if (res < 0 || (size_t)res >= (size - len)) {
printf("Error: rxmsg buffer (size %zu) too small for data.\n", size);
continue;
}
send(sa, rxmsg, strlen(rxmsg) + 1, 0);
len += res;
send(sa, rxmsg, len + 1, 0);
}
+18 -19
View File
@@ -25,6 +25,7 @@
#include <linux/can/error.h>
#include <linux/can/raw.h>
#include <net/if.h>
#include <stdarg.h>
#include <stdbool.h>
#include <stdint.h>
#include <stdio.h>
@@ -122,27 +123,25 @@ void show_help_and_exit()
exit(EXIT_SUCCESS);
}
void err_exit(const char *msg)
void __attribute__((format (printf, 1, 2))) err_exit(const char *format, ...)
{
printf("%s", msg);
exit(EXIT_FAILURE);
}
va_list ap;
void show_custom_format_and_exit(const char *param, const char *format)
{
char str_buf[80];
sprintf(str_buf, format, param);
err_exit(str_buf);
va_start(ap, format);
vfprintf(stdout, format, ap);
va_end(ap);
exit(EXIT_FAILURE);
}
void show_invalid_option(const char *option)
{
show_custom_format_and_exit(option, "Error: Invalid option %s\n");
err_exit("Error: Invalid option %s\n", option);
}
void show_err_and_exit(const char *err_type)
{
show_custom_format_and_exit(err_type, "Error: You can only have one %s parameter!\n");
err_exit("Error: You can only have one %s parameter!\n", err_type);
}
void show_loc_err_and_exit()
@@ -176,7 +175,6 @@ int main(int argc, char *argv[])
struct ifreq ifr;
struct can_frame frame;
bool show_bits = false, location_processed = false, transceiver_processed = false, arbitration_processed = false;
char tmp_str[256];
printf("CAN Sockets Error Messages Simulator\n");
if (argc < 3)
@@ -537,24 +535,25 @@ int main(int argc, char *argv[])
// create socket
if ((sock = socket(PF_CAN, SOCK_RAW, CAN_RAW)) < 0)
err_exit("Error while opening socket");
err_exit("Error while opening socket\n");
// set interface name
if (strlen(argv[1]) >= IFNAMSIZ)
err_exit("Name of CAN device '%s' is too long!\n\n", argv[1]);
strcpy(ifr.ifr_name, argv[1]); // can0, vcan0...
if (ioctl(sock, SIOCGIFINDEX, &ifr) < 0) {
sprintf(tmp_str, "Error setting CAN interface name %s", argv[1]);
err_exit(tmp_str);
}
if (ioctl(sock, SIOCGIFINDEX, &ifr) < 0)
err_exit("Error setting CAN interface name %s\n", argv[1]);
// bind socket to the CAN interface
addr.can_family = AF_CAN;
addr.can_ifindex = ifr.ifr_ifindex;
if (bind(sock, (struct sockaddr *)&addr, sizeof(addr)) < 0)
err_exit("Error in socket bind");
err_exit("Error in socket bind\n");
// Send CAN error frame
if (write(sock, &frame, sizeof(frame)) < 0)
err_exit("Error writing to socket");
err_exit("Error writing to socket\n");
else
printf("CAN error frame sent\n");
+25 -3
View File
@@ -177,7 +177,8 @@ int main(int argc, char **argv)
sigset_t sigset;
fd_set rdfs;
int s[MAXDEV];
int socki, accsocket;
int socki;
int accsocket = -1;
canid_t mask[MAXDEV] = {0};
canid_t value[MAXDEV] = {0};
int inv_filter[MAXDEV] = {0};
@@ -286,7 +287,7 @@ int main(int argc, char **argv)
inaddr.sin_addr.s_addr = htonl(INADDR_ANY);
inaddr.sin_port = htons(port);
while(bind(socki, (struct sockaddr*)&inaddr, sizeof(inaddr)) < 0) {
while(running && bind(socki, (struct sockaddr*)&inaddr, sizeof(inaddr)) < 0) {
struct timespec f = {
.tv_nsec = 100 * 1000 * 1000,
};
@@ -295,18 +296,28 @@ int main(int argc, char **argv)
nanosleep(&f, NULL);
}
/*
* Check if loop exited due to signal (during nanosleep) rather than
* successful bind.
*/
if (!running) {
close(socki);
return 128 + signal_num;
}
if (listen(socki, 3) != 0) {
perror("listen");
exit(1);
}
while(1) {
while(running) {
accsocket = accept(socki, (struct sockaddr*)&clientaddr, &sin_size);
if (accsocket > 0) {
//printf("accepted\n");
if (!fork())
break;
close(accsocket);
accsocket = -1;
}
else if (errno != EINTR) {
perror("accept");
@@ -314,6 +325,17 @@ int main(int argc, char **argv)
}
}
/*
* Check if loop exited due to signal (accept returned EINTR) rather
* than successful fork
*/
if (!running) {
if (accsocket > 0)
close(accsocket);
close(socki);
return 128 + signal_num;
}
for (i=0; i<currmax; i++) {
pr_debug("open %d '%s' m%08X v%08X i%d e%d.\n",
+6
View File
@@ -41,6 +41,7 @@ static void gmtime_to_j1939_pgn_65254_td(struct j1939_time_date_packet *tdp)
utc_tm = gmtime_r(&now, &utc_tm_buf);
local_tm = localtime_r(&now, &local_tm_buf);
if (local_tm) {
/* Calculate the offsets */
hour_offset = local_tm->tm_hour - utc_tm->tm_hour;
minute_offset = local_tm->tm_min - utc_tm->tm_min;
@@ -52,6 +53,11 @@ static void gmtime_to_j1939_pgn_65254_td(struct j1939_time_date_packet *tdp)
else
hour_offset -= 24; /* before midnight */
}
} else {
/* The local time offsets cannot be determined at the moment */
hour_offset = 0xF9;
minute_offset = 0xFF;
}
/*
* Seconds (spn959):
@@ -51,7 +51,7 @@ struct j1939_vp_err_msg {
#define J1939_VP1_PRIO_DEFAULT 6
#define J1939_VP1_MAX_TRANSFER_LENGH \
sizeof(struct j1939_vp1_packet)
#define J1939_VP1_REPETITION_RATE_MS 5000
#define J1939_VP1_REPETITION_RATE_MS 1000
#define J1939_VP1_JITTER_MS 500
/**
@@ -63,8 +63,8 @@ struct j1939_vp_err_msg {
* - Data Length: 4 bytes
* - Resolution: 10^-7 deg/bit
* - Offset: -210 degrees
* - Range: -210 to +211.1008122 degrees
* - Operating Range: -210 degrees (SOUTH) to +211.108122 degrees
* - Range: -210 to +211.10081215 degrees
* - Operating Range: -210 degrees (SOUTH) to +211.1081215 degrees
* (NORTH)
*
* @longitude: Raw longitude position of the vehicle
@@ -72,8 +72,8 @@ struct j1939_vp_err_msg {
* - Data Length: 4 bytes
* - Resolution: 10^-7 deg/bit
* - Offset: -210 degrees
* - Range: -210 to +211.1008122 degrees
* - Operating Range: -210 degrees (WEST) to +211.108122 degrees
* - Range: -210 to +211.10081215 degrees
* - Operating Range: -210 degrees (WEST) to +211.1081215 degrees
* (EAST)
*
* This structure defines each component of the Vehicle Position as described in
@@ -142,32 +142,35 @@ j1939_vp1_set_longitude(struct j1939_vp1_packet *packet, int32_t longitude)
/**
* struct j1939_vp2_packet - Represents the PGN 64502 Vehicle
* Position 2 packet
* FIXME: current packet layout is guessed based on limited information:
* https://www.isobus.net/isobus/pGNAndSPN/10801?type=PGN
*
* @total_satellites: Total number of satellites in view
* - SPN: 8128
* - Data Length: 1 byte
* - Range: 0 to 250
*
* @hdop: Horizontal dilution of precision
* - SPN: 8129
* - Data Length: 1 byte
* - Resolution: 0.1
* - Range: 0.0 to 25.0
*
* @vdop: Vertical dilution of precision
* - SPN: 8130
* - Data Length: 1 byte
* - Resolution: 0.1
* - Range: 0.0 to 25.0
*
* @pdop: Position dilution of precision
* - SPN: 8131
* - Data Length: 1 byte
* - Resolution: 0.1
* - Range: 0.0 to 25.0
*
* @tdop: Time dilution of precision
* - SPN: 8132
* - Data Length: 1 byte
* - Resolution: 0.1
* - Range: 0.0 to 25.0
*
* This structure defines each component of the Vehicle Position 2 as described
* in PGN 64502.
@@ -178,6 +181,9 @@ struct j1939_vp2_packet {
uint8_t vdop; /* SPN 8130 */
uint8_t pdop; /* SPN 8131 */
uint8_t tdop; /* SPN 8132 */
uint8_t unused5; /* Always 0xFF */
uint8_t unused6; /* Always 0xFF */
uint8_t unused7; /* Always 0xFF */
} __attribute__((__packed__));
/**
@@ -270,6 +270,12 @@ static int j1939_vp2_get_data(struct j1939_vp_srv_priv *priv,
j1939_vp2_set_pdop(vp2p, pdop);
j1939_vp2_set_tdop(vp2p, tdop);
/* This PG's last 3 bytes are not assigned and hence must be set
* to 0xFF as per J1939-71, section 5.2 */
vp2p->unused5 = 0xFF;
vp2p->unused6 = 0xFF;
vp2p->unused7 = 0xFF;
return 0;
}
+16 -10
View File
@@ -170,21 +170,23 @@ int parse_canframe(char *cs, union cfu *cu)
memset(cu, 0, sizeof(*cu)); /* init CAN CC/FD/XL frame, e.g. LEN = 0 */
if (len < 4)
return 0;
if (len >= 4 && cs[3] == CANID_DELIM) { /* 3 digits SFF CAN ID */
if (cs[3] == CANID_DELIM) { /* 3 digits SFF */
idx = 4; /* start of frame data */
idx = 4;
/* get 3 digits SFF CAN ID value */
for (i = 0; i < 3; i++) {
if ((tmp = asc2nibble(cs[i])) > 0x0F)
return 0;
cu->cc.can_id |= tmp << (2 - i) * 4;
}
} else if (cs[5] == CANID_DELIM) { /* 5 digits CAN XL VCID/PRIO*/
} else if (len >= 21 && cs[5] == CANID_DELIM && cs[20] == CANID_DELIM) {
/* 5 digits CAN XL VCID/PRIO - but also check for 2nd '#' here */
idx = 6;
idx = 6; /* start of CAN XL frame extra content (AF, SDT, etc) */
/* get 5 digits CAN XL VCID/PRIO */
for (i = 0; i < 5; i++) {
if ((tmp = asc2nibble(cs[i])) > 0x0F)
return 0;
@@ -196,9 +198,11 @@ int parse_canframe(char *cs, union cfu *cu)
cu->xl.prio &= CANXL_PRIO_MASK;
cu->xl.prio |= tmp;
} else if (cs[8] == CANID_DELIM) { /* 8 digits EFF */
} else if (len >= 9 && cs[8] == CANID_DELIM) { /* 8 digits EFF CAN ID */
idx = 9;
idx = 9; /* start of frame data */
/* get 8 digits EFF CAN ID value */
for (i = 0; i < 8; i++) {
if ((tmp = asc2nibble(cs[i])) > 0x0F)
return 0;
@@ -239,11 +243,12 @@ int parse_canframe(char *cs, union cfu *cu)
cu->fd.flags |= CANFD_FDF; /* dual-use */
idx += 2;
} else if (cs[idx + 14] == CANID_DELIM) { /* CAN XL frame '#80:00:11223344#' */
} else if (idx == 6) { /* CAN XL frame extra content '#80:00:11223344#' */
maxdlen = CANXL_MAX_DLEN;
mtu = CANXL_MTU;
data = cu->xl.data; /* fill CAN XL data */
data = cu->xl.data; /* overwrite pointer to CAN XL data */
/* get CAN XL frame extra content */
if ((cs[idx + 2] != XL_HDR_DELIM) || (cs[idx + 5] != XL_HDR_DELIM))
return 0;
@@ -277,6 +282,7 @@ int parse_canframe(char *cs, union cfu *cu)
idx++; /* skip CANID_DELIM */
}
/* copy CAN frame data content */
for (i = 0, dlen = 0; i < maxdlen; i++) {
if (cs[idx] == DATA_SEPERATOR) /* skip (optional) separator */
idx++;
+1 -2
View File
@@ -72,8 +72,7 @@ int mcp251xfd_regmap_read(struct mcp251xfd_priv *priv,
return 0;
/* maybe it's something like "spi0.0" */
tmp = strchr(file_path, '/');
if (tmp)
if (strchr(file_path, '/'))
return -ENOENT;
/* first try literally */