diff --git a/build_dependencies.sh b/build_dependencies.sh index 86d6c353..b890ec13 100755 --- a/build_dependencies.sh +++ b/build_dependencies.sh @@ -10,7 +10,7 @@ cd ${GITHUB_WORKSPACE} #1. Install Dependencies and packages apt update -apt install -y ninja-build meson curl libsoup2.4-dev libxml2-dev libglib2.0-dev gobject-introspection libgirepository1.0-dev libgtk-3-dev valac pandoc +apt install -y git python3 python3-pip cmake ninja-build meson curl libsoup2.4-dev libxml2-dev libglib2.0-dev gobject-introspection libgirepository1.0-dev libgtk-3-dev libcurl4-openssl-dev libcunit1-dev valac pandoc pip install jsonref ############################ @@ -28,17 +28,25 @@ cd .. rm -rf iarmbus ThunderTools Thunder entservices-apis entservices-testframework gssdp +THUNDER_TOOLS_COMMIT_SHA="d5dd83c7c19c49c7f25c558c126500bd2d64f7a4" +THUNDER_COMMIT_SHA="2c0fcc5529e7da734be558ca6efa05d934dcce31" git clone https://github.com/rdkcentral/iarmbus.git export IARMBUS_PATH=$GITHUB_WORKSPACE/iarmbus -git clone --branch R4.4.3 https://github.com/rdkcentral/ThunderTools.git +git clone --branch R4_4-RDK https://github.com/rdkcentral/ThunderTools.git +cd ThunderTools +git checkout $THUNDER_TOOLS_COMMIT_SHA +cd .. -git clone --branch R4.4.1 https://github.com/rdkcentral/Thunder.git +git clone --branch R4_4-RDK https://github.com/rdkcentral/Thunder.git +cd Thunder +git checkout $THUNDER_COMMIT_SHA +cd .. -git clone --branch main https://github.com/rdkcentral/entservices-apis.git +git clone --branch develop https://github.com/rdkcentral/entservices-apis.git -git clone https://$GITHUB_TOKEN@github.com/rdkcentral/entservices-testframework.git +git clone --branch 2.0.0 https://github.com/rdkcentral/entservices-testframework.git git clone --branch gssdp-1.2.3 https://gitlab.gnome.org/GNOME/gssdp.git @@ -60,7 +68,6 @@ cd - echo "======================================================================================" echo "buliding thunderTools" cd ThunderTools -patch -p1 < $GITHUB_WORKSPACE/entservices-testframework/patches/00010-R4.4-Add-support-for-project-dir.patch cd - @@ -79,10 +86,6 @@ echo "========================================================================== echo "buliding thunder" cd Thunder -patch -p1 < $GITHUB_WORKSPACE/entservices-testframework/patches/Use_Legact_Alt_Based_On_ThunderTools_R4.4.3.patch -patch -p1 < $GITHUB_WORKSPACE/entservices-testframework/patches/error_code_R4_4.patch -patch -p1 < $GITHUB_WORKSPACE/entservices-testframework/patches/1004-Add-support-for-project-dir.patch -patch -p1 < $GITHUB_WORKSPACE/entservices-testframework/patches/RDKEMW-733-Add-ENTOS-IDS.patch cd - cmake -G Ninja -S Thunder -B build/Thunder \ diff --git a/server/gdial-rest.c b/server/gdial-rest.c index 8af53e50..acf202f6 100644 --- a/server/gdial-rest.c +++ b/server/gdial-rest.c @@ -812,6 +812,10 @@ static void gdial_rest_http_server_apps_callback(SoupServer *server, for (i = 0; elements[i] != NULL; i++) { gsize ret; /* do not allow any element to be empty, stop on first one */ + if (elements[i][0] == '\0') { + g_strfreev(elements); + gdial_rest_server_http_return_if_fail(FALSE, msg, SOUP_STATUS_NOT_IMPLEMENTED); + } if (j == 0) { ret = g_strlcpy(base, elements[i], sizeof(base)); if (ret >= sizeof(base)) { @@ -844,12 +848,8 @@ static void gdial_rest_http_server_apps_callback(SoupServer *server, */ const gchar *copied_str[] = {base, app_name, instance, last_elem}; i = 0; j = 0; - while (i < element_num && (unsigned int)i < sizeof(copied_str)/sizeof(copied_str[0])) { + while (elements[j] != NULL && i < element_num && (unsigned int)i < sizeof(copied_str)/sizeof(copied_str[0])) { bool flag = false; - if (strlen(elements[j]) == 0) { - j++; - continue; - } invalid_uri = invalid_uri || g_strcmp0(copied_str[i], elements[j]); gdial_rest_server_http_check_if_fail(!invalid_uri, msg, SOUP_STATUS_NOT_IMPLEMENTED, flag); if(flag){ diff --git a/tests/test_security_uri_validation.py b/tests/test_security_uri_validation.py new file mode 100644 index 00000000..066dbaff --- /dev/null +++ b/tests/test_security_uri_validation.py @@ -0,0 +1,16 @@ +import pathlib +import unittest + + +class UriValidationGuardrail(unittest.TestCase): + def test_empty_path_components_are_rejected_before_copy(self): + source = (pathlib.Path(__file__).parents[1] / "server/gdial-rest.c").read_text() + loop = source.index("for (i = 0; elements[i] != NULL; i++)", source.rindex("g_strsplit(&path[1]")) + copy = source.index("g_strlcpy(base", loop) + rejection = source.index("if (elements[i][0] == '\\0')", loop) + self.assertLess(rejection, copy) + self.assertIn("while (elements[j] != NULL && i < element_num", source) + + +if __name__ == "__main__": + unittest.main()