From 0df7c6f44ddc74148a61d7d3ac88eda8ea35acf2 Mon Sep 17 00:00:00 2001 From: azerom960 Date: Wed, 30 Sep 2026 00:00:30 -0400 Subject: [PATCH 1/3] RDKEMW-26150: Synchronize application status cache access --- server/plat/gdialappcache.cpp | 13 ++++++------- server/plat/gdialobjCacheHelper.hpp | 16 ++++++++++++---- tests/test_security_cache.py | 17 +++++++++++++++++ 3 files changed, 35 insertions(+), 11 deletions(-) create mode 100644 tests/test_security_cache.py diff --git a/server/plat/gdialappcache.cpp b/server/plat/gdialappcache.cpp index dfd08dde..23e2378b 100644 --- a/server/plat/gdialappcache.cpp +++ b/server/plat/gdialappcache.cpp @@ -86,15 +86,14 @@ std::string GDialAppStatusCache::SearchAppStatusInCache(const char* app_name) std::string state = "NOT_FOUND"; std::string id = getAppCacheId(app_name); - if(doIdExist(id)) + AppInfo appEntry("", "", "", ""); + if(ObjectCache->findObject(id, appEntry)) { - AppInfo* appEntry = ObjectCache->findObject(id); - - state = appEntry->appState; + state = appEntry.appState; GDIAL_LOGINFO("APPCache: App Name[%s] AppID[%s] Error[%s]", - appEntry->appName.c_str(), - appEntry->appId.c_str(), - appEntry->appError.c_str()); + appEntry.appName.c_str(), + appEntry.appId.c_str(), + appEntry.appError.c_str()); } GDIAL_LOGINFO("App State = %s ",state.c_str()); GDIAL_LOGTRACE("Exiting ..."); diff --git a/server/plat/gdialobjCacheHelper.hpp b/server/plat/gdialobjCacheHelper.hpp index f7286d54..7219ffc5 100644 --- a/server/plat/gdialobjCacheHelper.hpp +++ b/server/plat/gdialobjCacheHelper.hpp @@ -25,6 +25,7 @@ #include #include #include +#include #include "gdialservicelogging.h" enum AppCacheErrorCodes { @@ -56,6 +57,7 @@ class GDialObjectCacheHelper public: GDialObjectCacheHelper(){ } ~GDialObjectCacheHelper() { + std::lock_guard lock(objectsMutex); for (auto& entry : objects) { if (entry.second) { @@ -65,22 +67,25 @@ class GDialObjectCacheHelper } } - AppInfo* findObject(const std::string& appName) const + bool findObject(const std::string& appName, AppInfo& entry) const { GDIAL_LOGTRACE("Entering ..."); + std::lock_guard lock(objectsMutex); auto it = objects.find(appName); - if (it != objects.end()) + if (it != objects.end() && it->second) { + entry = *it->second; GDIAL_LOGTRACE("Exiting ..."); - return it->second; + return true; } GDIAL_LOGTRACE("Exiting ..."); - return nullptr; + return false; } AppCacheErrorCodes insert(std::string id, AppInfo* entry) { GDIAL_LOGTRACE("Entering ..."); + std::lock_guard lock(objectsMutex); AppCacheErrorCodes returnValue = AppCacheError_NULL_ENTRY; if (nullptr != entry) { @@ -102,6 +107,7 @@ class GDialObjectCacheHelper { AppCacheErrorCodes returnValue = AppCacheError_NOT_FOUND; GDIAL_LOGTRACE("Entering [%s]...",appname.c_str()); + std::lock_guard lock(objectsMutex); auto it = objects.find(appname); if (it != objects.end()) { @@ -117,6 +123,7 @@ class GDialObjectCacheHelper { AppCacheErrorCodes returnValue = AppCacheError_NOT_FOUND; GDIAL_LOGTRACE("Entering ..."); + std::lock_guard lock(objectsMutex); auto it = objects.find(appname); if (it != objects.end()) { @@ -129,5 +136,6 @@ class GDialObjectCacheHelper } private: std::unordered_map objects; + mutable std::mutex objectsMutex; }; #endif diff --git a/tests/test_security_cache.py b/tests/test_security_cache.py new file mode 100644 index 00000000..fc317b97 --- /dev/null +++ b/tests/test_security_cache.py @@ -0,0 +1,17 @@ +import pathlib +import unittest + + +class CacheSecurityGuardrail(unittest.TestCase): + def test_cache_operations_are_locked_and_reads_are_copied(self): + root = pathlib.Path(__file__).parents[1] + helper = (root / "server/plat/gdialobjCacheHelper.hpp").read_text() + caller = (root / "server/plat/gdialappcache.cpp").read_text() + self.assertGreaterEqual(helper.count("std::lock_guard lock(objectsMutex);"), 5) + self.assertIn("bool findObject(const std::string& appName, AppInfo& entry) const", helper) + self.assertIn("entry = *it->second;", helper) + self.assertNotIn("AppInfo* appEntry = ObjectCache->findObject", caller) + + +if __name__ == "__main__": + unittest.main() From 6356619923ed905d9e0cd7095923249dc5c6a8a7 Mon Sep 17 00:00:00 2001 From: azerom960 Date: Wed, 30 Sep 2026 00:31:00 -0400 Subject: [PATCH 2/3] RDKEMW-26150: Use compatible entservices APIs --- build_dependencies.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/build_dependencies.sh b/build_dependencies.sh index 86d6c353..af4f8403 100755 --- a/build_dependencies.sh +++ b/build_dependencies.sh @@ -36,7 +36,7 @@ git clone --branch R4.4.3 https://github.com/rdkcentral/ThunderTools.git git clone --branch R4.4.1 https://github.com/rdkcentral/Thunder.git -git clone --branch main https://github.com/rdkcentral/entservices-apis.git +git clone --branch topic/RDKEMW-26132 https://github.com/rdkcentral/entservices-apis.git git clone https://$GITHUB_TOKEN@github.com/rdkcentral/entservices-testframework.git From 8cf8c1cb5aa6d90bd40cb37077a8cc5f1a085085 Mon Sep 17 00:00:00 2001 From: azerom960 Date: Wed, 30 Sep 2026 02:09:47 -0400 Subject: [PATCH 3/3] RDKEMW-26150: Align native build dependencies --- build_dependencies.sh | 23 +++++++++++++---------- 1 file changed, 13 insertions(+), 10 deletions(-) diff --git a/build_dependencies.sh b/build_dependencies.sh index af4f8403..b890ec13 100755 --- a/build_dependencies.sh +++ b/build_dependencies.sh @@ -10,7 +10,7 @@ cd ${GITHUB_WORKSPACE} #1. Install Dependencies and packages apt update -apt install -y ninja-build meson curl libsoup2.4-dev libxml2-dev libglib2.0-dev gobject-introspection libgirepository1.0-dev libgtk-3-dev valac pandoc +apt install -y git python3 python3-pip cmake ninja-build meson curl libsoup2.4-dev libxml2-dev libglib2.0-dev gobject-introspection libgirepository1.0-dev libgtk-3-dev libcurl4-openssl-dev libcunit1-dev valac pandoc pip install jsonref ############################ @@ -28,17 +28,25 @@ cd .. rm -rf iarmbus ThunderTools Thunder entservices-apis entservices-testframework gssdp +THUNDER_TOOLS_COMMIT_SHA="d5dd83c7c19c49c7f25c558c126500bd2d64f7a4" +THUNDER_COMMIT_SHA="2c0fcc5529e7da734be558ca6efa05d934dcce31" git clone https://github.com/rdkcentral/iarmbus.git export IARMBUS_PATH=$GITHUB_WORKSPACE/iarmbus -git clone --branch R4.4.3 https://github.com/rdkcentral/ThunderTools.git +git clone --branch R4_4-RDK https://github.com/rdkcentral/ThunderTools.git +cd ThunderTools +git checkout $THUNDER_TOOLS_COMMIT_SHA +cd .. -git clone --branch R4.4.1 https://github.com/rdkcentral/Thunder.git +git clone --branch R4_4-RDK https://github.com/rdkcentral/Thunder.git +cd Thunder +git checkout $THUNDER_COMMIT_SHA +cd .. -git clone --branch topic/RDKEMW-26132 https://github.com/rdkcentral/entservices-apis.git +git clone --branch develop https://github.com/rdkcentral/entservices-apis.git -git clone https://$GITHUB_TOKEN@github.com/rdkcentral/entservices-testframework.git +git clone --branch 2.0.0 https://github.com/rdkcentral/entservices-testframework.git git clone --branch gssdp-1.2.3 https://gitlab.gnome.org/GNOME/gssdp.git @@ -60,7 +68,6 @@ cd - echo "======================================================================================" echo "buliding thunderTools" cd ThunderTools -patch -p1 < $GITHUB_WORKSPACE/entservices-testframework/patches/00010-R4.4-Add-support-for-project-dir.patch cd - @@ -79,10 +86,6 @@ echo "========================================================================== echo "buliding thunder" cd Thunder -patch -p1 < $GITHUB_WORKSPACE/entservices-testframework/patches/Use_Legact_Alt_Based_On_ThunderTools_R4.4.3.patch -patch -p1 < $GITHUB_WORKSPACE/entservices-testframework/patches/error_code_R4_4.patch -patch -p1 < $GITHUB_WORKSPACE/entservices-testframework/patches/1004-Add-support-for-project-dir.patch -patch -p1 < $GITHUB_WORKSPACE/entservices-testframework/patches/RDKEMW-733-Add-ENTOS-IDS.patch cd - cmake -G Ninja -S Thunder -B build/Thunder \