Skip to content

RDKEMW-25731: Harden CEC receive validation - #65

Open
andrejz2 wants to merge 3 commits into
developfrom
topic/RDKEMW-25731
Open

andrejz2 wants to merge 3 commits into
developfrom
topic/RDKEMW-25731

Conversation

@andrejz2

Copy link
Copy Markdown

Summary

  • validate receive buffers and lengths at the driver callback boundary
  • contain callback processing failures before returning to the HAL
  • add focused coverage for valid and invalid receive lengths

Test plan

  • focused receive-length regression test passes
  • component and L1 test targets build in the local compatibility environment
  • full L1 run reaches an existing unrelated driver-test instability; focused coverage completes successfully

Jira: RDKEMW-25731
Parent: RDKEMW-25668

Generated with Devin

Reject invalid frame buffers and lengths before allocation, and contain callback processing failures so malformed input cannot unwind through the HAL boundary.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
@andrejz2
andrejz2 requested a review from a team as a code owner September 24, 2026 18:57
Copilot AI lite review requested due to automatic review settings September 24, 2026 18:57

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

- Expose and verify the receive-frame boundary predicate
- Make callback frame ownership exception-safe

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 25, 2026 15:09

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@andrejz2

Copy link
Copy Markdown
Author

Addressed security review feedback by making the receive-boundary predicate directly testable and making callback frame ownership exception-safe. Focused validation coverage passes locally; current-head CI is running.

Comment thread ccec/src/DriverImpl.cpp Fixed
@andrejz2

Copy link
Copy Markdown
Author

Current-head repository build/tests and available security/license checks pass for 2c4b83cda0f5fbe55c25df3e55d427eeaca5eceb. External Coverity job jenkins-coverity-build-component-native-200077 reported Build Failed without a target URL or diagnostic logs, so this PR remains CI-blocked and is not being marked Ready for Review. A Coverity rerun or Jenkins log access is required.

Changed from unique_ptr::release() to raw pointer with explicit
nulling after queue takes ownership. This pattern is clearer to
static analysis tools while maintaining the same memory-safety
guarantees.

Generated with [Devin](https://devin.ai)

Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
Copilot AI review requested due to automatic review settings September 26, 2026 01:42

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@andrejz2

Copy link
Copy Markdown
Author

Coverity false positive addressed by changing from unique_ptr::release() to raw pointer with explicit nulling after queue takes ownership. New head is 9e3a8dd. Waiting for CI to confirm the static analysis warning is resolved.

@andrejz2

Copy link
Copy Markdown
Author

Final adversarial review passed for head 9e3a8dd. All CI checks successful (build, CodeQL, Coverity, Fossid, signature, analysis). No new vulnerabilities introduced. Memory safety maintained. Ready for review.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants