Skip to content

RDKEMW-22727 : Fix coverity issues on iarm-event-sender - #59

Merged
apatel859 merged 2 commits into
developfrom
feature/RDKEMW-22727
Aug 17, 2026
Merged

apatel859 merged 2 commits into
developfrom
feature/RDKEMW-22727

Conversation

@balav08

@balav08 balav08 commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

Reason for change: Fixing coverity reported issues.
Test Procedure: Refer ticket.
Risks: Low
Priority: P2
version: minor

Reason for change: Fixing coverity reported issues.
Test Procedure: Refer ticket.
Risks: Low
Priority: P2
version: minor

Signed-off-by: balaji velmurugan <balaji_velmurugan@comcast.com>
Copilot AI lite review requested due to automatic review settings July 30, 2026 12:27
@balav08
balav08 requested a review from a team as a code owner July 30, 2026 12:27

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR addresses a Coverity finding in iarm-event-sender by adding return-value checking for an IARM_Bus_Call made when handling the PeripheralUpgradeEvent.

Changes:

  • Captures the return value of IARM_Bus_Call in the PeripheralUpgradeEvent path.
  • Logs a warning when the call fails.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread iarm-event-sender/IARM_event_sender.c Outdated
Copilot AI review requested due to automatic review settings August 14, 2026 10:15

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.

Suppressed comments (1)

iarm-event-sender/IARM_event_sender.c:547

  • memcpy(..., strtok(...), CTRLM_DEVICE_UPDATE_PATH_LENGTH) can read past the end of the token (fixed-length copy from a NUL-terminated string) and will also crash if the payload is missing the expected ':' separator because strtok can return NULL. Also, the result of IARM_Bus_Call is currently only logged; sendIARMEventPayload still returns IARM_RESULT_SUCCESS even when the call fails. Consider validating tokens, using a bounded string copy, and storing the call result in retCode so callers can detect failure.
             memcpy(firmwareInfo.firmwareLocation, strtok(eventPayload, ":"),CTRLM_DEVICE_UPDATE_PATH_LENGTH);
             memcpy(firmwareInfo.firmwareNames, strtok(NULL, ":"),CTRLM_DEVICE_UPDATE_PATH_LENGTH);
             g_message("IARM_event_sender entered case for PeripheralUpgradeEvent : %s and %s\r\n",firmwareInfo.firmwareLocation,firmwareInfo.firmwareNames);

             IARM_Result_t ret = IARM_Bus_Call(CTRLM_MAIN_IARM_BUS_NAME,

@apatel859
apatel859 merged commit 6193b2a into develop Aug 17, 2026
11 checks passed
@github-actions github-actions Bot locked and limited conversation to collaborators Aug 17, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants