Skip to content

RDKEMW-25480: Harden string validation in _dsSetSecondaryLanguage - #304

Open
andrejz2 wants to merge 2 commits into
developfrom
topic/RDKEMW-25480
Open

andrejz2 wants to merge 2 commits into
developfrom
topic/RDKEMW-25480

Conversation

@andrejz2

Copy link
Copy Markdown

Harden string validation in _dsSetSecondaryLanguage to prevent injection attacks from empty strings and uncaught exceptions.

Changes

  • Added validation for non-empty secondaryLanguage before persisting
  • Wrapped persistHostProperty in try/catch to prevent crashes
  • Added security regression test to validate string checking logic

Testing

  • Added testMs12Validation.cpp with 8 test cases validating input validation
  • All tests pass: valid values accepted, empty/NULL values rejected

Parent Story: RDKEMW-25465

Add validation for non-empty secondaryLanguage before persisting to prevent
injection attacks. Wrap persistHostProperty in try/catch to prevent crashes.
Add security regression test to validate string checking logic.
@andrejz2
andrejz2 requested a review from a team as a code owner September 23, 2026 21:13
Copilot AI lite review requested due to automatic review settings September 23, 2026 21:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Comment thread rpc/srv/dsAudio.c Fixed
@andrejz2

Copy link
Copy Markdown
Author

Ready for Review

All required CI checks have completed successfully for the current head SHA:

  • Coverity: Success
  • CodeQL: Success
  • Signature Check: Success
  • Fossid: Success
  • Build: Success
  • Analyze: Success

The PR is mergeable and ready for human review.

Parent Story: RDKEMW-25465

Remove unnecessary NULL check on char array (secondaryLanguage) to address
Coverity warning. The array is always non-NULL, so only strlen check is needed.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 24, 2026 15:33

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@andrejz2

Copy link
Copy Markdown
Author

Addressed Coverity warning by removing unnecessary NULL check on char array.

The field is a char array, not a pointer, so the NULL check was unnecessary. Removed it to address the Coverity false positive while preserving the strlen validation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants