Skip to content

RDKEMW-25493: Harden port name validation in audio persistence handlers - #317

Open
andrejz2 wants to merge 2 commits into
developfrom
topic/RDKEMW-25493
Open

andrejz2 wants to merge 2 commits into
developfrom
topic/RDKEMW-25493

Conversation

@andrejz2

Copy link
Copy Markdown

Add validation for portName before using as persistence key to prevent injection attacks from whitespace and control characters.

Changes

  • Added validation for portName in _dsEnableAudioPort
  • Added validation for portName in _dsSetEnablePersist
  • Rejects empty strings and whitespace/control characters
  • Added security regression test to validate port name checking logic

Testing

  • Added testPortNameValidation.cpp with 6 test cases validating port name validation
  • All tests pass: valid accepted, empty/whitespace/control rejected

Parent Story: RDKEMW-25465

Add validation for portName before using as persistence key to prevent
injection attacks from whitespace and control characters.
Add security regression test to validate port name checking logic.
Copilot AI lite review requested due to automatic review settings September 23, 2026 21:28
@andrejz2
andrejz2 requested a review from a team as a code owner September 23, 2026 21:28

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Comment thread rpc/srv/dsAudio.c Fixed
Comment thread rpc/srv/dsAudio.c Fixed
@andrejz2

Copy link
Copy Markdown
Author

Ready for Review

All required CI checks have completed successfully for the current head SHA:

  • Coverity: Success
  • CodeQL: Success
  • Signature Check: Success
  • Fossid: Success
  • Build: Success
  • Analyze: Success

The PR is mergeable and ready for human review.

Parent Story: RDKEMW-25465

Remove unnecessary NULL checks on char array (portName) to address
Coverity warning. The array is always non-NULL, so only strlen check is needed.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 24, 2026 15:33

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@andrejz2

Copy link
Copy Markdown
Author

Addressed Coverity warnings by removing unnecessary NULL checks on char array.

The field is a char array, not a pointer, so the NULL checks were unnecessary. Removed them to address the Coverity false positives while preserving the strlen validation.

@andrejz2

Copy link
Copy Markdown
Author

This has been addressed in the latest commit (902db1a). The NULL checks on char array have been removed.

1 similar comment
@andrejz2

Copy link
Copy Markdown
Author

This has been addressed in the latest commit (902db1a). The NULL checks on char array have been removed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants